Skip to content
M31A

11-Stage Policy Gate

Security governance, 10-tier authority stack, and monotonic merger rules.


The M31A policy engine enforces deterministic governance over all side effects (file mutations, child processes, Git operations, and network requests).

The 4 Policy Outcomes

ALLOW
Permitted unconditionally within sandbox bounds.
DENY
Forbidden fail-closed with zero side effects.
ASK
Requires human operator authorization. Unattended = DENY.
ESCALATE
Requires administrative consent or halts mission.

10-Tier Authority Precedence Stack

Layer 0: BuiltInSafety (Hardcoded immutable safety vetoes)
↓
Layer 1: SystemAdmin (/etc/m31/policy.toml)
↓
Layer 2: Organization (Enterprise compliance rules)
↓
Layer 3: Workspace (<workspace>/.m31/policy.toml)
↓
Layer 4: User (~/.config/m31/policy.toml)
↓
Layer 5: Mission (Mission-specific policy constraints)
↓
Layer 6: AgentRole (Role-based boundary limits)
↓
Layer 7: Task (Task-specific scope restrictions)
↓
Layer 8: SessionApproval (Durable SQLite policy_grants from user prompts)
↓
Layer 9: DeveloperDefault (Sensible baseline engineering fallbacks)

Monotonic Non-Weakening Merger Rule

When rules from multiple layers match a proposed action, higher authority always wins. A DENY decision at any higher layer completely overrides an ALLOW or ASK at lower layers. Lower layers can only narrow scopes — never expand permissions.

Layer 0 Built-in Safety Vetoes

The following operations can never be permitted by any configuration or session grant:

  • • Access to credentials (**/.ssh/**, **/.aws/**, **/.env*, **/*id_rsa*)
  • • OS tampering (/etc/sudoers*, /etc/shadow, /etc/m31/**)
  • • Shell profile modifications (**/.bashrc, **/.zshrc, /etc/profile)
  • • Destructive disk commands (rm -rf /, mkfs*, dd if=*)