Skip to content

[FEATURE] Add evidence-based earned autonomy policy engine #189

Description

@Joncallim

Parent Epic: #184
Execution mode: implementation
VNext programme: #333
Depends on: #186, #188, #337
Consumed by: #340, #343, #190, #191
Future scheduled-proof consumer: #356 — not a dependency of #189.

Problem Statement

Forge already records canonical outcomes and capability reliability evidence, but it does not yet have one deterministic policy engine that converts sufficiently comparable independently verified history into a narrowly scoped autonomy ceiling. The old Project-centric wording is too narrow for VNext, while a global agent/model trust score would be unsafe: it would ignore Resource scope, Operation risk, package/runtime/model changes, evidence freshness and critical failures.

Desired Outcome

Forge evaluates versioned earned-autonomy policy for a precise cohort — Principal/Workforce role + Capability/Operation + Resource scope + runtime/model/harness/package/policy lineage — and produces immutable promotion/hold/demotion/revocation decisions. The decision is a ceiling only: system security, MCP admission, #336 confinement/Grant policy, Resource rules and explicit human limits can always impose stricter authority.

Every decision is deterministic, replayable and explainable from stored evidence. The evaluator consumes generic verified failure/proof evidence contracts and can close before recurring proof scheduling (#356) exists; scheduled proofs feed the same evidence path later.

User Story

As the Forge operator,
I want reliable narrowly scoped capabilities to earn lower-friction execution while immediately losing that privilege when evidence deteriorates,
So that autonomy grows from verified behavior without turning any agent/model into a broadly trusted actor.

Requirements

A. Policy/cohort identity

A versioned autonomy policy must bind at least:

  • policy id/version;
  • Workforce/package/workflow/harness lineage where applicable;
  • Capability and Operation id/version;
  • normalized Resource scope fingerprint/classification;
  • risk class;
  • runtime/provider/model compatibility rules;
  • current operator ceiling and absolute system maximum;
  • minimum comparable sample count;
  • rolling evidence window/freshness;
  • verified-pass/promotion and demotion thresholds;
  • critical-failure/violation overrides;
  • requalification rules after material lineage/scope changes;
  • expiry/review policy.

Do not key authority to agentType or model name alone.

B. Autonomy ladder

Support an initial generic policy ladder:

  • L0 — plan/request only;
  • L1 — execute typed Operation in confinement after explicit approval;
  • L2 — bounded low-risk Operation may execute, human reviews result;
  • L3 — may create a branch/draft PR after required independent verification;
  • L4 — may open/update ready-for-review PR after required verification;
  • L5 — reserved for specifically defined reversible Operations; never a generic auto-merge level.

Levels are policy conveniences over explicit Capabilities, not magic permission bundles. The effective Grant must still be calculated per Operation/Resource.

C. Evidence eligibility

Promotion may consume only comparable #186 evidence whose required #188 independent verification/Gate state is valid. Exclude or hold on:

  • worker self-assessment/unverified success;
  • missing/tampered/stale evidence;
  • incompatible Resource scope;
  • changed Operation definition/risk semantics;
  • material package/workflow/harness/runtime/model/policy change outside configured compatibility;
  • unresolved critical findings/rollbacks/security violations.

Unknown evidence does not count as a pass.

D. Deterministic evaluation

Given the same policy version + evidence snapshot, evaluation must produce the same result and stable reason codes. Persist the exact evidence IDs/cohort snapshot and thresholds used. No LLM or model confidence may decide promotion/demotion.

Required results include at least promote | hold | maintain | demote | revoke | expired/requalification_required.

E. Immediate revocation/demotion

Independent of aggregate success percentage, policy can immediately demote/revoke for:

Revocation affects new admission immediately; queued stale work must fail its current authority check.

F. Human authority

Operator-set cap/revoke decisions always dominate automated promotion. An operator may deliberately lower a ceiling without deleting evidence. Raising beyond policy/system maxima is impossible; an explicit reviewed policy change is required.

Record actor, reason and audit evidence for every human override.

G. Effective authority calculation

Before every privileged Operation/admission, calculate the intersection/minimum of:

An autonomy decision never creates a Capability that the parent Mission/Resource does not already permit.

