273 lines
9.9 KiB
Markdown
273 lines
9.9 KiB
Markdown
|
|
# approval-engine — Agent Instructions
|
||
|
|
|
||
|
|
## Repo Identity
|
||
|
|
|
||
|
|
**Purpose:** PIP for the approval object: durable, authenticated, consumable, atomically supersedable.
|
||
|
|
|
||
|
|
**Domain:** infotech
|
||
|
|
**Repo slug:** approval-engine
|
||
|
|
**Topic ID:** `cee7bedf-2b48-46ef-8601-006474f2ad7a`
|
||
|
|
**Workplan prefix:** `APPROVAL-WP-`
|
||
|
|
|
||
|
|
---
|
||
|
|
|
||
|
|
## State Hub Integration
|
||
|
|
|
||
|
|
The Custodian State Hub tracks work across all domains. Codex uses HTTP REST and
|
||
|
|
the `statehub` CLI by default. MCP is opt-in because the current Codex MCP bridge
|
||
|
|
adds severe call latency; the full administrative MCP surface remains available
|
||
|
|
to clients that need it.
|
||
|
|
|
||
|
|
| Context | URL |
|
||
|
|
|---------|-----|
|
||
|
|
| Local workstation | `http://127.0.0.1:8000` |
|
||
|
|
| Remote via tunnel | `http://127.0.0.1:18000` |
|
||
|
|
| Optional local edge relay | http://127.0.0.1:18080 |
|
||
|
|
|
||
|
|
When an operator has enabled the edge relay, set API_BASE to the relay URL.
|
||
|
|
Queueable writes return an explicit queued receipt if the central hub is
|
||
|
|
unreachable. Treat that as pending local evidence, then ask the operator to run
|
||
|
|
statehub outbox status/replay after connectivity returns.
|
||
|
|
|
||
|
|
Codex workspace-write sandboxes need network access enabled to reach the host's
|
||
|
|
loopback listener. Bootstrap this once with `make -C ~/state-hub configure-codex`
|
||
|
|
and restart Codex. The canonical REST health endpoint is `/state/health`, not
|
||
|
|
`/health`. If a sandboxed loopback probe fails, retry it with escalated execution
|
||
|
|
before declaring State Hub unavailable; a managed Codex permission profile may
|
||
|
|
still enforce isolated networking. Experimental MCP can be enabled explicitly
|
||
|
|
with `make -C ~/state-hub configure-codex WITH_MCP=1`.
|
||
|
|
|
||
|
|
### Orient at session start
|
||
|
|
|
||
|
|
```bash
|
||
|
|
# Offline brief — works without hub connection
|
||
|
|
cat .custodian-brief.md
|
||
|
|
|
||
|
|
# Active workplans for this domain
|
||
|
|
curl -s "http://127.0.0.1:8000/workplans/?topic_id=cee7bedf-2b48-46ef-8601-006474f2ad7a&status=active" \
|
||
|
|
| python3 -m json.tool
|
||
|
|
|
||
|
|
# Check inbox
|
||
|
|
curl -s "http://127.0.0.1:8000/messages/?to_agent=approval-engine&unread_only=true" \
|
||
|
|
| python3 -m json.tool
|
||
|
|
```
|
||
|
|
|
||
|
|
Mark a message read:
|
||
|
|
```bash
|
||
|
|
curl -s -X PATCH "http://127.0.0.1:8000/messages/<id>/read" \
|
||
|
|
-H "Content-Type: application/json" -d '{}'
|
||
|
|
```
|
||
|
|
|
||
|
|
### Log progress (required at session close)
|
||
|
|
|
||
|
|
```bash
|
||
|
|
curl -s -X POST http://127.0.0.1:8000/progress/ \
|
||
|
|
-H "Content-Type: application/json" \
|
||
|
|
-d '{
|
||
|
|
"summary": "what was done",
|
||
|
|
"event_type": "note",
|
||
|
|
"author": "codex",
|
||
|
|
"workplan_id": "<uuid>",
|
||
|
|
"task_id": "<uuid>"
|
||
|
|
}'
|
||
|
|
```
|
||
|
|
|
||
|
|
Omit `workplan_id` / `task_id` when not applicable.
