feat(WARDEN-WP-0020): conservative triage tier as the --execute default (Option A)
Per Bernd's call: the guardrails prevent security harm but not LLM content errors, so the worker should triage + draft, not auto-send, until reply quality is proven (matches the build-stage/recoverability posture). run_conservative triages NEW messages into a reviewed digest (state_dir/worker-digest.md) with drafted replies, posts ONE progress note, tracks seen message ids (schedule-safe dedup), and sends NOTHING to other agents / marks nothing read. `warden worker run --execute` now runs this conservative tier; `--full-auto` opts into the auto-send path. Live-verified with the LLM brain on the real inbox: produced a high-quality draft reply to a secrets-engine coordination message and correctly flagged the llm-connect custody request as NEEDS YOU. Conservative mode is safe to schedule (T4). 244 tests, lint clean. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
parent
a55b3b7735
commit
d0261ebb52
4 changed files with 137 additions and 12 deletions
|
|
@ -1164,15 +1164,21 @@ def worker_run(
|
|||
str,
|
||||
typer.Option("--brain", help="Planner: 'rule' (deterministic, default) or 'llm' (llm-connect)"),
|
||||
] = "rule",
|
||||
full_auto: Annotated[
|
||||
bool,
|
||||
typer.Option("--full-auto", help="With --execute: auto-send replies + mark-read (default is conservative: triage + drafts only)"),
|
||||
] = False,
|
||||
) -> None:
|
||||
"""Read ops-warden's unread coordination requests and render a guardrailed plan.
|
||||
"""Read ops-warden's unread coordination requests and act on them, guardrailed.
|
||||
|
||||
Plans with the deterministic RuleBrain (default) or the llm-connect brain (--brain llm).
|
||||
Either way the allowlist + no-secret guardrails are enforced on every action. --execute
|
||||
is rejected until the guarded executor (T3) ships; dry-run is the default.
|
||||
Default `--dry-run` previews. `--execute` runs the **conservative** tier: triage new
|
||||
messages into a reviewed digest with drafted replies, post one progress note, and send
|
||||
NOTHING to other agents (safe to schedule). `--execute --full-auto` auto-sends the safe
|
||||
allowlisted actions. The allowlist + no-secret guardrails hold in every mode.
|
||||
"""
|
||||
from warden.worker import (
|
||||
HubClient, LlmConnectBrain, RuleBrain, build_plans, execute_plans, render_plans,
|
||||
run_conservative,
|
||||
)
|
||||
|
||||
if brain not in ("rule", "llm"):
|
||||
|
|
@ -1198,7 +1204,11 @@ def worker_run(
|
|||
)
|
||||
return
|
||||
|
||||
# --execute: run the guarded executor. Topic for audit progress events.
|
||||
# --execute. Topic for audit progress events.
|
||||
topic_id = "cee7bedf-2b48-46ef-8601-006474f2ad7a"
|
||||
console.print("[yellow]Executing (full-auto, in-scope only; escalations left for a human)…[/yellow]")
|
||||
console.print(execute_plans(plans, hub, topic_id=topic_id))
|
||||
if full_auto:
|
||||
console.print("[yellow]Executing FULL-AUTO (in-scope only; escalations left for a human)…[/yellow]")
|
||||
console.print(execute_plans(plans, hub, topic_id=topic_id))
|
||||
else:
|
||||
console.print("[green]Conservative triage[/green] — drafting; nothing sent to other agents.")
|
||||
console.print(run_conservative(plans, hub, topic_id=topic_id))
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue