Documentation
¶
Overview ¶
Package policy evaluates immutable, side-effect-free automation rules for semantic agent events. It deliberately does not encode or deliver a decision: callers must fall back to a human whenever an adapter cannot represent the proposed action or a delivery fails.
Index ¶
Constants ¶
const ( ReasonDefault = "default_action" ReasonRule = "rule_match" ReasonInvalidEvent = "invalid_event" ReasonNonActionable = "non_actionable" ReasonSensitive = "sensitive_event" ReasonRisk = "risk_not_low" ReasonDryRun = "dry_run" ReasonNoEngine = "engine_unavailable" )
Static evaluation reasons are safe to expose in logs. They never contain event text, regex matches, metadata, or other terminal output.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type Config ¶
Config describes the ordered rules evaluated by an Engine.
func DefaultConfig ¶
func DefaultConfig() Config
DefaultConfig preserves Relayer's human-in-the-loop behavior.
type Engine ¶
type Engine struct {
// contains filtered or unexported fields
}
Engine is immutable after construction and safe for concurrent evaluation.
func New ¶
New validates and defensively copies a policy configuration. Regexes are compiled once so Evaluate remains deterministic and allocation-light.
type Evaluation ¶
type Evaluation struct {
Action Action
ProposedAction Action
RuleName string
Reason string
EventID string
Automatic bool
DryRun bool
}
Evaluation separates the configured proposal from the effective action. Sensitive events and dry-run configurations retain ProposedAction for a safe audit record while forcing ActionAsk and disabling automation.
type Match ¶
type Match struct {
EventTypes []adapters.EventType
TextRegex string
AgentIDs []string
RiskLevels []adapters.RiskLevel
Sensitive *bool
}
Match combines fields with AND semantics. Values inside each list use OR semantics. TextRegex is evaluated against Summary + "\n" + Match but that text is never retained by Engine or copied into Evaluation.