pub enum Verb {
Read,
Write,
Supersede,
Delete,
Erase,
LoopRun,
LoopReview,
LoopApply,
Admin,
RunExecute,
RunRespond,
RunCancel,
}Expand description
One operation class — the unit of granting, GRANT SELECT-style.
The string forms (read, loop.review, …) are the wire/CAL vocabulary;
they appear in grant-grain objects and eventually in GRANT statements,
so they are frozen once the spec ships.
Variants§
Read
Write
Supersede
Delete
Erase
LoopRun
LoopReview
LoopApply
Admin
RunExecute
D5 (governed-agents §6.8): start/resume/fork a workflow run —
Control-tier: it spends budgets and executes effects, so it is not
plain write.
RunRespond
D5: answer a requires_action Client ask. This IS the approval
boundary — Control-tier, and the driver additionally refuses
responder == triggering principal on approval asks (separation of
duties, mirroring the loop’s self-approval block).
RunCancel
D5: cancel a run. Deliberately LOW-tier and broadly grantable — the brake must never be blocked by missing privilege (the kill-switch SLA depends on it).