Repository navigation
Using Agentic Process Evidence with OpenShell #4238
Replies: 1 comment 1 reply
|
Proposal: reference policy pack — 17 intents, 4 tiers, signed work orders (Intent Rules v1.0.0) Body: Intent Rules v1.0.0: 17 intents across four tiers (read-only, state-changing, financial, founder-only admin), four agent roles with bounded authority, signed versioned work orders per consequential action, five verifier questions answered pre-execution, deny-by-default, append-only audit. Ships as declarative YAML — the same shape as OpenShell policy. Mapping: our YAML drops into the declarative policy format; the five verifier questions extend the policy prover's 'never grants more than intended' check to per-action runtime decisions; our short-lived capability tokens mirror the credential-brokering model. The 2-page brief: [paste your GitHub release URL]. Happy to adapt the schema or co-develop the mapping. What would make this useful to the project? |
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
We have been looking at running Agentic Process Evidence (APE) on agents that run in OpenShell, and we would like to know how this sits with you before we open a feature request.
OpenShell provides extensive protection via its sandboxing and proxy policies. This approach gives high level of control for the category of issues that can be caught on an event scale misalignment. Some policies/cases in agentic control can be aligned on an event based view and the misaligned as a whole, examples of such policies:
These policies needs to be checked on the sandbox lifetime, aggregating multiple single events into sessions, that can be gated in realtime or async. A baseline approach is to define an "agentic process" boundaries with respect to the sandbox lifetime and its tasks. The baseline approach gives us for example the ability to map SDLC steps (such as commits) to the thought process, decisions and risks introduced by the agentic sessions that ran in OpenShell.
APE lets us govern an agentic process with evidence and process-aware logging, and use contextual policies to manage the agentic process as a whole.
main integration use cases
Single process per sandbox and multiple processes per sandbox
OpenShell responsibility
Single process per sandbox
for example, code review agent spun up with a single commit to review
Multiple processes per sandbox
for example, coding agent spun up and is continuously triggered with tickets
APE responsibility
All reactions