You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Parent Epic: #184
Execution mode: implementation
VNext programme: #333
Depends on: #186, #188, #337
Consumed by: #340, #343, #190, #191
Future scheduled-proof consumer: #356 — not a dependency of #189.
Problem Statement
Forge already records canonical outcomes and capability reliability evidence, but it does not yet have one deterministic policy engine that converts sufficiently comparable independently verified history into a narrowly scoped autonomy ceiling. The old Project-centric wording is too narrow for VNext, while a global agent/model trust score would be unsafe: it would ignore Resource scope, Operation risk, package/runtime/model changes, evidence freshness and critical failures.
Desired Outcome
Forge evaluates versioned earned-autonomy policy for a precise cohort — Principal/Workforce role + Capability/Operation + Resource scope + runtime/model/harness/package/policy lineage — and produces immutable promotion/hold/demotion/revocation decisions. The decision is a ceiling only: system security, MCP admission, #336 confinement/Grant policy, Resource rules and explicit human limits can always impose stricter authority.
Every decision is deterministic, replayable and explainable from stored evidence. The evaluator consumes generic verified failure/proof evidence contracts and can close before recurring proof scheduling (#356) exists; scheduled proofs feed the same evidence path later.
User Story
As the Forge operator,
I want reliable narrowly scoped capabilities to earn lower-friction execution while immediately losing that privilege when evidence deteriorates,
So that autonomy grows from verified behavior without turning any agent/model into a broadly trusted actor.
Requirements
A. Policy/cohort identity
A versioned autonomy policy must bind at least:
policy id/version;
Workforce/package/workflow/harness lineage where applicable;
current operator ceiling and absolute system maximum;
minimum comparable sample count;
rolling evidence window/freshness;
verified-pass/promotion and demotion thresholds;
critical-failure/violation overrides;
requalification rules after material lineage/scope changes;
expiry/review policy.
Do not key authority to agentType or model name alone.
B. Autonomy ladder
Support an initial generic policy ladder:
L0 — plan/request only;
L1 — execute typed Operation in confinement after explicit approval;
L2 — bounded low-risk Operation may execute, human reviews result;
L3 — may create a branch/draft PR after required independent verification;
L4 — may open/update ready-for-review PR after required verification;
L5 — reserved for specifically defined reversible Operations; never a generic auto-merge level.
Levels are policy conveniences over explicit Capabilities, not magic permission bundles. The effective Grant must still be calculated per Operation/Resource.
C. Evidence eligibility
Promotion may consume only comparable #186 evidence whose required #188 independent verification/Gate state is valid. Exclude or hold on:
worker self-assessment/unverified success;
missing/tampered/stale evidence;
incompatible Resource scope;
changed Operation definition/risk semantics;
material package/workflow/harness/runtime/model/policy change outside configured compatibility;
Given the same policy version + evidence snapshot, evaluation must produce the same result and stable reason codes. Persist the exact evidence IDs/cohort snapshot and thresholds used. No LLM or model confidence may decide promotion/demotion.
Required results include at least promote | hold | maintain | demote | revoke | expired/requalification_required.
E. Immediate revocation/demotion
Independent of aggregate success percentage, policy can immediately demote/revoke for:
material scope/Operation/security-contract change;
repeated bounded remediation failure according to policy.
Revocation affects new admission immediately; queued stale work must fail its current authority check.
F. Human authority
Operator-set cap/revoke decisions always dominate automated promotion. An operator may deliberately lower a ceiling without deleting evidence. Raising beyond policy/system maxima is impossible; an explicit reviewed policy change is required.
Record actor, reason and audit evidence for every human override.
G. Effective authority calculation
Before every privileged Operation/admission, calculate the intersection/minimum of:
An autonomy decision never creates a Capability that the parent Mission/Resource does not already permit.
H. Persistence
Persist immutable evaluation decisions/evidence snapshots. A rebuildable current-state projection may point to the latest applicable decision, but history is append-only. Use database ordering/version identity rather than timestamps alone for precedence where races matter.
I. Advisory rollout
Implement evaluation in dry-run/advisory mode first. Compare proposed decisions to existing human gates without changing admission. Only enable enforcement after mutation/race/replay/security review and explicit migration state proves current decisions are valid.
J. Enforcement integration
Enforce effective autonomy at the common admission boundary before:
Fail closed if policy/current decision/evidence cannot be loaded when a higher autonomy level is required.
K. Future scheduled-proof compatibility
Define one generic proof-failure/evidence input contract that #355 fixtures can exercise now and #356 can emit later. #189 must not import #356 modules, wait for Trigger scheduling, or encode schedule-specific semantics. Its only concern is the verified evidence identity, comparability, severity/failure class, freshness and policy scope.
Implementation Sequence
Policy + cohort schemas — versioned explicit identities, no enforcement.
Worker self-assessment/unverified successes do not count as verified passes.
Missing/stale/tampered/incompatible evidence causes hold/requalification, never promotion.
A critical failure/security violation/rollback/required deterministic proof failure can demote or revoke immediately regardless of aggregate percentage.
Very Large / trust-critical - expected as 6-9 small PRs, with advisory mode and replayable evaluator isolated before enforcement.
Technical Notes
Do not hard-code illustrative percentages into architecture. Seed conservative versioned defaults by risk class, but treat policy values as explicit reviewed configuration whose changes trigger new decision lineage. The autonomy engine should understand evidence, not how that evidence happened to be scheduled.
Parent Epic: #184
Execution mode: implementation
VNext programme: #333
Depends on: #186, #188, #337
Consumed by: #340, #343, #190, #191
Future scheduled-proof consumer: #356 — not a dependency of #189.
Problem Statement
Forge already records canonical outcomes and capability reliability evidence, but it does not yet have one deterministic policy engine that converts sufficiently comparable independently verified history into a narrowly scoped autonomy ceiling. The old Project-centric wording is too narrow for VNext, while a global agent/model trust score would be unsafe: it would ignore Resource scope, Operation risk, package/runtime/model changes, evidence freshness and critical failures.
Desired Outcome
Forge evaluates versioned earned-autonomy policy for a precise cohort — Principal/Workforce role + Capability/Operation + Resource scope + runtime/model/harness/package/policy lineage — and produces immutable promotion/hold/demotion/revocation decisions. The decision is a ceiling only: system security, MCP admission, #336 confinement/Grant policy, Resource rules and explicit human limits can always impose stricter authority.
Every decision is deterministic, replayable and explainable from stored evidence. The evaluator consumes generic verified failure/proof evidence contracts and can close before recurring proof scheduling (#356) exists; scheduled proofs feed the same evidence path later.
User Story
As the Forge operator,
I want reliable narrowly scoped capabilities to earn lower-friction execution while immediately losing that privilege when evidence deteriorates,
So that autonomy grows from verified behavior without turning any agent/model into a broadly trusted actor.
Requirements
A. Policy/cohort identity
A versioned autonomy policy must bind at least:
Do not key authority to
agentTypeor model name alone.B. Autonomy ladder
Support an initial generic policy ladder:
L0— plan/request only;L1— execute typed Operation in confinement after explicit approval;L2— bounded low-risk Operation may execute, human reviews result;L3— may create a branch/draft PR after required independent verification;L4— may open/update ready-for-review PR after required verification;L5— reserved for specifically defined reversible Operations; never a generic auto-merge level.Levels are policy conveniences over explicit Capabilities, not magic permission bundles. The effective Grant must still be calculated per Operation/Resource.
C. Evidence eligibility
Promotion may consume only comparable #186 evidence whose required #188 independent verification/Gate state is valid. Exclude or hold on:
Unknown evidence does not count as a pass.
D. Deterministic evaluation
Given the same policy version + evidence snapshot, evaluation must produce the same result and stable reason codes. Persist the exact evidence IDs/cohort snapshot and thresholds used. No LLM or model confidence may decide promotion/demotion.
Required results include at least
promote | hold | maintain | demote | revoke | expired/requalification_required.E. Immediate revocation/demotion
Independent of aggregate success percentage, policy can immediately demote/revoke for:
Revocation affects new admission immediately; queued stale work must fail its current authority check.
F. Human authority
Operator-set cap/revoke decisions always dominate automated promotion. An operator may deliberately lower a ceiling without deleting evidence. Raising beyond policy/system maxima is impossible; an explicit reviewed policy change is required.
Record actor, reason and audit evidence for every human override.
G. Effective authority calculation
Before every privileged Operation/admission, calculate the intersection/minimum of:
An autonomy decision never creates a Capability that the parent Mission/Resource does not already permit.
H. Persistence
Persist immutable evaluation decisions/evidence snapshots. A rebuildable current-state projection may point to the latest applicable decision, but history is append-only. Use database ordering/version identity rather than timestamps alone for precedence where races matter.
I. Advisory rollout
Implement evaluation in dry-run/advisory mode first. Compare proposed decisions to existing human gates without changing admission. Only enable enforcement after mutation/race/replay/security review and explicit migration state proves current decisions are valid.
J. Enforcement integration
Enforce effective autonomy at the common admission boundary before:
Fail closed if policy/current decision/evidence cannot be loaded when a higher autonomy level is required.
K. Future scheduled-proof compatibility
Define one generic proof-failure/evidence input contract that #355 fixtures can exercise now and #356 can emit later. #189 must not import #356 modules, wait for Trigger scheduling, or encode schedule-specific semantics. Its only concern is the verified evidence identity, comparability, severity/failure class, freshness and policy scope.
Implementation Sequence
Primary Code Seams To Inspect First
Do not import future #356 Trigger/scheduling code into the autonomy engine.
Orthogonal Checkpoints
Acceptance Criteria
Out of Scope
Implementation Scope
Very Large / trust-critical - expected as 6-9 small PRs, with advisory mode and replayable evaluator isolated before enforcement.
Technical Notes
Do not hard-code illustrative percentages into architecture. Seed conservative versioned defaults by risk class, but treat policy values as explicit reviewed configuration whose changes trigger new decision lineage. The autonomy engine should understand evidence, not how that evidence happened to be scheduled.