diff --git a/.github/workflows/ttp-governed-pr-action.yml b/.github/workflows/ttp-governed-pr-action.yml new file mode 100644 index 0000000..c5ffc3e --- /dev/null +++ b/.github/workflows/ttp-governed-pr-action.yml @@ -0,0 +1,46 @@ +name: TTP Governed PR Action (Skeleton) + +on: + issue_comment: + types: [created] + +jobs: + governed-action: + if: contains(github.event.comment.body, '/ttp') + runs-on: ubuntu-latest + permissions: + contents: read + pull-requests: write + issues: write + steps: + - uses: actions/checkout@v4 + + - name: Build /re/authorize request context + run: | + echo '{"todo":"collect action, paths, actor, branch, run id"}' > request.json + + - name: Runtime Authority Gate + env: + RUNTIME_AUTH_URL: ${{ secrets.RUNTIME_AUTH_URL }} + RUNTIME_AUTH_TOKEN: ${{ secrets.RUNTIME_AUTH_TOKEN }} + run: | + curl -sS -X POST "$RUNTIME_AUTH_URL/re/authorize" \ + -H "Authorization: Bearer $RUNTIME_AUTH_TOKEN" \ + -H "Content-Type: application/json" \ + -d @request.json > decision.json + cat decision.json + + - name: Enforce decision + run: | + DECISION=$(jq -r '.decision' decision.json) + case "$DECISION" in + PERMIT) echo "execute allowed action" ;; + CONSTRAIN) echo "execute constrained action" ;; + STEP_UP) echo "request human step-up approval" ; exit 1 ;; + ESCALATE) echo "escalate to maintainers/security owners" ; exit 1 ;; + DENY|*) echo "deny action" ; exit 1 ;; + esac + + - name: Persist receipt reference + run: | + jq -r '.receipt.receipt_id' decision.json diff --git a/agents/manifests/role-agents.yaml b/agents/manifests/role-agents.yaml new file mode 100644 index 0000000..bcb4533 --- /dev/null +++ b/agents/manifests/role-agents.yaml @@ -0,0 +1,141 @@ +version: 1 +agents: + - name: Protocol Editor Agent + workload_identity: wi://ttp/github/protocol-editor + purpose: Maintain protocol core text and schemas. + allowed_actions: [issue.comment, pull_request.review, merge recommendation, policy modification request] + forbidden_actions: [release tag request, protected merge approval request] + allowed_paths: [protocol/**, spec/**, rfcs/**] + protected_actions_requiring_step_up: [receipt schema modification request, policy modification request] + minimum_trust_score: 0.90 + freshness_s: 600 + risk_tier: high + compliance_implications: [integrity-control, change-management] + cost_profile: standard + receipt_requirements: [authority_basis, trust_context, risk_posture, compliance_posture, cost_posture, chain_hash] + + - name: Spec & RFC Maintainer Agent + workload_identity: wi://ttp/github/spec-rfc-maintainer + purpose: Curate RFC lifecycle and spec consistency. + allowed_actions: [issue.comment, pull_request.review, label.apply] + forbidden_actions: [workflow modification request, release tag request] + allowed_paths: [rfcs/**, protocol/**, docs/**] + protected_actions_requiring_step_up: [merge to main] + minimum_trust_score: 0.85 + freshness_s: 900 + risk_tier: medium + compliance_implications: [review-evidence] + cost_profile: light + receipt_requirements: [authority_basis, trust_context, github_context] + + - name: Rust Compiler Agent + workload_identity: wi://ttp/github/rust-compiler + purpose: Build/compiler integration and CI runtime checks. + allowed_actions: [workflow.dispatch, issue.comment, pull_request.review] + forbidden_actions: [policy modification request, receipt schema modification request] + allowed_paths: [compiler/**, .github/workflows/**] + protected_actions_requiring_step_up: [workflow modification request] + minimum_trust_score: 0.88 + freshness_s: 300 + risk_tier: high + compliance_implications: [build-integrity] + cost_profile: standard + receipt_requirements: [risk_posture, cost_posture, chain_hash] + + - name: Runtime Systems Agent + workload_identity: wi://ttp/github/runtime-systems + purpose: Maintain runtime authority and verifier paths. + allowed_actions: [pull_request.review, issue.comment, workflow.dispatch] + forbidden_actions: [release tag request] + allowed_paths: [runtime/**, reference-implementations/**] + protected_actions_requiring_step_up: [edits to core runtime authorization behavior, merge to main] + minimum_trust_score: 0.92 + freshness_s: 300 + risk_tier: critical + compliance_implications: [runtime-control, security-review] + cost_profile: heavy + receipt_requirements: [authority_basis, approval_chain, risk_posture, compliance_posture, chain_hash, signature] + + - name: ZK / Proof Systems Agent + workload_identity: wi://ttp/github/zk-proof-systems + purpose: Maintain proof-related semantics and references. + allowed_actions: [issue.comment, pull_request.review] + forbidden_actions: [workflow modification request, release tag request] + allowed_paths: [spec/**, docs/**] + protected_actions_requiring_step_up: [merge to main] + minimum_trust_score: 0.87 + freshness_s: 1200 + risk_tier: medium + compliance_implications: [evidence-quality] + cost_profile: standard + receipt_requirements: [trust_context, risk_posture, github_context] + + - name: Identity / SCIM-RE Architect Agent + workload_identity: wi://ttp/github/scim-re-architect + purpose: Maintain identity and authority-plane mappings. + allowed_actions: [pull_request.review, issue.comment, policy modification request] + forbidden_actions: [release tag request] + allowed_paths: [docs/**, policy/**, spec/**] + protected_actions_requiring_step_up: [policy modification request, receipt schema modification request] + minimum_trust_score: 0.91 + freshness_s: 600 + risk_tier: high + compliance_implications: [identity-governance] + cost_profile: standard + receipt_requirements: [authority_basis, compliance_posture, approval_chain] + + - name: Security Research Agent + workload_identity: wi://ttp/github/security-research + purpose: Analyze threats, controls, and verification logic. + allowed_actions: [issue.comment, pull_request.review, label.apply] + forbidden_actions: [merge to main, release tag request] + allowed_paths: [docs/security.md, protocol/**, reference-implementations/**] + protected_actions_requiring_step_up: [edits to signing, key, or verification paths] + minimum_trust_score: 0.93 + freshness_s: 300 + risk_tier: critical + compliance_implications: [security-review, evidence-retention] + cost_profile: heavy + receipt_requirements: [risk_posture, compliance_posture, chain_hash, signature] + + - name: Agent Framework Integration Agent + workload_identity: wi://ttp/github/framework-integration + purpose: Integrate TTP with agent frameworks and callbacks. + allowed_actions: [issue.comment, pull_request.review, workflow.dispatch] + forbidden_actions: [policy modification request, receipt schema modification request] + allowed_paths: [sdk/**, examples/**, docs/**] + protected_actions_requiring_step_up: [workflow modification request] + minimum_trust_score: 0.84 + freshness_s: 900 + risk_tier: medium + compliance_implications: [integration-evidence] + cost_profile: standard + receipt_requirements: [trust_context, risk_posture, github_context] + + - name: Docs / DX Agent + workload_identity: wi://ttp/github/docs-dx + purpose: Maintain docs quality and contributor experience. + allowed_actions: [issue.comment, pull_request.review, label.apply] + forbidden_actions: [workflow modification request, merge to main, release tag request] + allowed_paths: [docs/**, README.md, CONTRIBUTING.md] + protected_actions_requiring_step_up: [merge recommendation for protected paths] + minimum_trust_score: 0.80 + freshness_s: 1800 + risk_tier: low + compliance_implications: [change-traceability] + cost_profile: light + receipt_requirements: [authority_basis, github_context] + + - name: Standards / Ecosystem Agent + workload_identity: wi://ttp/github/standards-ecosystem + purpose: Coordinate standards-track and ecosystem alignment. + allowed_actions: [issue.comment, pull_request.review, label.apply, merge recommendation] + forbidden_actions: [release tag request] + allowed_paths: [rfcs/**, docs/**, protocol/**] + protected_actions_requiring_step_up: [merge to main, policy modification request] + minimum_trust_score: 0.89 + freshness_s: 