|
||
|
|
|
||
|
|
### Update task status
|
||
|
|
|
||
|
|
```bash
|
||
|
|
curl -s -X PATCH "http://127.0.0.1:8000/tasks/<task_id>" \
|
||
|
|
-H "Content-Type: application/json" \
|
||
|
|
-d '{"status": "progress"}'
|
||
|
|
# values: wait | todo | progress | done | cancel
|
||
|
|
```
|
||
|
|
|
||
|
|
### Flag a task for human review
|
||
|
|
|
||
|
|
```bash
|
||
|
|
curl -s -X PATCH "http://127.0.0.1:8000/tasks/<task_id>" \
|
||
|
|
-H "Content-Type: application/json" \
|
||
|
|
-d '{"needs_human": true, "intervention_note": "reason"}'
|
||
|
|
```
|
||
|
|
|
||
|
|
---
|
||
|
|
|
||
|
|
## Session Protocol
|
||
|
|
|
||
|
|
**Start:**
|
||
|
|
1. `cat .custodian-brief.md` — domain goal and open workplans (offline-safe)
|
||
|
|
2. Check inbox: `GET /messages/?to_agent=approval-engine&unread_only=true`; mark read
|
||
|
|
3. Scan workplans: `ls workplans/` — note `status: ready`, `active`, or `blocked` files and open tasks
|
||
|
|
4. Check human-needed tasks: `GET /tasks/?needs_human=true`
|
||
|
|
|
||
|
|
**During work:**
|
||
|
|
- Update task statuses in workplan files as tasks progress
|
||
|
|
- Record significant decisions via `POST /decisions/`
|
||
|
|
|
||
|
|
**Close:**
|
||
|
|
1. Update workplan file task statuses to reflect progress
|
||
|
|
2. If finishing a workplan: hand off **residuals** as live work records first
|
||
|
|
(intake with `origin: residual` + `origin_ref: <WP-id>`, or a next workplan /
|
||
|
|
decision / engagement). Do not park leftovers only in prose or `SCOPE.md`.
|
||
|
|
Canon: `the-custodian/canon/standards/work-record-types_v0.1.md` § Residuals.
|
||
|
|
3. Log: `POST /progress/` with a summary of what changed (name handoff ids)
|
||
|
|
4. After workplan file changes, run:
|
||
|
|
```bash
|
||
|
|
statehub fix-consistency
|
||
|
|
```
|
||
|
|
Coding agents should run this directly; ask the operator only if the CLI or
|
||
|
|
State Hub API is unavailable. This syncs task status from files into the hub DB.
|
||
|
|
If C-06/C-11 reports that this host is not the identifier registrar, do not
|
||
|
|
retry, export `STATEHUB_REGISTRAR`, or register records by hand. Commit and
|
||
|
|
push the file-backed work first, then run the repo-manager fallback once:
|
||
|
|
```bash
|
||
|
|
uv run --project ~/repo-manager rmgr registrar-reconcile \
|
||
|
|
--path . --confirm-primary --push
|
||
|
|
```
|
||
|
|
If unavailable, send one deduplicated registrar request to `repo-manager`
|
||
|
|
naming the repo and canonical ids; UUID absence does not block local work.
|
||
|
|
|
||
|
|
---
|
||
|
|
|
||
|
|
## Credential and access routing
|
||
|
|
|
||
|
|
**Audience:** Codex, Claude Code, Grok, and custodian agents that call **llm-connect**
|
||
|
|
for inference. Run this check **before** requesting secrets, API keys, SSH access,
|
||
|
|
login tokens, or database passwords — in any repo, not only `ops-warden`.
|
||
|
|
|
||
|
|
The companion (`net-kingdom/SECURITY-COMPANION.md`) says what the rules are;
|
||
|
|
`ops-warden` stewards the paths through them. **Do not** message `ops-warden`
|
||
|
|
on State Hub expecting a secret value; the reply is a pointer, not a key.
