Files
pi-extensions/CONTEXT.md
T
SikongJueluo fba79504ac docs: add agent guidance and permission research docs
- add AGENTS.md and docs for issue tracker, triage labels, and domain docs
- add CONTEXT.md glossary for the permission authorization domain
- add research report on context ownership for forwarded bash asks
- ignore .pi-subagents and .codegraph directories
- remove pi-permission-ai-judge from settings packages
2026-08-09 00:23:24 +08:00

1.7 KiB

Permission Authorization

This context describes how ambiguous coding-agent operations are reviewed before they may execute.

Language

Deterministic Permission Policy: The rule-based authority that classifies an operation as allowed, denied, or requiring a decision. Avoid: Static judge

Authorization Judge: An independent reviewer that proposes a verdict for an operation the Deterministic Permission Policy could not decide. Avoid: Bash parser, safety classifier

Shadow Mode: An observation mode in which an Authorization Judge records a verdict without changing whether the operation executes. Avoid: Dry run

Enforce Mode: An authority mode in which selected Authorization Judge verdicts may directly determine whether an operation executes. Avoid: Production mode

Defer: A verdict stating that the available information or the judge itself is insufficient to decide, leaving the decision to the next authority. Avoid: Deny, error

False Allow: A Shadow Mode outcome in which the Authorization Judge proposes approval and the human reviewer rejects the same permission request. Avoid: False positive

Requesting Session: The session in which the operation requiring authorization originated. For a forwarded request, this is the child session. Avoid: Current session

Serving Session: The authority-bearing session that resolves a forwarded request and runs its configured Authorization Judge before the terminal human authority. Avoid: Parent context, current session

Conversation Owner: The session whose conversation entries are supplied to an Authorization Judge. It may differ from the Requesting Session for forwarded requests. Avoid: Requester