Skip to content

Third-party autonomy & security governance spec #4782

Description

@JSONbored

Problem: Running full merge/close/label authority unattended on a paying customer's repository is a materially higher trust boundary than reviewing gittensory's own backlog, and no governance model exists for it yet.

Area: Product spec / safety

Proposal: Define a customer-scoped version of the existing graduated autonomy dial, a hard kill-switch, and an audit-trail requirement for any rented loop acting on a third-party repository. Explicitly define what "full autonomy" is allowed to mean for a rented loop (it should never default to unattended merge authority without an explicit, informed customer opt-in) and precisely what state a loop is left in when the kill-switch is pulled mid-run.

Deliverables:

  • A written governance spec covering autonomy levels, kill-switch behavior, and audit-trail requirements.

Acceptance criteria:

  • Spec explicitly states the default (most conservative) autonomy level for a newly rented loop.
  • Kill-switch behavior is specified precisely enough to be testable (Incident runbook for the kill-switch #4809 tests against it directly).

Resources:

  • The existing per-repo autonomy-level mechanism used for review/merge authority today.

Boundaries:

  • Spec only. Do not wire real unattended merge authority for third-party repos until this spec is approved and Miner Wave 3's safety-governor enforcement (tracked separately) has actually landed.

Part of #4778.

Metadata

Metadata

Assignees

Labels

maintainer-onlyOwner-only work — yields no Gittensor points.roadmapOn the Wave-2 agent-layer roadmap board (project 9)

Projects

Status
Done

Relationships

None yet

Development

No branches or pull requests

Issue actions