Expand description
Orchestration modes and runtime configuration (spec §11.1, §11.4, Appendix A).
Two things live here. The first is OrchestrationMode: how much rope the
model gets before the deterministic pipeline takes over. The second is
OrchestratorConfig: the knobs an application turns, every one of which
defaults to the careful setting.
§Safety settings are not knobs
A few fields exist only so that a configuration file which tries to disable
them fails loudly instead of quietly working. OrchestratorConfig::validate
refuses reject_unknown_fields = false, require_evidence_for_mutations = false and fail_closed_on_policy_store_error = false, because the library
does not implement the permissive behaviour at all: the plan types deny
unknown fields unconditionally, evidence is validated unconditionally, and
there is no fail-open path for an unavailable policy source (I19). A config
that asks for the permissive behaviour is a config whose author believes
something untrue, and that is worth an error.
Sandboxed autonomy goes further: the variant cannot be written down without
a SandboxAcknowledgement, whose only constructor is named after what it
gives up and logs a warning when called.
Structs§
- Attachment
Config - How much of a turn’s files reaches a model.
- Execution
Config - How commands are executed (Appendix A, spec §13.4, §16).
- Interaction
Config - How server-created cards behave (spec §15).
- Narration
Config - How the assistant is allowed to talk (spec §18, §19).
- Observability
Config - What the runtime records about itself (spec §26).
- Orchestrator
Config - Everything the runtime needs to know before it handles a turn (Appendix A).
- Privacy
Config - What may leave the runtime and for how long it is kept (spec §25.5).
- Resource
Budget - What a sandboxed autonomous run may spend before it is cut off.
- Sandbox
Acknowledgement - Proof that the caller knows what
OrchestrationMode::SandboxedAutonomousgives up. - Understanding
Config - How a turn is understood: the limits on what it may ask, the conversation shown, the budget of its model tasks, which acts are verified, and each task kind’s settings.
Enums§
- Config
Error - A configuration value the library refuses to work with.
- Orchestration
Mode - How much autonomy the model gets: which risk classes are eligible at all (§11.4).
Constants§
- SANDBOX_
ACKNOWLEDGEMENT - The exact phrase that acknowledges sandboxed autonomy, on the wire and in
the name of
SandboxAcknowledgement::i_accept_unreviewed_autonomous_writes.