Expand description
The codes in the HELM reason-code registry.
A reason code is an open string on the wire. These constants name the registered codes; a code missing from this list is still a valid value, not an error.
Constants§
- ACTIVATION_
BINDING_ MISMATCH - DENY: The company activation record does not match the authenticated tenant, company domain, workspace, or configured environment
- ACTIVATION_
CEILING_ EXCEEDED - DENY: The signed or requested effect, autonomy, or exposure limit exceeds the current company activation ceiling
- ACTIVATION_
RECORD_ INVALID - DENY: The company activation record failed schema, integrity, signature, or lifetime validation
- ACTIVATION_
TRUST_ UNAVAILABLE - DENY: No pinned control-plane activation verification key is configured
- AGENT_
KILLED - DENY: Agent has been terminated via per-agent kill switch
- ALL
- Every registered reason code, in registry order.
- APPROVAL_
REJECTED - DENY: A distinct human approver rejected the escalated effect
- APPROVAL_
REQUIRED - ESCALATE: High-risk effect requires human approval before execution
- APPROVAL_
TIMEOUT - DENY: Human approval not received within timeout — action denied
- APPROVER_
NOT_ DISTINCT - DENY: The approver is the requester; an approval needs a distinct principal
- ARITHMETIC_
OVERFLOW - DENY: An amount or counter total overflows a 64-bit integer
- AUTHORITY_
CHANGED - DENY: An authority row the permit was issued under changed before the dispatch claim; the permit is voided and the effect must be proposed again
- BUDGET_
ERROR - DENY: Budget system unavailable (fail-closed)
- BUDGET_
EXCEEDED - DENY: Operation exceeds allocated budget
- CAPABILITY_
IRREVERSIBLE - DENY: Irreversible effect class cannot dispatch without an authoritative approval integration
- CAPABILITY_
MANIFEST_ DRIFT - DENY: Caller-pinned capability manifest hash does not match the registry revision
- CAPABILITY_
ROLLBACK_ PLAN_ INVALID - DENY: Reversible non-read-only capability lacks a loadable, matching, valid rollback plan
- CAPABILITY_
TOKEN_ INVALID - DENY: Task capability token is malformed, expired, revoked, exhausted, out of scope, or fails signature/binding verification
- CAPABILITY_
UNKNOWN - ESCALATE: Dispatched capability_id is not registered and is quarantined for review
- CONTEXT_
MISMATCH - DENY: Environment fingerprint does not match boot-time snapshot
- DATA_
EGRESS_ BLOCKED - DENY: Data transmission to unauthorized external endpoint blocked
- DELEGATION_
INVALID - DENY: Delegation session is invalid, expired, revoked, or has a binding mismatch
- DELEGATION_
PRINCIPAL_ MISMATCH - DENY: Requesting principal does not match the delegation session’s bound delegate principal
- DELEGATION_
SCOPE_ VIOLATION - DENY: Delegate attempted an action outside the session’s granted capabilities
- EFFECT_
OUT_ OF_ SCOPE - DENY: A mandate of the chain does not cover the effect type or target, or the effect type has no control row
- EMERGENCY_
STOP_ FENCED - DENY: A durable tenant/workspace emergency-stop fence is active for newly governed dispatches
- EMERGENCY_
STOP_ SCOPE_ REQUIRED - DENY: A governed dispatch omitted the authoritative tenant/workspace scope required while emergency-stop fencing is enabled
- EMERGENCY_
STOP_ UNVERIFIED - DENY: Emergency-stop fence status could not be verified, so the governed dispatch was denied fail-closed
- ENVELOPE_
INVALID - DENY: Effect envelope failed validation
- ERR_
ASSUMPTION_ STALE - DENY/ESCALATE: A declared plan assumption or dependency is stale before side-effect dispatch
- ERR_
ATTESTATION_ RESULT_ REQUIRED - DENY: Signed verifier-issued attestation result is required for emergency authorization
- ERR_
COMPUTE_ GAS_ EXHAUSTED - DENY: Sandboxed execution exhausted configured compute or gas budget
- ERR_
COMPUTE_ TIME_ EXHAUSTED - DENY: Sandboxed execution exceeded the configured wall-clock time budget
- ERR_
CONNECTOR_ CONTRACT_ DRIFT - DENY: Connector observed output shape drift and failed closed
- ERR_
CONTINUITY_ STALE - DENY: Safe Deprecation continuity checkpoint is stale, replayed, expired, or rollbacked
- ERR_
DEV_ FALLBACK_ PRESENT - DENY: Dev, audit, mock, software-key, env-fallback, or unsigned overlay path is enabled
- ERR_
EMERGENCY_ CAPSULE_ INVALID - DENY: Emergency capsule failed binding, expiry, subset-proof, or delegation validation
- ERR_
GREEN_ TEST_ SCOPE_ MISSING - DENY: Passing tests were submitted without a declared verification scope
- ERR_
GROUNDED_ ACTION_ REF_ REQUIRED - DENY: GUI or computer-use action is missing grounded screenshot and DOM/accessibility evidence
- ERR_
GUI_ POSTCONDITION_ UNVERIFIED - DENY: GUI or computer-use action postcondition was not verified
- ERR_
HARDWARE_ QUORUM_ UNBOUND - DENY: Hardware-bound emergency quorum is missing, duplicated, unauthorized, or revoked
- ERR_
HARNESS_ MUTATION_ REQUIRES_ APPROVAL - ESCALATE: Mutation of connector, tool, sandbox, policy, verifier, evidence, or routing state requires explicit approval
- ERR_
HARNESS_ TRACE_ REQUIRED - DENY: Side-effectful execution is missing a hash-linked HarnessTrace
- ERR_
HOST_ DESTINATION_ MISMATCH - DENY: Host-observed egress destination differs from HELM authority metadata
- ERR_
HOST_ EGRESS_ AFTER_ DENY - DENY: Host-observed egress occurred after HELM denied the corresponding action
- ERR_
HOST_ EGRESS_ WITHOUT_ INTENT - DENY: Host-observed egress has no corresponding HELM intent or authority receipt
- ERR_
HOST_ PROCESS_ UNBOUND - DENY: Host receipt process identity cannot be bound to a HELM workload identity
- ERR_
HOST_ RECEIPT_ MISSING - DENY: A HELM network-authority receipt has no matching host evidence receipt
- ERR_
HOST_ VOLUME_ EXCEEDED - DENY: Host-observed egress byte volume exceeds the HELM authority ceiling
- ERR_
PLAN_ TRANSACTION_ CONFLICT - DENY/ESCALATE: PlanTransaction read/write sets conflict with another open transaction
- ERR_
PLAN_ TRANSACTION_ REQUIRED - DENY: Multi-artifact or write-bearing execution is missing a PlanTransaction
- ERR_
POLICY_ DENIED_ BUT_ HOST_ OBSERVED_ EGRESS - DENY: Host evidence contradicts a HELM policy denial for network egress
- ERR_
TON_ ACTON_ ARGV_ REJECTED - DENY: Acton argv failed typed connector validation
- ERR_
TON_ ACTON_ GENERIC_ MAINNET_ SCRIPT_ DENIED - DENY: Generic Acton mainnet script execution is denied by default
- ERR_
TON_ ACTON_ RAW_ SHELL_ FORBIDDEN - DENY: Raw shell or raw command execution was requested for Acton
- ERR_
TON_ ACTON_ UNKNOWN_ COMMAND - DENY: Requested Acton action is not one of the typed HELM TON Acton actions
- ERR_
TON_ ACTON_ UNSUPPORTED_ VERSION - DENY: Observed Acton version is outside the connector contract
- ERR_
TON_ APPROVAL_ CEREMONY_ REQUIRED - ESCALATE: TON T3 action requires approval ceremony evidence
- ERR_
TON_ COVERAGE_ THRESHOLD_ FAILED - DENY/ESCALATE: Acton coverage result is below policy threshold
- ERR_
TON_ EXPECTED_ EFFECT_ MISMATCH - DENY/ESCALATE: Declared TON expected effects are missing or do not match the action envelope
- ERR_
TON_ LIBRARY_ MAINNET_ REQUIRES_ APPROVAL - ESCALATE: Mainnet TON library publish or top-up requires approval
- ERR_
TON_ LIBRARY_ SPEND_ CEILING_ EXCEEDED - DENY: TON library publish or top-up exceeds spend ceilings
- ERR_
TON_ MAINNET_ REQUIRES_ APPROVAL - ESCALATE: TON mainnet action requires policy approval before dispatch
- ERR_
TON_ MUTATION_ THRESHOLD_ FAILED - DENY/ESCALATE: Acton mutation score is below policy threshold
- ERR_
TON_ NETWORK_ GRANT_ REQUIRED - DENY: TON networked action requires an explicit sandbox network grant
- ERR_
TON_ PLAINTEXT_ MNEMONIC_ FORBIDDEN - DENY: Plaintext wallet mnemonic or private key material is forbidden
- ERR_
TON_ SANDBOX_ GRANT_ REQUIRED - DENY: Acton execution requires a valid HELM sandbox grant
- ERR_
TON_ SCRIPT_ MANIFEST_ HASH_ MISMATCH - DENY: Acton script hash does not match the HELM sidecar manifest
- ERR_
TON_ SCRIPT_ MANIFEST_ REQUIRED - DENY: Networked Acton script is missing the required HELM sidecar manifest
- ERR_
TON_ SOURCE_ VERIFICATION_ REQUIRED - DENY: TON source verification evidence is required before the action can dispatch
- ERR_
TON_ SPEND_ CEILING_ EXCEEDED - DENY: TON spend exceeds action or daily policy ceilings
- ERR_
TON_ TOLK_ COMPILER_ MISMATCH - DENY: Observed Tolk compiler version does not match policy or connector contract
- ERR_
TON_ TOLK_ COMPILER_ UNPINNED - DENY: A Tolk compiler version pin is required for bytecode-sensitive TON work
- ERR_
TON_ VERIFY_ BYTECODE_ MISMATCH - DENY: TON verifier bytecode comparison failed
- ERR_
TON_ VERIFY_ DRY_ RUN_ REQUIRED - DENY: TON verifier dry-run evidence is required before final verification or deployment
- ERR_
TON_ WALLET_ REF_ REQUIRED - DENY: TON action requires an opaque wallet reference
- IDEMPOTENCY_
CONFLICT - DENY: The idempotency key was already used with a different request
- IDENTITY_
ISOLATION_ VIOLATION - DENY: Agent credential reuse or impersonation detected
- INSUFFICIENT_
PRIVILEGE - DENY: Agent privilege tier insufficient for requested effect type
- JURISDICTION_
VIOLATION - DENY: Effect violates jurisdictional constraint
- MANDATE_
INACTIVE - DENY: No active mandate held by the principal covers the effect, or a mandate of its chain is revoked
- MANDATE_
OUTSIDE_ VALIDITY - DENY: A mandate of the chain is outside its validity window
- MISSING_
REQUIREMENT - DENY: Required precondition not satisfied
- NO_
POLICY_ DEFINED - DENY: No policy covers this effect type
- PDP_
DENY - DENY: External PDP returned deny
- PDP_
ERROR - DENY: PDP unavailable or returned error (fail-closed)
- PERMIT_
ARGUMENT_ MISMATCH - DENY: The arguments an adapter was about to send are not the bytes the permit’s argument digest covers
- PERMIT_
EXPIRED - DENY: The permit expired before the dispatch claim; it is voided and the effect must be proposed again
- PER_
CALL_ LIMIT - DENY: The effect’s amount exceeds a per-call limit of the mandate chain
- POLICY_
EPOCH_ CHANGED - DENY: The active policy epoch changed before the effect could be issued
- POLICY_
HASH_ MISMATCH - DENY: Policy source bytes did not match the published canonical policy hash
- POLICY_
NOT_ READY - DENY: No verified EffectivePolicySnapshot is installed for the requested scope
- POLICY_
SIGNATURE_ INVALID - DENY: Policy source signature or provenance verification failed
- POLICY_
VIOLATION - DENY: Effect violates an active policy rule
- PRECONDITION_
FAILED - DENY: A precondition the effect type declares does not hold, so no attempt was created
- PRG_
EVALUATION_ ERROR - DENY: Policy Requirement Graph evaluation failed
- PRINCIPAL_
INACTIVE - DENY: The requesting principal is unknown to the tenant or disabled
- PROMPT_
INJECTION_ DETECTED - DENY: Prompt injection pattern detected in untrusted input
- PROVENANCE_
FAILURE - DENY: Provenance chain broken or unverifiable
- PROVIDER_
CREDENTIAL_ REJECTED - DENY: The connection’s credential is unavailable, or the provider rejected it as invalid, revoked or lacking permission
- PROVIDER_
ERROR - DENY: The provider failed or refused the call for a reason other than its credential
- PROVIDER_
RESPONSE_ TOO_ LARGE - DENY: A provider response exceeded the adapter’s size limit and was not read
- READBACK_
MISMATCH - DENY: The adapter’s read-back of the provider does not match the proposed effect, so the outcome is FAILED
- SAFEDEP_
DEGRADED_ NARROWING - ESCALATE: Safe Deprecation classified the hazard as recoverable degraded narrowing
- SAFEDEP_
DEPRECATED_ READONLY - DENY: Safe Deprecation classified the hazard as read-only deprecation
- SAFEDEP_
TERMINAL_ FREEZE - DENY: Safe Deprecation classified the hazard as terminal freeze
- SANDBOX_
VIOLATION - DENY: Effect exceeds sandbox boundary
- SCHEMA_
VIOLATION - DENY: Request does not conform to schema
- SEMANTIC_
THREAT_ REVIEW_ REQUIRED - ESCALATE: Configured deterministic semantic advisory requires human review
- SESSION_
RISK_ MEMORY_ DENY - DENY: Session trajectory risk exceeded the deterministic authorization threshold
- STEP_
UP_ REQUIRED - DENY: Approving a high-risk, irreversible or authority-widening effect needs a step-up assertion the request did not carry
- SYSTEM_
FROZEN - DENY: System is in global freeze state — all actions denied
- TAINTED_
CREDENTIAL_ ACCESS_ DENY - DENY: Credential or token access attempted from tainted source
- TAINTED_
DATA_ EGRESS_ DENY - DENY: Data egress or exfiltration attempted from tainted source
- TAINTED_
HIGH_ RISK_ ESCALATE - ESCALATE: High-risk effect from tainted source requires human approval
- TAINTED_
INPUT_ HIGH_ RISK_ DENY - DENY: High-risk effect denied due to tainted/untrusted input source
- TAINTED_
PRIVILEGED_ INVOKE_ DENY - DENY: Privileged agent invocation attempted from tainted source
- TAINTED_
SOFTWARE_ PUBLISH_ DENY - DENY: Software publish or release attempted from tainted source
- TEMPORAL_
INTERVENTION - ESCALATE: Time-based intervention triggered
- TEMPORAL_
THROTTLE - ESCALATE: Rate limit or cooldown active
- TENANT_
ISOLATION - DENY: Cross-tenant access violation
- UNICODE_
OBFUSCATION_ DETECTED - DENY: Unicode obfuscation (zero-width chars, homoglyphs) detected
- VERIFICATION_
FAILURE - DENY: Cryptographic verification failed
Functions§
- is_
registered - Whether
codeis in the registry.