|
||
|
|
|
||
|
|
### Lookup (do this first)
|
||
|
|
|
||
|
|
```bash
|
||
|
|
warden route find "<describe your need>" --json
|
||
|
|
warden route show <catalog-id> --json
|
||
|
|
```
|
||
|
|
|
||
|
|
Requires the `warden` CLI from `~/ops-warden`.
|
||
|
|
|
||
|
|
| Agent runtime | How to orient |
|
||
|
|
| --- | --- |
|
||
|
|
| **Codex / Grok** (shell, HTTP State Hub) | `warden route`; inbox `to_agent=approval-engine` is for coordination, not secret vending |
|
||
|
|
| **Claude Code** (MCP when available) | domain summary for workplans; **still** use `warden route` for credential ownership |
|
||
|
|
| **llm-connect** | Never put secret retrieval in prompts |
|
||
|
|
|
||
|
|
### Quick routing table
|
||
|
|
|
||
|
|
| I need… | Owner | ops-warden executes? |
|
||
|
|
| --- | --- | --- |
|
||
|
|
| SSH cert (`adm`/`agt`/`atm`) | ops-warden | **Yes** — `warden sign` |
|
||
|
|
| API key, DB password, provider token | OpenBao | No — route only |
|
||
|
|
| Login / OIDC / MFA | key-cape | No — route only |
|
||
|
|
| Authorization decision | access-engine (`flex-auth`) | No — route only |
|
||
|
|
| Approval current-state | **this engine** (not yet implemented) | No |
|
||
|
|
| SSH tunnel | ops-bridge | No — route only |
|
||
|
|
|
||
|
|
### Anti-patterns
|
||
|
|
|
||
|
|
- Asking State Hub or `ops-warden` to vend a secret
|
||
|
|
- Pasting secrets into Git, State Hub, workplans, logs, or chat
|
||
|
|
- Treating a callable tool as permission (companion §7)
|
||
|
|
|
||
|
|
**Canon:** `~/ops-warden/wiki/CredentialRouting.md`
|
||
|
|
|
||
|
|
<!-- REPO-AGENTS-EXTENSIONS -->
|
||
|
|
<!-- Append repo-specific agent instructions below this marker.
|
||
|
|
The state-hub template sync preserves content after this line. -->
|
||
|
|
|
||
|
|
## This repository's layer
|
||
|
|
|
||
|
|
Engine, role **PIP**. Statute v0.7, companion v0.2. Declaration: `INTENT.md`
|
||
|
|
frontmatter and `layer.yaml`.
|
||
|
|
|
||
|
|
- Answer "is this approval valid for this exact binding, and has it been used?"
|
||
|
|
Never "may this actor do X".
|
||
|
|
- Do not implement consumption until `GH-WP-0002-T06` / `APPROVAL-WP-0001-T05`
|
||
|
|
settles the contract with `access-engine`.
|
||
|
|
- The outbox is local. Do not emit synchronously to `audit-core` inside a
|
||
|
|
mutation transaction.
|
||
|
|
- Approval evidence is load-bearing. Atomicity covers crash, not compromise.
|
||
|
|
- An approval is not a Railiance workload.
|
||
|
|
- Remote hub: this host reaches State Hub on `http://127.0.0.1:8000` (primary
|
||
|
|
on railiance01). Do not use `127.0.0.1:18000` — that reverse tunnel is being
|
||
|
|
retired (`CUST-WP-0067`).
|
||
|
|
|
||
|
|
---
|
||
|
|
|
||
|
|
## Workplan Convention (ADR-001)
|
||
|
|
|
||
|
|
Work items originate as files in this repo — not in the hub. The hub is a
|
||
|
|
read/cache/index layer that rebuilds from files.
|
||
|
|
|
||
|
|
**File location:** `workplans/APPROVAL-WP-NNNN-<slug>.md`
|
||
|
|
|
||
|
|
**Archived location:** finished workplans may move to
|
||
|
|
`workplans/archived/YYMMDD-APPROVAL-WP-NNNN-<slug>.md`. The `YYMMDD` prefix is
|
||
|
|
the completion/archive date; the frontmatter `id` does not change.
|
||
|
|
|
||
|
|
**Ad Hoc Tasks:** small opportunistic fixes discovered during a session use
|
||
|
|
`workplans/ADHOC-YYYY-MM-DD.md`, workplan id
|
||
|
|
`APPROVAL-WP-ADHOC-YYYY-MM-DD`, and task ids
|
||
|
|
`APPROVAL-WP-ADHOC-YYYY-MM-DD-T01`, etc. `APPROVAL-WP` includes its final `-WP`
|
||
|
|
token. Unqualified historic `ADHOC-*` ids are grandfathered and must not be
|
||
|
|
copied into new records. Use this only for low-risk work completed directly;
|
||
|
|
create a normal workplan for anything needing analysis, design, approval,
|
||
|
|
dependencies, or multiple phases.
|
||
|
|
|
||
|
|
**Frontmatter:**
|
||
|
|
|
||
|
|
```yaml
|
||
|
|
---
|
||
|
|
id: APPROVAL-WP-NNNN
|
||
|
|
type: workplan
|
||
|
|
title: "..."
|
||
|
|
domain: infotech
|
||
|
|
repo: approval-engine
|
||
|
|
status: proposed | ready | active | blocked | backlog | finished | archived
|
||
|
|
owner: codex
|
||
|
|
topic_slug: ...
|
||
|
|
created: "YYYY-MM-DD"
|
||
|
|
updated: "YYYY-MM-DD"
|
||
|
|
state_hub_workstream_id: "<uuid>" # fix-consistency — do not edit (legacy field name; workplan UUID)
|
||
|
|
---
|
||
|
|
```
|
||
|
|
|
||
|
|
Use `proposed` for a new draft, `ready` after review against current repo
|
||
|
|
state, and `finished` after implementation. `stalled` and `needs_review` are
|
||
|
|
derived health labels, not frontmatter statuses.
|
||
|
|
|
||
|
|
**Terminology:** workplan is the fleet term; `workstream` appears only in legacy
|
||
|
|
API/MCP/frontmatter bridges until `STATE-WP-0069` retires them — see
|
||
|
|
`the-custodian/canon/standards/workplan-terminology-fleet_v0.1.md`.
|
||
|
|
|
||
|
|
**Task block format** (one per `##` section):
|
||
|
|
|
||
|
|
```
|
||
|
|
## Task Title
|
||
|
|
|
||
|
|
` ` `task
|
||
|
|
id: APPROVAL-WP-NNNN-T01
|
||
|
|
status: wait | todo | progress | done | cancel
|
||
|
|
priority: high | medium | low
|
||
|
|
state_hub_task_id: "<uuid>" # written by fix-consistency — do not edit
|
||
|
|
` ` `
|
||
|
|
|
||
|
|
Task description text.
|
||
|
|
```
|
||
|
|
|
||
|
|
Status progression: `todo` → `progress` → `done`; use `wait` for waiting/blocked work and `cancel` for stopped work.
|
||
|
|
|
||
|
|
**Residuals when finishing:** actionable leftovers become live work records
|
||
|
|
before `status: finished` — usually an intake (`origin: residual`,
|
||
|
|
`origin_ref: APPROVAL-WP-NNNN`) or a spawned workplan. Residual is a *role*,
|
||
|
|
not a kind. Fleet list lives on State Hub, not in `SCOPE.md`.
|
||
|
|
|
||
|
|
To create a new workplan:
|
||
|
|
1. Write the file following the format above
|
||
|
|
2. Run `statehub fix-consistency` locally.
|
||
|
|
3. On a non-registrar C-06/C-11 skip, use the repo-manager fallback documented
|
||
|
|
above exactly once; never set registrar authority directly.
|