Skip to content

ai: guardrails, memory, structuredOutput, lifecycle and tool.outputSchema are enforced by the agent runtime (5 keys), starting with the guardrails the built-in agents already declare #20274

Description

@objectstack-fleet

Ruled: 5950198150 · letter A′ (new) · 2026-10-02T10:20Z

Blocked-by: #21320

Filing gate: ① a declared≠enforced family, filed as one sweep card per family under ruling A′ item ④ on #18900 (5727134555). This is triage's standing request 5857165909 on the seat post. Family agent-runtime, seat verdict ENFORCE.

  • reach: the declared authoring door. packages/spec parses these keys and publishes them in the reference docs. The liveness ledger rows cited below record them as not enforced, and the census re-measured the reader side (§5 cross-checks, each with a lit control).
  • The criterion is the maintainer's: 「每族该问的是:主流平台有没有这个能力 —— 有 ⇒ 补消费端(一次做对);没有 ⇒ 退役,而不是看仓里有没有人读」.
  • The maintainer's one word, per ruling A′ ④: ENFORCE (the seat's proposal: the mainstream has it, so build the consumer once, correctly) or RETIRE (retire the keys together with their ledger rows).

Census by the domain:spec execution seat 1 (session_01Rjy9MeetSfq34PKn81CRiN, seat post #6017), 2026-09-27. Bases: objectstack a9fb83ef, re-checked against 4d7e740d, where no ledger file or cited surface moved; objectui 6fa5f64a1 (pin f8a9d0fb); cloud 96eb092. Ledger instrument: check-liveness.mts --json, whose byStatus equals the committed state-counts.md row for row. ⛔ Filed bare: routing and grading belong to triage. ⛔ Not a claim. The ranking is by value, user-visible risk × keys. This family's rank is 4 of 16.

Capability: Agent safety guardrails (denied topics, token and time limits), conversation memory, schema-validated structured output, a conversation state machine, and a tool output contract

key ledger status ledger row what the ledger cites
agent.lifecycle experimental packages/spec/liveness/agent.json:87 evidence: no runtime reader (StateMachine)
agent.memory experimental packages/spec/liveness/agent.json:92 evidence: no runtime reader
agent.guardrails experimental packages/spec/liveness/agent.json:97 evidence: no runtime reader
agent.structuredOutput experimental packages/spec/liveness/agent.json:102 evidence: no runtime reader
tool.outputSchema experimental (verified 2026-08-29) packages/spec/liveness/tool.json:44 evidence: cloud @15f55df: packages/service-ai/src/tools/action-tools.ts#outputSchemaKeys lists the top-level property names and packages/service-ai/src/tools/action-tools.ts#buildToolDescription folds them into the LLM-facing description as a trailing Returns-an-obje…

Mainstream evidence:

  • Guardrails: Amazon Bedrock Guardrails ("denied topics", content filters); Microsoft Copilot Studio content moderation; Salesforce Agentforce Einstein Trust Layer (toxicity detection, data masking).
  • Memory: Amazon Bedrock Agents memory (session summaries); OpenAI Assistants threads; Copilot Studio global / topic variables.
  • Structured output: OpenAI Structured Outputs (json_schema). AI Builder prompt JSON output is UNVERIFIED.
  • Lifecycle / state machine: Dialogflow CX flows and pages; Copilot Studio topics (authored conversation graphs); Agentforce topics.
  • Tool output contract: MCP tool outputSchema + structuredContent (spec 2025-06-18); Power Automate connector action outputs.

Verdict: ENFORCE — the mainstream has the capability, so build the consumer once, correctly.

Reader that must exist / disposition: cloud packages/service-ai/src/agent-runtime.ts (and routes/agent-routes.ts, routes/assistant-routes.ts, which already read agent.planning?.maxIterations, e.g. agent-routes.ts:757) must read guardrails / memory / structuredOutput / lifecycle; cloud packages/service-ai/src/tools/action-tools.ts must validate outputs against outputSchema instead of only folding its keys into the description.

User-visible risk (3): Measured: cloud's own built-in agents author guardrails.blockedTopics: ['delete_records', 'drop_database', 'raw_sql', 'system_tables'] plus token and time limits (cloud service-ai-studio/src/agents/ask-agent.ts:122-127, metadata-assistant-agent.ts:77-81), and nothing in cloud or objectstack reads them. This is safety-shaped false compliance. Mitigation: the spec describe carries [EXPERIMENTAL — not enforced], and os lint warns on experimental rows (packages/lint/src/lint-liveness-properties.ts:157-159, shouldWarn). The lint walks stack collections (qa.json _note), so the cloud built-in agents, which are TypeScript in cloud, most likely never meet that warning. That last point is UNVERIFIED.

Acceptance: Every ledger row listed leaves dead/planned/experimental for live, citing the new reader as file#symbol (and a producer where the read depends on a supplied input); pnpm check:liveness green; the family's byStatus in state-counts.md regenerated.

Lane: domain:spec parent (objectstack) + cloud sub-issue (service-ai); ⚠️ NORTH-STAR 〈现在不做〉 places the built-in enterprise agent in the cloud repo

File surface: packages/spec/src/ai/agent.zod.ts:197,299,340,370 · packages/spec/src/ai/tool.zod.ts:194 · packages/spec/liveness/{agent,tool}.json · cloud packages/service-ai/src/{agent-runtime.ts,routes/agent-routes.ts,tools/action-tools.ts}

Dedupe: agent\.(lifecycle\|memory\|guardrails\|structuredOutput) \| guardrails\.(blockedTopics\|maxTokens\|maxExecution) \| blockedTopics \| structuredOutput \| StructuredOutputConfig → 3 open hits. None carries a key of this family:

Dedupe: tool\.outputSchema \| outputSchemaKeys → 0 open hits.

四轴:

  • 实际业务需求: 企业用户上线 AI 助手时,最先问的就是护栏(禁谈话题、令牌与时长上限)。Bedrock、Copilot Studio、Agentforce 都把它做成可配置能力。平台自带的助手已经写了 blockedTopics,但没有任何代码执行。
  • 项目长远合理性: 分量最重的一轴。AI 可操作是本平台的核心叙事,规格里的护栏必须由运行期兑现,否则规格本身不可信。一次做对:护栏在运行期统一执行,输出按 schema 校验,记忆与状态机采用主流语义。
  • 防 AI 写错: 护栏不执行,AI 生成的助手会「声明了安全」却没有安全。执行之后,违反护栏的调用会被拒绝并留下审计痕迹。
  • 创业阶段不扩散: 消费端在 cloud 仓,本仓只做契约;先做 guardrails(风险最高),其余三键可以跟进,但裁决仍是「做」而不是退役。

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:aiAI-native — agent / tool / skill metadata, and the MCP surface an agent drivesdomain:specenhancementNew feature or requestpriority:p2Medium: important, M3security

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions