Expand description
Whether a command may run now, and if not, what would let it (spec §14.3).
PolicySnapshot::decide in
core answers the narrow question: does this origin satisfy this policy?
PolicyEngine answers the question a turn actually asks, which has three
more inputs — the constraints the user put on the turn (“do not submit
anything yet”), the orchestration mode, and the configuration — and which has
to produce not just a verdict but the card that would change it.
§Gates, in order
-
Mode (§11.4). A sandboxed run is not eligible for destructive, irreversible or externally regulated commands at all. No card helps.
-
Constraints (§10.4). Evaluated in a fixed order so the same set of constraints always names the same blocker:
Constraint Blocks DoNotSubmitanything that leaves the system: RiskClass::ExternalRegulated, or anAtomicityScope::ExternalSagaDoNotDeleteRiskClass::DestructiveDraftOnlyanything above RiskClass::ReversibleLowRiskNoExternalEffectsRiskClass::ExternalRegulatedAskBeforeApplyingnothing — it raises ConfirmationPolicy::NonetoConfirmationPolicy::ExplicitClickApplyOnlyIfnothing here; the reducer turns it into a clarification -
Policy (§14.3, I12). The core snapshot decides, against the policy as the constraints left it.
§An absent policy is a conservative policy
PolicyRequest::policy is an Option because a domain that has not
classified a command is a real situation. It is treated as
CommandPolicy::conservative: irreversible, explicit click, per case,
server receipts only. Silence is never permission.
Modules§
- reason
- Reason keys the engine adds to the ones in
turnframe_core::policy::reason.
Structs§
- Confirmation
Copy - Server-authored copy for the cards the engine builds.
- NoReview
Diff - A diff builder that shows nothing, so review cards degrade to confirmations.
- Policy
Engine - Applies constraints, mode and policy to one command, and builds the card that would unblock it.
- Policy
Request - One command as the policy engine sees it.
Enums§
- Block
Reason - Why a command may not run, when no card the end user can click would help.
- Policy
Outcome - What the engine decided about one command.
Constants§
- CONFIRM_
OPTION_ ID - Option identifier of the confirming CTA on a card the engine builds.
- DECLINE_
OPTION_ ID - Option identifier of the declining CTA on a card the engine builds.
Traits§
- Review
Diff Builder - Builds the before/after lines of a
InteractionKind::ReviewChangescard.