Expand description
Typed command envelopes, origins, risk and confirmation policy (spec §14).
§Why there is no model-proposal origin
CommandOrigin deliberately has no variant for “the model proposed it”.
A model output is a proposal (I9); it becomes a command only after evidence
validation, target resolution and reduction. When that pipeline produces a
low-risk command straight from the user’s words, the origin is
CommandOrigin::DirectSafeUserAct carrying the digest of the validated
evidence, so the authority is the user’s text, not the model. Anything more
consequential needs a server-issued origin: a confirmed interaction, an
internal policy, or a verified external callback (I12).
Structs§
- Command
Batch - A group of envelopes executed under one atomicity scope.
- Command
Envelope - A typed command with everything the executor and the journal need (spec §14.2).
- Command
Policy - The policy attached to a command (spec §14.3).
- Idempotency
Key - Stable idempotency key of a command (I14).
Enums§
- Atomicity
Scope - How commands are grouped for all-or-nothing execution (spec §13.4).
- Claim
Mode - How the assistant may talk about the outcome of a command (spec §17.2).
- Command
Origin - Who or what authorized a command (spec §14.2).
- Confirmation
Policy - Confirmation a command requires before execution (spec §14.3).
- Resolution
Channel - How a user’s answer to an interaction reached the server (spec §15.7).
- Risk
Class - Risk class of a command, ordered from harmless to regulated (spec §14.3).
Functions§
- origin_
satisfies - Pure check of I12: does
originsatisfypolicy?