policy: govern grapharc agent by policy document - #131
Open
DhineshPonnarasan wants to merge 1 commit into
Open
DhineshPonnarasan wants to merge 1 commit into
DhineshPonnarasan wants to merge 1 commit into
Conversation
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Closes #6.
This wires policy documents into the
grapharc agenttool-execution path so--policy <doc.toml>governs the samePermissionPolicyboundary consumed by the agent harness.What changed
Load a
PolicyDocumentfrom--policyand compile it throughPolicyEngine.permission_policy().Combine document policy with CLI
--allow/--deny/--askrestrictions using a fail-closed, most-restrictive composition:DENY > ASK > ALLOWdeny.Propagate the selected tenant into policy evaluation and reject undeclared tenants.
Route document
askdecisions through the existing approval boundary.Fail closed for document
askwhen running non-interactively / with JSON output.Preserve policy provenance including source, version, digest, tenant, and audit information.
Record document-driven denials in the policy audit path while retaining run-trace visibility.
Prevent policy-bearing runs from bypassing the governed path through
claude-clidelegation.Keep denied tools out of the model-visible tool set.
Add focused tests covering policy composition, tenant handling, approval behavior, audit/provenance, denied-tool visibility, and end-to-end CLI behavior.
Design
The policy flow is:
PolicyDocument → PolicyEngine → PermissionPolicy → Harness/AgentNodeThere is one permission boundary rather than a second policy engine in the CLI.
The document is the authority ceiling. CLI restrictions may make that ceiling narrower, but an
--allowflag cannot widen authority granted by the document.Verification
uv run ruff check .— passedgit diff --check— passed (Windows emitted only LF→CRLF warnings)The full test suite was also exercised on Windows. The remaining failures are environment/platform-related and pre-existing to this change, including sandbox
forkbehavior on Windows, missingclaudeCLI/provider environment, Windows symlink privileges, and platform-specific timing behavior. No silent platform fallback was introduced to mask those failures.Scope
This PR intentionally does not modify the README, roadmap, cookbook, or deep-dive documentation. The implementation is limited to the policy/harness/CLI integration and its tests.