From 6595169a3c693d02bfe3a02b66e2c6ca5f73d6a7 Mon Sep 17 00:00:00 2001 From: operator Date: Thu, 8 Oct 2026 04:03:45 +0000 Subject: [PATCH] docs(policy): agy hold-all exit criteria grill record (Final) E1-E6: supervised 3-observation proof bar per kind, independent flips, automatic on proof, single-miss rollback, fleet-wide, grill questions stay coordinator-gated. Scope accepted verbatim in-record. --- docs/MUSE-CHOICES-POLICY.md | 83 +++++++++++++++++++++++++++++++++++++ 1 file changed, 83 insertions(+) diff --git a/docs/MUSE-CHOICES-POLICY.md b/docs/MUSE-CHOICES-POLICY.md index a5e59ff..240f606 100644 --- a/docs/MUSE-CHOICES-POLICY.md +++ b/docs/MUSE-CHOICES-POLICY.md @@ -1,3 +1,17 @@ +--- +title: "Muse-Choices Deny/Escalate & Agy Hold-All Exit Policy" +status: "signed-off" +coordinator: "operator-main" +scope: "muse-choices-policy" +accepted_at: "2026-10-07T05:55:03Z" +accepted_quote: "ACCEPT" +gate: "coordinator" +signoff_targets: + - "choices-deny-escalate" + - "agy-hold-all-exit" + - "interview-gated-choices" +--- + # Muse-Choices Deny/Escalate Policy — DECISION RECORD (Final) Topic: add deny/escalate decisions to the `muse-choices` auto-approve daemon @@ -101,3 +115,72 @@ lane-coordination evidence. - Model-based review of choices (deferred future layer). - Peer-agent consultation over sidechat (rejected in favor of D0). - Changes to approval matching shapes (covered by the matcher test suite). + +## agy hold-all exit criteria — DECISION RECORD (Final) + +Interview opened 2026-10-07. Topic selected by user (option 1, chat): +what proof flips agy panes from hold-all to auto-answering. The D0–D5 +record above is Final and untouched by this interview. Numbering +continues as E1+ to avoid collision. + +### Settled during interview + +- E1 (proof bar): supervised live proof per kind, fixed count. + Source: user selected option 1, 2026-10-07. Rationale: the risk is + behavioral (how agy's renderer treats digit keys) — only live + observation on real agy prompts proves it; synthetic tests cannot. + A correct observation means a resolve-approve (or equivalent + human-gated send of the kind's key) produces the intended selection + with no stray keys. The count itself is E1b. +- E1b (count): three consecutive correct observations per kind, + uniform across kinds; a miss resets the count. Source: user + selected option 1, 2026-10-07. Rationale: one success could be + luck (cursor already placed); three in a row across separate + prompts proves the key binding, not the moment. +- E2 (rollout grain): independent per-kind flip — each kind exits + hold-all the moment its 3 observations complete. Source: user + selected option 1, 2026-10-07. Rationale: matches the uniform bar; + rarely-seen kinds do not block proven ones. +- E3 (flip authority): automatic on completed proof — the 3 + observations are themselves human-gated (each a resolve-approve), + so completion is the approval. The flip applies automatically and + is recorded in the audit log plus a dated note in this doc. + Source: user selected option 1, 2026-10-07. Rationale: no extra + ceremony beyond the supervision already done; the audit trail + shows all 3 proofs. +- E4 (rollback): single miss re-holds the kind — any post-flip + wrong-send (wrong selection or stray keys), however observed, + immediately re-holds that kind and wipes its proof count; re-flip + needs 3 fresh observations. Source: user selected option 1, + 2026-10-07. Rationale: fail-closed and symmetric with the bar. +- E5 (applicability): fleet-wide — proof on any agy pane flips the + kind on all agy panes. Source: user selected option 1, 2026-10-07. + Rationale: the key binding is a property of the agy binary, + identical on every pane. +- E6 (grill exclusion): numbered-plain stays coordinator-gated on + agy; the E-rules never flip it. Source: user selected option 1, + 2026-10-07. Rationale: the E-rules prove the technical question + (keys work); the grill hold answers the governance question + (interviews need sign-off). Proof cannot lift a governance gate. + +### Open questions (unresolved) + +None. All interview questions resolved and the scope accepted. + +### Scope contract (ACCEPTED) + +- IN: this record section only (agy exit criteria, now Final). +- OUT: the flip mechanism (code), tests, daemon restarts, any + implementation. Accepting this record never approves those stages; + each returns for its own go-ahead. +- Done means: every E-question settled below, section marked Final, + user acceptance quoted verbatim with channel and time. +- "Go" / "do it all" authorize only the IN boundary. No owning issue + exists in this workflow, so this record is the lane-coordination + evidence. + +Acceptance (quoted verbatim, chat, 2026-10-07T05:55:03Z): "ACCEPT". +Accepted as written. Per the grill scope contract, later work outside +the IN boundary (the flip mechanism, tests, restarts) needs explicit +owner approval or its own follow-up interview; "go" authorizes only +this boundary.