H. Persistence

Persist immutable evaluation decisions/evidence snapshots. A rebuildable current-state projection may point to the latest applicable decision, but history is append-only. Use database ordering/version identity rather than timestamps alone for precedence where races matter.

I. Advisory rollout

Implement evaluation in dry-run/advisory mode first. Compare proposed decisions to existing human gates without changing admission. Only enable enforcement after mutation/race/replay/security review and explicit migration state proves current decisions are valid.

J. Enforcement integration

Enforce effective autonomy at the common admission boundary before:

Fail closed if policy/current decision/evidence cannot be loaded when a higher autonomy level is required.

K. Future scheduled-proof compatibility

Define one generic proof-failure/evidence input contract that #355 fixtures can exercise now and #356 can emit later. #189 must not import #356 modules, wait for Trigger scheduling, or encode schedule-specific semantics. Its only concern is the verified evidence identity, comparability, severity/failure class, freshness and policy scope.

Implementation Sequence

  1. Policy + cohort schemas — versioned explicit identities, no enforcement.
  2. Evidence eligibility selector — [FEATURE] Add capability reliability ledger #186/[FEATURE] Add independent Verification Workforce execution #188 comparison/freshness/incompatibility matrix.
  3. Pure deterministic evaluator — stable reason codes and replay fixtures.
  4. Immutable decisions + current projection — concurrent evaluation/precedence tests.
  5. Human cap/revoke APIs — audited lower-only authority changes.
  6. Dry-run/advisory integration — compare against current gates on Phase-3 fixtures.
  7. Effective-authority calculator — intersection of system/Grant/Resource/autonomy/operator/budget ceilings.
  8. Admission enforcement — Phase-3 branch/PR and confined low-risk Operation fixtures first.
  9. Immediate revocation pipeline — critical finding, generic deterministic proof failure (using [FEATURE] Complete verification-goal on-demand proof execution through VNext #355-compatible fixture), rollback/tamper and queued stale work; no [FEATURE] Schedule verification-goal proof runs through generic Triggers #356 dependency.
  10. Requalification/expiry — package/model/harness/scope/policy changes and evidence aging.
  11. Future-consumer conformance — synthetic scheduled-proof evidence proves the generic contract can later accept [FEATURE] Schedule verification-goal proof runs through generic Triggers #356 output without importing [FEATURE] Schedule verification-goal proof runs through generic Triggers #356.
  12. Race/replay/migration gate — only then permit policy-controlled L2+ behavior.

Primary Code Seams To Inspect First

Do not import future #356 Trigger/scheduling code into the autonomy engine.

Orthogonal Checkpoints

  1. Cohort correctness: Resource/Operation/runtime/model/package/harness scope mixing and false comparability.
  2. Evidence integrity: missing/stale/tampered/unverified successes, rollback/failure attribution.
  3. Policy determinism: replay/mutation tests, thresholds, sample/window boundaries, overflow/rounding.
  4. Authority containment: autonomy tries to create wider Grant/Capability or bypass MCP/security/operator ceiling.
  5. Concurrency/precedence: simultaneous promotion/revoke, stale cached projection, queued work after revocation.
  6. Human override: lower cap, explicit revoke, policy update/requalification and audit lineage.
  7. Enforcement: advisory-vs-live migration, fail-closed missing state, restart/replay.
  8. Dependency isolation: [FEATURE] Add evidence-based earned autonomy policy engine #189 closes with [FEATURE] Schedule verification-goal proof runs through generic Triggers #356 still open; synthetic scheduled-proof evidence exercises only the generic evidence contract.

Acceptance Criteria

Out of Scope

Implementation Scope

Very Large / trust-critical - expected as 6-9 small PRs, with advisory mode and replayable evaluator isolated before enforcement.

Technical Notes

Do not hard-code illustrative percentages into architecture. Seed conservative versioned defaults by risk class, but treat policy values as explicit reviewed configuration whose changes trigger new decision lineage. The autonomy engine should understand evidence, not how that evidence happened to be scheduled.

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    dependency-blockedREADINESS PROJECTION — Issue is blocked by unresolved dependencies. This label is a cache.enhancementNew feature or request

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions