11-Stage Policy Gate
Security governance, 10-tier authority stack, and monotonic merger rules.
The M31A policy engine enforces deterministic governance over all side effects (file mutations, child processes, Git operations, and network requests).
The 4 Policy Outcomes
ALLOW
Permitted unconditionally within sandbox bounds.
DENY
Forbidden fail-closed with zero side effects.
ASK
Requires human operator authorization. Unattended = DENY.
ESCALATE
Requires administrative consent or halts mission.
10-Tier Authority Precedence Stack
Layer 0: BuiltInSafety (Hardcoded immutable safety vetoes)
↓
Layer 1: SystemAdmin (/etc/m31/policy.toml)
↓
Layer 2: Organization (Enterprise compliance rules)
↓
Layer 3: Workspace (<workspace>/.m31/policy.toml)
↓
Layer 4: User (~/.config/m31/policy.toml)
↓
Layer 5: Mission (Mission-specific policy constraints)
↓
Layer 6: AgentRole (Role-based boundary limits)
↓
Layer 7: Task (Task-specific scope restrictions)
↓
Layer 8: SessionApproval (Durable SQLite policy_grants from user prompts)
↓
Layer 9: DeveloperDefault (Sensible baseline engineering fallbacks)
Monotonic Non-Weakening Merger Rule
When rules from multiple layers match a proposed action, higher authority always wins. A DENY decision at any higher layer completely overrides an ALLOW or ASK at lower layers. Lower layers can only narrow scopes — never expand permissions.
Layer 0 Built-in Safety Vetoes
The following operations can never be permitted by any configuration or session grant:
- • Access to credentials (
**/.ssh/**,**/.aws/**,**/.env*,**/*id_rsa*) - • OS tampering (
/etc/sudoers*,/etc/shadow,/etc/m31/**) - • Shell profile modifications (
**/.bashrc,**/.zshrc,/etc/profile) - • Destructive disk commands (
rm -rf /,mkfs*,dd if=*)