1200 + risk_tier: high + compliance_implications: [governance-evidence] + cost_profile: standard + receipt_requirements: [authority_basis, approval_chain, risk_posture, compliance_posture] diff --git a/docs/architecture.md b/docs/architecture.md index 726edfc..17a0d36 100644 --- a/docs/architecture.md +++ b/docs/architecture.md @@ -255,6 +255,18 @@ See [examples/service-integration](../examples/service-integration/) for Kong an --- +## 10. GitHub Self-Governance Extension (TTP Governing TTP) + +TTP can be applied to its own repository operations by treating AI role-agents as governed workload identities and routing meaningful GitHub actions through a Runtime Authority Gate (`POST /re/authorize`) before execution. + +Reference materials: +- [GitHub Self-Governance Reference Architecture](github-self-governance-reference-architecture.md) +- [SCIM-RE Mapping Appendix](scim-re-github-role-agent-mapping.md) +- [ExecutionReceipt schema extension](../spec/extensions/execution-receipt-v2.schema.json) +- [Role-agent manifests](../agents/manifests/role-agents.yaml) + +--- + ## Performance Considerations ### Token Verification Latency diff --git a/docs/github-self-governance-reference-architecture.md b/docs/github-self-governance-reference-architecture.md new file mode 100644 index 0000000..952e818 --- /dev/null +++ b/docs/github-self-governance-reference-architecture.md @@ -0,0 +1,311 @@ +# TTP GitHub Self-Governance Reference Architecture + +## 1. Executive Summary + +TTP GitHub Self-Governance is a protocol extension that applies **trust-before-execution** to AI role-agents operating in GitHub. + +Every meaningful non-human action is gated by a Runtime Authority Gate (`POST /re/authorize`) before execution. The gate computes authority, trust, risk, compliance, and cost in one runtime decision and emits a signed, chain-hashed `ExecutionReceipt`. + +This document specifies the architecture, decision model, policy patterns, and implementation path for using TTP to govern TTP's own repository. + +## 2. Why This Belongs in TTP + +TTP already solves runtime trust for autonomous actors. GitHub development workflows are high-impact execution surfaces for non-human identities. Governing repository actions with TTP is a natural extension of protocol scope because: + +- identity alone is insufficient for sensitive repo actions, +- policy and trust must be evaluated at execution time, +- governance evidence must be cryptographically auditable. + +This is protocol infrastructure, not bot automation. + +## 3. Protocol Extension: GitHub Self-Governance + +### 3.1 New governed surface + +Governed actions include: +- issue and PR interaction actions, +- workflow dispatch and workflow modifications, +- merge/release recommendations and approvals, +- policy and receipt-model modifications. + +### 3.2 Runtime Authority Gate + +All meaningful actions MUST call: + +`POST /re/authorize` + +Inputs: +- subject workload identity, +- requested action/resource, +- repo context (branch, paths, commit SHA, workflow run id), +- current trust and attestation state, +- active grants and constraints. + +Outputs: +- decision outcome (`PERMIT`, `CONSTRAIN`, `STEP_UP`, `ESCALATE`, `DENY`), +- constraints/step-up requirements, +- signed `ExecutionReceipt`. + +## 4. SCIM-RE Resource Mapping for Role-Agents + +GitHub Self-Governance uses SCIM-RE authority-plane resources without changing provisioning semantics: + +- **WorkloadIdentity**: AI role-agent identity (GitHub App / workflow-bound actor) +- **AuthorityGrant**: time-bounded, trust-conditioned permission envelope +- **Attestation**: freshness/legitimacy proof at action time +- **ExecutionReceipt**: signed decision artifact containing whether action should occur + +Mapping intent: +- provisioning plane remains unchanged, +- authority plane performs runtime authorization and evidence capture. + +## 5. Runtime Decision Model + +Decision tuple: + +``` +Decision = f(authority, trust, risk, compliance, cost, context, constraints) +``` + +### Authority +- subject identity validity +- grant validity window +- action-resource compatibility +- branch/path/environment constraints + +### Trust +- current trust score +- attestation freshness and validity +- decay curve effect +- anomaly penalties + +### Risk +- action criticality +- blast radius +- reversibility +- delegation depth +- protected-path sensitivity + +### Compliance +- implicated controls/framework tags +- evidence mode required +- retention tier required +- human oversight requirement + +### Cost +- execution cost estimate +- review/escalation cost estimate +- evidence generation/storage cost estimate +- avoided-loss estimate +- control overhead category + +### Outcomes +- `PERMIT` +- `CONSTRAIN` +- `STEP_UP` +- `ESCALATE` +- `DENY` + +Fail closed on missing/ambiguous signals. + +## 6. Risk Framework + +Risk classes: + +- **Low**: comments/labels/reviews without protected-path effect +- **Medium**: workflow dispatch, merge recommendations, non-protected automation changes +- **High**: policy modifications, workflow file edits, receipt model updates +- **Critical**: merge to main, release tags, core runtime authorization/key path changes + +Risk calculation factors: +- action criticality +- blast radius +- reversibility +- delegation chain depth +- anomaly score +- protected file/path impact + +## 7. Compliance Framework + +Compliance is evaluated in decision-time, not post-processing. + +Per-action compliance attributes: +- framework tags (SOC2/ISO27001/internal-control-map) +- control IDs touched +- evidence mode (`required`, `enhanced`, `forensic`) +- retention tier (`standard`, `elevated`, `long_term`) +- human oversight requirement (`none`, `single`, `dual`) + +If required compliance controls cannot be satisfied, decision MUST be `ESCALATE` or `DENY`. + +## 8. Cost Framework + +Cost dimensions at authorization time: +- execution compute/tooling cost +- human review cost (step-up/escalation) +- evidence capture/storage cost +- estimated avoided-loss value +- control overhead class (`light`, `standard`, `heavy`) + +Cost does not override hard security/compliance denials. It only informs constrain/escalate policy. + +## 9. ExecutionReceipt Extension + +Extended receipt fields include: +- identity + trust context +- authority grant basis + policy basis +- risk posture snapshot +- compliance posture snapshot +- cost snapshot +- approval/escalation chain +- signature + chain hash +- GitHub context: repo, branch, paths touched, workflow run id, commit SHA, invoking actor + +Reference schema extension: `spec/extensions/execution-receipt-v2.schema.json`. + +## 10. GitHub Integration Architecture + +### 10.1 Components +- GitHub App (repo-facing execution identity) +- GitHub Actions workers (constrained executors) +- Runtime Authority service (`/re/authorize`) +- Receipt signer/store +- Trust Authority scorer + +### 10.2 Control flow +1. Slash command / workflow trigger requests action. +2. Worker assembles authorization request context. +3. Worker calls `POST /re/authorize`. +4. Authority returns outcome + constraints + receipt. +5. Worker enforces result: + - execute permitted action, + - constrain scope, + - request step-up, + - escalate to human approver, + - deny. +6. Receipt is persisted and chain-linked. + +### 10.3 Guardrails +- agent reasoning is not authority, +- workflows have no standing power, +- authority is short-lived and action-scoped. + +## 11. Agent Role Manifests + +Source of truth: `agents/manifests/role-agents.yaml`. + +The ten role-agents modeled: +1. Protocol Editor Agent +2. Spec & RFC Maintainer Agent +3. Rust Compiler Agent +4. Runtime Systems Agent +5. ZK / Proof Systems Agent +6. Identity / SCIM-RE Architect Agent +7. Security Research Agent +8. Agent Framework Integration Agent +9. Docs / DX Agent +10. Standards / Ecosystem Agent + +Each manifest defines purpose, workload identity, allowed/forbidden actions, path scope, protected actions, trust threshold, freshness, risk tier, compliance implications, cost profile, and receipt requirements. + +## 12. Protected Actions and Step-Up Policy + +Protected actions requiring `STEP_UP` or `ESCALATE`: +- merge to `main` +- release tags +- edits to `.github/workflows/**` +- edits to `policy/**` +- edits to trust model semantics +- edits to receipt schema +- edits to signing/key/verification paths +- edits to core runtime authorization behavior + +Policy source: `policy/github-self-governance-policy.yaml`. + +## 13. Repo Structure + +Proposed self-governance layout: + +``` +.github/workflows/ +agents/ +policy/ +receipts/ +rfcs/ +spec/ +runtime/ +compiler/ +docs/ +examples/ +``` + +This repository adds initial seeds for: +- `agents/manifests/` +- `policy/` +- `runtime/api/` +- `rfcs/` +- `spec/extensions/` + +## 14. Example API Contracts + +Normative example contracts are in: +- `runtime/api/re-authorize.contract.md` + +Includes request/response schema and outcome mapping. + +## 15. Example Workflow Skeletons + +Reference workflow: +- `.github/workflows/ttp-governed-pr-action.yml` + +Pattern: +1. collect action context, +2. call Runtime Authority, +3. enforce outcome, +4. upload/store receipt metadata. + +## 16. Phased Implementation Plan + +### Phase 1 +- advisory agents only +- comments/reviews/labels +- no merge authority + +### Phase 2 +- scoped workflow dispatch +- trust decay + attestation checks +- constrained execution mode + +### Phase 3 +- protected action step-up +- merge/release gating +- receipt-backed approvals + +### Phase 4 +- public reference implementation +- repository self-governed with TTP policy plane + +## 17. Maintainer / Ecosystem Value + +Maintainers gain: +- deterministic runtime governance for non-human actions, +- auditable execution evidence, +- reduced ambiguity in sensitive repo operations. + +Ecosystem gains: +- concrete reference model for CI/CD governance, +- reusable authority-plane patterns for machine identities, +- practical bridge between protocol semantics and operational tooling. + +## 18. Commercial Wedge and Revenue Logic + +This is a governance infrastructure wedge, not a bot feature. + +Value path: +- starter self-hosted governance, +- enterprise governance controls, +- managed authority service, +- compliance/evidence modules, +- advisory and implementation services. + +Commercial offerings remain optional and non-normative; core protocol semantics and interoperability remain open. diff --git a/docs/scim-re-github-role-agent-mapping.md b/docs/scim-re-github-role-agent-mapping.md new file mode 100644 index 0000000..a7a29d0 --- /dev/null +++ b/docs/scim-re-github-role-agent-mapping.md @@ -0,0 +1,21 @@ +# SCIM-RE Mapping Appendix: GitHub Role-Agents + +## Resource mapping + +- WorkloadIdentity -> GitHub role-agent identity (GitHub App subject + role manifest) +- AuthorityGrant -> scoped, time-bounded action permission envelope +- Attestation -> freshness/legitimacy proof bound to invocation context +- ExecutionReceipt -> signed, chain-hashed decision artifact + +## Plane separation + +- Provisioning plane: account/group lifecycle (unchanged) +- Authority plane: runtime decisioning (`/re/authorize`) and receipt generation + +## Outcome mapping + +- `PERMIT` -> authorized action execution +- `CONSTRAIN` -> authorized with reduced scope +- `STEP_UP` -> requires additional human/environment approval +- `ESCALATE` -> routed to higher authority chain +- `DENY` -> blocked and receipted diff --git a/examples/github-app-self-governance.md b/examples/github-app-self-governance.md new file mode 100644 index 0000000..cbf3930 --- /dev/null +++ b/examples/github-app-self-governance.md @@ -0,0 +1,18 @@ +# Example: GitHub App + Runtime Authority Integration + +This example shows how a GitHub App invokes Runtime Authority before executing sensitive repository actions. + +## Pattern + +1. GitHub event arrives (issue comment, PR review request, workflow dispatch intent). +2. App/worker resolves role-agent identity and action context. +3. Worker calls `POST /re/authorize`. +4. Authority returns `PERMIT|CONSTRAIN|STEP_UP|ESCALATE|DENY` + receipt. +5. Worker enforces decision and records receipt linkage. + +## Key controls + +- no standing workflow authority +- short-lived grants per action +- step-up for protected actions +- signed, chain-hashed receipts for every meaningful decision diff --git a/policy/github-self-governance-policy.yaml b/policy/github-self-governance-policy.yaml new file mode 100644 index 0000000..f9406ff --- /dev/null +++ b/policy/github-self-governance-policy.yaml @@ -0,0 +1,29 @@ +version: 1 +protected_actions: + - merge to main + - release tag request + - workflow modification request + - policy modification request + - receipt schema modification request + - edits to signing, key, or verification paths + - edits to core runtime authorization behavior + +risk_classes: + low: [issue.comment, pull_request.review, label.apply] + medium: [workflow.dispatch, merge recommendation] + high: [workflow modification request, policy modification request] + critical: [protected merge approval request, release tag request, receipt schema modification request] + +default_decision: DENY + +outcome_rules: + - when: risk == low && trust.score >= 0.8 && authority.valid == true + outcome: PERMIT + - when: risk == medium && trust.score >= 0.85 && compliance.human_oversight in [none,single] + outcome: CONSTRAIN + - when: action in protected_actions && trust.score >= 0.9 && attestation.fresh == true + outcome: STEP_UP + - when: action in protected_actions && (trust.score < 0.9 || compliance.human_oversight == dual) + outcome: ESCALATE + - when: authority.valid == false || attestation.fresh == false || context.ambiguous == true + outcome: DENY diff --git a/rfcs/0001-github-self-governance-role-agents.md b/rfcs/0001-github-self-governance-role-agents.md new file mode 100644 index 0000000..aafc745 --- /dev/null +++ b/rfcs/0001-github-self-governance-role-agents.md @@ -0,0 +1,17 @@ +# RFC-0001: GitHub Self-Governance with TTP + SCIM-RE + +Status: Draft + +This RFC introduces runtime governance for non-human GitHub role-agents using TTP authority gates and SCIM-RE authority-plane resources. + +Normative additions: +- Runtime Authority Gate (`POST /re/authorize`) for meaningful repo actions +- Extended `ExecutionReceipt` structure with risk/compliance/cost context +- Policy outcomes: PERMIT, CONSTRAIN, STEP_UP, ESCALATE, DENY +- Protected action handling with mandatory step-up/escalation paths + +Companion docs: +- `docs/github-self-governance-reference-architecture.md` +- `runtime/api/re-authorize.contract.md` +- `spec/extensions/execution-receipt-v2.schema.json` +- `policy/github-self-governance-policy.yaml` diff --git a/runtime/api/re-authorize.contract.md b/runtime/api/re-authorize.contract.md new file mode 100644 index 0000000..51436f8 --- /dev/null +++ b/runtime/api/re-authorize.contract.md @@ -0,0 +1,56 @@ +# Runtime Authority API: `POST /re/authorize` + +## Request + +```json +{ + "subject": { + "workload_identity": "wi://ttp/github/runtime-systems", + "invoking_actor": "github-app:ttp-governance" + }, + "action": "workflow modification request", + "resource": "repo:blocksifr/ttp-protocol:.github/workflows/ci.yml", + "context": { + "repo": "blocksifr/ttp-protocol", + "branch": "feature/runtime-gate", + "paths_touched": [".github/workflows/ci.yml"], + "workflow_run_id": "123456789", + "commit_sha": "abc123...", + "environment": "github-actions" + }, + "authority_grant": { + "grant_id": "grant-789", + "expires_at": "2026-04-17T12:00:00Z" + }, + "attestation": { + "attestation_id": "att-456", + "freshness_s": 120, + "valid": true + } +} +``` + +## Response + +```json +{ + "decision": "STEP_UP", + "constraints": ["require_environment_reviewer", "require_security_owner_approval"], + "reason_codes": ["PROTECTED_ACTION", "HUMAN_STEP_UP_REQUIRED"], + "receipt": { + "receipt_id": "er-123", + "decision": "STEP_UP", + "chain_hash": "sha256:...", + "signature": "ed25519:...", + "issued_at": "2026-04-17T11:00:00Z" + } +} +``` + +## Outcome semantics + +- `PERMIT`: execute action in current scope. +- `CONSTRAIN`: execute only under returned constraints. +- `STEP_UP`: pause for required step-up approval. +- `ESCALATE`: route to higher authority chain. +- `DENY`: block execution; receipt still recorded. diff --git a/spec/extensions/execution-receipt-v2.schema.json b/spec/extensions/execution-receipt-v2.schema.json new file mode 100644 index 0000000..0950d97 --- /dev/null +++ b/spec/extensions/execution-receipt-v2.schema.json @@ -0,0 +1,117 @@ +{ + "$schema": "https://json-schema.org/draft/2020-12/schema", + "$id": "https://ttp.dev/spec/extensions/execution-receipt-v2.schema.json", + "title": "ExecutionReceiptV2", + "type": "object", + "required": [ + "receipt_id", + "subject", + "decision", + "action", + "resource", + "trust", + "authority", + "risk", + "compliance", + "cost", + "github_context", + "chain_hash", + "signature", + "issued_at" + ], + "properties": { + "receipt_id": { "type": "string" }, + "subject": { + "type": "object", + "required": ["workload_identity", "invoking_actor"], + "properties": { + "workload_identity": { "type": "string" }, + "invoking_actor": { "type": "string" } + } + }, + "decision": { + "type": "string", + "enum": ["PERMIT", "CONSTRAIN", "STEP_UP", "ESCALATE", "DENY"] + }, + "action": { "type": "string" }, + "resource": { "type": "string" }, + "trust": { + "type": "object", + "required": ["score", "freshness_s"], + "properties": { + "score": { "type": "number", "minimum": 0, "maximum": 1 }, + "freshness_s": { "type": "integer", "minimum": 0 }, + "decay_model": { "type": "string" }, + "anomaly_score": { "type": "number", "minimum": 0, "maximum": 1 } + } + }, + "authority": { + "type": "object", + "required": ["grant_id", "grant_valid", "constraints"], + "properties": { + "grant_id": { "type": "string" }, + "grant_valid": { "type": "boolean" }, + "constraints": { "type": "array", "items": { "type": "string" } } + } + }, + "risk": { + "type": "object", + "required": ["tier", "criticality", "blast_radius"], + "properties": { + "tier": { "type": "string", "enum": ["low", "medium", "high", "critical"] }, + "criticality": { "type": "number", "minimum": 0, "maximum": 1 }, + "blast_radius": { "type": "number", "minimum": 0, "maximum": 1 }, + "reversible": { "type": "boolean" }, + "delegation_depth": { "type": "integer", "minimum": 0 } + } + }, + "compliance": { + "type": "object", + "required": ["frameworks", "controls", "evidence_mode", "retention_tier", "human_oversight"], + "properties": { + "frameworks": { "type": "array", "items": { "type": "string" } }, + "controls": { "type": "array", "items": { "type": "string" } }, + "evidence_mode": { "type": "string" }, + "retention_tier": { "type": "string" }, + "human_oversight": { "type": "string", "enum": ["none", "single", "dual"] } + } + }, + "cost": { + "type": "object", + "required": ["execution_cost", "review_cost", "evidence_cost", "avoided_loss_estimate", "overhead_class"], + "properties": { + "execution_cost": { "type": "number", "minimum": 0 }, + "review_cost": { "type": "number", "minimum": 0 }, + "evidence_cost": { "type": "number", "minimum": 0 }, + "avoided_loss_estimate": { "type": "number", "minimum": 0 }, + "overhead_class": { "type": "string", "enum": ["light", "standard", "heavy"] } + } + }, + "github_context": { + "type": "object", + "required": ["repo", "branch", "paths_touched", "workflow_run_id", "commit_sha"], + "properties": { + "repo": { "type": "string" }, + "branch": { "type": "string" }, + "paths_touched": { "type": "array", "items": { "type": "string" } }, + "workflow_run_id": { "type": "string" }, + "commit_sha": { "type": "string" } + } + }, + "approval_chain": { + "type": "array", + "items": { + "type": "object", + "required": ["actor", "action", "timestamp"], + "properties": { + "actor": { "type": "string" }, + "action": { "type": "string" }, + "timestamp": { "type": "string", "format": "date-time" } + } + } + }, + "chain_hash": { "type": "string" }, + "signature": { "type": "string" }, + "issued_at": { "type": "string", "format": "date-time" } + } +}