-
-
Notifications
You must be signed in to change notification settings - Fork 89
Third-party autonomy & security governance spec #4782
Copy link
Copy link
Closed
Labels
maintainer-onlyOwner-only work — yields no Gittensor points.Owner-only work — yields no Gittensor points.roadmapOn the Wave-2 agent-layer roadmap board (project 9)On the Wave-2 agent-layer roadmap board (project 9)
Description
Metadata
Metadata
Assignees
Labels
maintainer-onlyOwner-only work — yields no Gittensor points.Owner-only work — yields no Gittensor points.roadmapOn the Wave-2 agent-layer roadmap board (project 9)On the Wave-2 agent-layer roadmap board (project 9)
Projects
StatusShow more project fields
Done
Problem: Running full merge/close/label authority unattended on a paying customer's repository is a materially higher trust boundary than reviewing gittensory's own backlog, and no governance model exists for it yet.
Area: Product spec / safety
Proposal: Define a customer-scoped version of the existing graduated autonomy dial, a hard kill-switch, and an audit-trail requirement for any rented loop acting on a third-party repository. Explicitly define what "full autonomy" is allowed to mean for a rented loop (it should never default to unattended merge authority without an explicit, informed customer opt-in) and precisely what state a loop is left in when the kill-switch is pulled mid-run.
Deliverables:
Acceptance criteria:
Resources:
Boundaries:
Part of #4778.