Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
46 changes: 46 additions & 0 deletions .github/workflows/ttp-governed-pr-action.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,46 @@
name: TTP Governed PR Action (Skeleton)

on:
issue_comment:
types: [created]

jobs:
governed-action:
if: contains(github.event.comment.body, '/ttp')
runs-on: ubuntu-latest
permissions:
contents: read
pull-requests: write
issues: write
steps:
- uses: actions/checkout@v4

- name: Build /re/authorize request context
run: |
echo '{"todo":"collect action, paths, actor, branch, run id"}' > request.json

- name: Runtime Authority Gate
env:
RUNTIME_AUTH_URL: ${{ secrets.RUNTIME_AUTH_URL }}
RUNTIME_AUTH_TOKEN: ${{ secrets.RUNTIME_AUTH_TOKEN }}
run: |
curl -sS -X POST "$RUNTIME_AUTH_URL/re/authorize" \
-H "Authorization: Bearer $RUNTIME_AUTH_TOKEN" \
-H "Content-Type: application/json" \
-d @request.json > decision.json
cat decision.json

- name: Enforce decision
run: |
DECISION=$(jq -r '.decision' decision.json)
case "$DECISION" in
PERMIT) echo "execute allowed action" ;;
CONSTRAIN) echo "execute constrained action" ;;
STEP_UP) echo "request human step-up approval" ; exit 1 ;;
ESCALATE) echo "escalate to maintainers/security owners" ; exit 1 ;;
DENY|*) echo "deny action" ; exit 1 ;;
esac

- name: Persist receipt reference
run: |
jq -r '.receipt.receipt_id' decision.json
141 changes: 141 additions & 0 deletions agents/manifests/role-agents.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,141 @@
version: 1
agents:
- name: Protocol Editor Agent
workload_identity: wi://ttp/github/protocol-editor
purpose: Maintain protocol core text and schemas.
allowed_actions: [issue.comment, pull_request.review, merge recommendation, policy modification request]
forbidden_actions: [release tag request, protected merge approval request]
allowed_paths: [protocol/**, spec/**, rfcs/**]
protected_actions_requiring_step_up: [receipt schema modification request, policy modification request]
minimum_trust_score: 0.90
freshness_s: 600
risk_tier: high
compliance_implications: [integrity-control, change-management]
cost_profile: standard
receipt_requirements: [authority_basis, trust_context, risk_posture, compliance_posture, cost_posture, chain_hash]

- name: Spec & RFC Maintainer Agent
workload_identity: wi://ttp/github/spec-rfc-maintainer
purpose: Curate RFC lifecycle and spec consistency.
allowed_actions: [issue.comment, pull_request.review, label.apply]
forbidden_actions: [workflow modification request, release tag request]
allowed_paths: [rfcs/**, protocol/**, docs/**]
protected_actions_requiring_step_up: [merge to main]
minimum_trust_score: 0.85
freshness_s: 900
risk_tier: medium
compliance_implications: [review-evidence]
cost_profile: light
receipt_requirements: [authority_basis, trust_context, github_context]

- name: Rust Compiler Agent
workload_identity: wi://ttp/github/rust-compiler
purpose: Build/compiler integration and CI runtime checks.
allowed_actions: [workflow.dispatch, issue.comment, pull_request.review]
forbidden_actions: [policy modification request, receipt schema modification request]
allowed_paths: [compiler/**, .github/workflows/**]
protected_actions_requiring_step_up: [workflow modification request]
minimum_trust_score: 0.88
freshness_s: 300
risk_tier: high
compliance_implications: [build-integrity]
cost_profile: standard
receipt_requirements: [risk_posture, cost_posture, chain_hash]

- name: Runtime Systems Agent
workload_identity: wi://ttp/github/runtime-systems
purpose: Maintain runtime authority and verifier paths.
allowed_actions: [pull_request.review, issue.comment, workflow.dispatch]
forbidden_actions: [release tag request]
allowed_paths: [runtime/**, reference-implementations/**]
protected_actions_requiring_step_up: [edits to core runtime authorization behavior, merge to main]
minimum_trust_score: 0.92
freshness_s: 300
risk_tier: critical
compliance_implications: [runtime-control, security-review]
cost_profile: heavy
receipt_requirements: [authority_basis, approval_chain, risk_posture, compliance_posture, chain_hash, signature]

- name: ZK / Proof Systems Agent
workload_identity: wi://ttp/github/zk-proof-systems
purpose: Maintain proof-related semantics and references.
allowed_actions: [issue.comment, pull_request.review]
forbidden_actions: [workflow modification request, release tag request]
allowed_paths: [spec/**, docs/**]
protected_actions_requiring_step_up: [merge to main]
minimum_trust_score: 0.87
freshness_s: 1200
risk_tier: medium
compliance_implications: [evidence-quality]
cost_profile: standard
receipt_requirements: [trust_context, risk_posture, github_context]

- name: Identity / SCIM-RE Architect Agent
workload_identity: wi://ttp/github/scim-re-architect
purpose: Maintain identity and authority-plane mappings.
allowed_actions: [pull_request.review, issue.comment, policy modification request]
forbidden_actions: [release tag request]
allowed_paths: [docs/**, policy/**, spec/**]
protected_actions_requiring_step_up: [policy modification request, receipt schema modification request]
minimum_trust_score: 0.91
freshness_s: 600
risk_tier: high
compliance_implications: [identity-governance]
cost_profile: standard
receipt_requirements: [authority_basis, compliance_posture, approval_chain]

- name: Security Research Agent
workload_identity: wi://ttp/github/security-research
purpose: Analyze threats, controls, and verification logic.
allowed_actions: [issue.comment, pull_request.review, label.apply]
forbidden_actions: [merge to main, release tag request]
allowed_paths: [docs/security.md, protocol/**, reference-implementations/**]
protected_actions_requiring_step_up: [edits to signing, key, or verification paths]
minimum_trust_score: 0.93
freshness_s: 300
risk_tier: critical
compliance_implications: [security-review, evidence-retention]
cost_profile: heavy
receipt_requirements: [risk_posture, compliance_posture, chain_hash, signature]

- name: Agent Framework Integration Agent
workload_identity: wi://ttp/github/framework-integration
purpose: Integrate TTP with agent frameworks and callbacks.
allowed_actions: [issue.comment, pull_request.review, workflow.dispatch]
forbidden_actions: [policy modification request, receipt schema modification request]
allowed_paths: [sdk/**, examples/**, docs/**]
protected_actions_requiring_step_up: [workflow modification request]
minimum_trust_score: 0.84
freshness_s: 900
risk_tier: medium
compliance_implications: [integration-evidence]
cost_profile: standard
receipt_requirements: [trust_context, risk_posture, github_context]

- name: Docs / DX Agent
workload_identity: wi://ttp/github/docs-dx
purpose: Maintain docs quality and contributor experience.
allowed_actions: [issue.comment, pull_request.review, label.apply]
forbidden_actions: [workflow modification request, merge to main, release tag request]
allowed_paths: [docs/**, README.md, CONTRIBUTING.md]
protected_actions_requiring_step_up: [merge recommendation for protected paths]
minimum_trust_score: 0.80
freshness_s: 1800
risk_tier: low
compliance_implications: [change-traceability]
cost_profile: light
receipt_requirements: [authority_basis, github_context]

- name: Standards / Ecosystem Agent
workload_identity: wi://ttp/github/standards-ecosystem
purpose: Coordinate standards-track and ecosystem alignment.
allowed_actions: [issue.comment, pull_request.review, label.apply, merge recommendation]
forbidden_actions: [release tag request]
allowed_paths: [rfcs/**, docs/**, protocol/**]
protected_actions_requiring_step_up: [merge to main, policy modification request]
minimum_trust_score: 0.89
freshness_s: 1200
risk_tier: high
compliance_implications: [governance-evidence]
cost_profile: standard
receipt_requirements: [authority_basis, approval_chain, risk_posture, compliance_posture]
12 changes: 12 additions & 0 deletions docs/architecture.md
Original file line number Diff line number Diff line change
Expand Up @@ -255,6 +255,18 @@ See [examples/service-integration](../examples/service-integration/) for Kong an

---

## 10. GitHub Self-Governance Extension (TTP Governing TTP)

TTP can be applied to its own repository operations by treating AI role-agents as governed workload identities and routing meaningful GitHub actions through a Runtime Authority Gate (`POST /re/authorize`) before execution.

Reference materials:
- [GitHub Self-Governance Reference Architecture](github-self-governance-reference-architecture.md)
- [SCIM-RE Mapping Appendix](scim-re-github-role-agent-mapping.md)
- [ExecutionReceipt schema extension](../spec/extensions/execution-receipt-v2.schema.json)
- [Role-agent manifests](../agents/manifests/role-agents.yaml)

---

## Performance Considerations

### Token Verification Latency
Expand Down
Loading
Loading