Skip to content

autonomy: third-party tracker text has no author-trust axis and is carved out of the untrusted-provenance class #1714

Description

@kyle-sexton

This was generated by AI while filing the follow-ups handed over by the #1657 design audit.

Context

Whether an externally-filed issue reaches the untrusted-provenance work class is unspecified. The
governing prose arguably covers it, but the executable tests for that class read pull-request fields an
issue does not have, and plugins/autonomy/reference/routines.md affirmatively carves third-party text
already inside the org's own tracker out of the provenance trigger, deferring it to admission instead.
Admission's own axes encode neither author trust nor content trust, so the deferral target does not
implement the control the carve-out defers to it. The same carve-out is repeated verbatim across five
sibling routines, leaving the org's own issue-triage routine deriving the lowest class in the taxonomy
while a routine reading a vendor changelog derives the highest.

Citations for both halves, and the five routines, are in the #1657 design audit — see
the determination comment
(gaps G2 and G3, follow-up 3). Not restated here.

Proposed work

  • Decide the question one way and record the decision: either give admission-policy.md an author-trust
    axis so "admission-governed" is a real deferral target, or drop the routines.md carve-out so
    third-party tracker text derives the untrusted-provenance class the way external changelog prose
    already does.
  • Re-derive the affected routine rows from whichever answer lands, rather than leaving them at their
    current class by inertia.

Acceptance criteria

  • One of the two options is chosen and written down with its rationale in the surface that owns it
    (plugins/autonomy/reference/guardrails/admission-policy.md or
    plugins/autonomy/reference/routines.md), so a classifier no longer has to guess.
  • The chosen answer removes the contradiction: the carve-out and its deferral target can be read
    together without one pointing at a control the other does not have.
  • The five sibling routines that repeat the carve-out verbatim (issue-triage-sweep,
    backlog-readiness-check, duplicate-detection-sweep, pr-queue-tending, doc-freshness-sweep)
    each have their derived work class and isolation floor re-derived under the new answer — updated
    where the answer changes them, explicitly confirmed where it does not.
  • The asymmetry the audit names (tracker prose vs. external changelog prose) is either eliminated or
    justified in writing.

References

Metadata

Field Value
Category autonomy / guardrails
Area security
Ecosystem markdown

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    needs-humanHuman-in-the-loop required; autonomous sessions must not resolve items carrying this.priority: highSignificant impact, or blocks an imminent release; staff this cycle.status: needs-decisionAwaiting a human or maintainer judgment call.work-class: structuralRefactors, migrations, contract changes; cross-cutting and hard to reverse.

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions