Expand description
Versioned, frontend-neutral security Plan contracts.
A Plan is a reviewable semantic description bound to captured source and state snapshots. It is deliberately not an executable action IR and never carries file content, environment values, secret plaintext, or raw command arguments.
Structs§
- Permission
Resolution V1 - Permission derivation for one complete operation.
- Permission
SetV1 - A stable, sorted, duplicate-free permission set.
- Plan
Approval V1 - Explicit frontend approval for one exact ready Plan.
- Plan
Fingerprint V1 - Plan
Inputs V1 - Plan
Step V1 - PlanV1
- Snapshot
Digest Builder V1 - Deterministic snapshot digest builder. Observation ordering does not affect the result, while duplicate labels fail closed.
- Snapshot
Digest V1 - A SHA-256 digest over framed snapshot observations.
Enums§
- Environment
Sensitivity V1 - Filesystem
Access V1 - Network
Scope V1 - Permission
V1 - A reviewable capability required by a planned operation.
- Plan
Action V1 - Plan
Approval Error - Plan
Operation V1 - Snapshot
Digest Error