Skip to content

[WIP] Add execution governance features with PolicyEditor and RuleMetrics - #45

Merged
sv-pro merged 1 commit into
devfrom
copilot/claudeexecution-governance-features
Mar 16, 2026
Merged

[WIP] Add execution governance features with PolicyEditor and RuleMetrics#45
sv-pro merged 1 commit into
devfrom
copilot/claudeexecution-governance-features

Conversation

Copilot AI commented Mar 16, 2026

Copy link
Copy Markdown
Contributor
  • Understand the repository structure and existing branches
  • Cherry-pick execution governance implementation from claude/execution-governance-implementation-dtQLo (commit 5fd93d4)
    • PolicyEditor (src/agent_hypervisor/policy_editor/)
    • RuleMetrics additions to policy_tuner
    • PolicyAnalyzer and TunerReporter enhancements
    • ide_agent_governance_demo.py example
    • execution_governance_diagram.md doc
    • New tests (test_ide_governance_demo.py, test_policy_editor.py, test_policy_tuner.py additions)
    • README.md updates
  • Run tests to validate
  • Code review and security scan
Original prompt

Summary

Create a pull request merging branch claude/execution-governance-implementation-dtQLo into dev.

This branch implements execution governance features including:

What's included in this PR:

  1. PolicyEditor (src/agent_hypervisor/policy_editor/) — Read-only policy file inspector and previewer with:

    • load_policy — parse YAML policy files into structured PolicyFile objects
    • validate — structural rule validation and duplicate ID detection
    • list_rules — human-readable table formatting with filtering
    • preview_rule — dry-run impact analysis against representative cases
    • rule_risk_score — 0–10 risk scoring for rules
    • scope_reduction_hint — heuristic suggestions for narrower rule scope
  2. RuleMetrics (src/agent_hypervisor/policy_tuner/models.py) — Per-rule governance metrics (usage count, risk score, scope hints) added to TunerReport

  3. PolicyAnalyzer enhancement (src/agent_hypervisor/policy_tuner/analyzer.py) — Populates rule_metrics from runtime trace data

  4. TunerReporter enhancement (src/agent_hypervisor/policy_tuner/reporter.py) — Renders "Per-Rule Governance Metrics" section in Markdown and JSON output

  5. ide_agent_governance_demo.py (examples/integrations/) — Self-contained in-process governance demo with 3 scenarios (safe read → allow, prompt injection → deny, risky command → ask → approve → execute)

  6. execution_governance_diagram.md (docs/) — Full architecture diagram for the governance flow

  7. New tests:

    • tests/test_ide_governance_demo.py — 30+ tests covering all 3 scenarios
    • tests/test_policy_editor.py — 40+ tests for all PolicyEditor methods
    • tests/test_policy_tuner.py additions — Rule metrics tests
  8. README.md updates — Section 9: Execution Governance, Policy Editor usage, Policy Tuner report sections

Base branch: dev

Head branch: claude/execution-governance-implementation-dtQLo

Please open this pull request with base dev and head claude/execution-governance-implementation-dtQLo.

The following is the prior conversation context from the user's chat exploration (may be truncated):

Assistant: The tool call to create or update the file safe_openclaw_poc/world_manifest.yaml in the agent-hypervisor repository was dismissed. Let me know if you'd like me to retry it or make adjustments!

User: Read safe_openclaw_poc_prompt.md and proceed it

Assistant: I've read the prompt file. This is a well-structured PoC request for "Agent Physics Engineering" — a demo proving the need for a runtime safety layer between AI agents and their tools.

Let me now generate the full project and push it to your repository. I'll proceed file by file.


Step 1 — Project Tree

safe_openclaw_poc/
  README.md
  main.py
  world_manifest.yaml
  agent/
    __init__.py
    agent_loop.py
    prompt_builder.py
  physics/
    __init__.py
    proxy.py
    channels.py
    provenance.py
    policy.py
    manifest.py
  tools/
    __init__.py
    memory_tool.py
    email_tool.py
  demos/
    raw_mode_demo.py
    safe_mode_demo.py
  tests/
    test_tool_ontology.py
    test_memory_poisoning.py
    test_channel_separation.py

Now pushing all files:

Assistant: I have created a branch named feat/safe-openclaw-poc from the dev branch for the sv-pro/agent-hypervisor repository. Let me know how you would like to proceed next!

Assistant: The world_manifest.yaml file has been added to the safe_openclaw_poc/ directory in the feat/safe-openclaw-poc branch. You can view the file here. Let me know what you'd like to do next!

User: Read safe_openclaw_poc_prompt.md and proceed it

Assistant: Let me first check what already exists in the repository on that branch before proceeding.

Assistant: Good. So far only world_manifest.yaml exists in safe_openclaw_poc/. I'll now proceed to create all the remaining files as specified in the prompt. I'll push them all to the feat/safe-openclaw-poc branch. Let me do this in parallel batches.

Batch 1 — Core physics dataclasses: channels.py, provenance.py

This pull request was created from Copilot chat.


📍 Connect Copilot coding agent with Jira, Azure Boards or Linear to delegate work to Copilot in one click without leaving your project management tool.

@sv-pro
sv-pro marked this pull request as ready for review March 16, 2026 13:39
@sv-pro
sv-pro merged commit fd39d7c into dev Mar 16, 2026
1 check failed
Copilot AI requested a review from sv-pro March 16, 2026 13:40
Copilot stopped work on behalf of sv-pro due to an error March 16, 2026 13:40
@sv-pro
sv-pro deleted the copilot/claudeexecution-governance-features branch March 27, 2026 14:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants