mirror of
https://github.com/rcourtman/Pulse.git
synced 2026-10-03 12:42:43 +00:00
Recover live Patrol approvals for Assistant handoffs
This commit is contained in:
@@ -134,7 +134,10 @@ lifecycle evidence, and retry/idempotency handling must not create duplicate
|
||||
lifecycle events. Approval or rejection decisions for those plans must flow
|
||||
through `POST /api/actions/{id}/decision`, which records API-owned audit and
|
||||
lifecycle evidence only; lifecycle surfaces must not treat approval as
|
||||
implicit command execution or define a parallel execution handoff. When a
|
||||
implicit command execution or define a parallel execution handoff. Assistant
|
||||
handoffs that recover a live Patrol approval by finding ID are still AI/runtime
|
||||
review context only; agent lifecycle surfaces must not treat that recovered
|
||||
approval reference as an agent command grant or host-execution shortcut. When a
|
||||
planned resource capability is actually executed from an agent-lifecycle
|
||||
surface, that handoff must route through `POST /api/actions/{id}/execute` so
|
||||
the API-owned action audit records `executing` before dispatch and the
|
||||
|
||||
@@ -241,13 +241,15 @@ runtime cost control, and shared AI transport surfaces.
|
||||
Those timeline facts remain read-only explanation context and do not grant
|
||||
action authority. The runtime may also persist structured pending-action and
|
||||
approval references from the same investigation record as
|
||||
model-context metadata, but those references are review context only: they
|
||||
must not include raw command text, must not grant approval or execution
|
||||
authority, and must route any operator decision back through the governed
|
||||
approval/remediation flow. When
|
||||
those references include an approval ID, Assistant runtime may refresh a
|
||||
current status snapshot from the canonical approval store on each turn, but
|
||||
it must enforce org scoping and still omit the approval command payload.
|
||||
model-context metadata, and the API handoff builder may recover the current
|
||||
live Patrol investigation-fix approval by finding ID when the durable record
|
||||
does not yet carry the latest approval ID. Those references are review
|
||||
context only: they must not include raw command text, must not grant
|
||||
approval or execution authority, and must route any operator decision back
|
||||
through the governed approval/remediation flow. When those references include
|
||||
an approval ID, Assistant runtime may refresh a current status snapshot from
|
||||
the canonical approval store on each turn, but it must enforce org scoping
|
||||
and still omit the approval command payload.
|
||||
When those references resolve to a governed action plan or action audit,
|
||||
Assistant runtime must hydrate the canonical action ID, lifecycle state,
|
||||
requester, capability, approval policy, plan expiry, preflight/dry-run
|
||||
|
||||
@@ -316,11 +316,15 @@ the canonical monitored-system blocked payload.
|
||||
Context]`, structured handoff resources, related root-cause/correlation
|
||||
finding context, and structured handoff actions model-only, with the
|
||||
briefing summarizing operator next steps, latest lifecycle event, and
|
||||
governed action posture without raw command text. Related finding context
|
||||
must resolve from the current unified finding store, stay bounded and
|
||||
deduplicated, include current recency and latest lifecycle facts, and seed
|
||||
only structured handoff resources for canonical policy, state, topology,
|
||||
and timeline hydration. Chat execution owns
|
||||
governed action posture without raw command text. Structured handoff action
|
||||
references may use the current live Patrol investigation-fix approval for
|
||||
the finding when that approval is newer than the approval ID on the durable
|
||||
record, but the payload may carry only IDs, status/risk/target metadata, and
|
||||
fix/action references, never the approval command payload. Related finding
|
||||
context must resolve from the current unified finding store, stay bounded
|
||||
and deduplicated, include current recency and latest lifecycle facts, and
|
||||
seed only structured handoff resources for canonical policy, state,
|
||||
topology, and timeline hydration. Chat execution owns
|
||||
resource-policy sanitization of the assembled model-only handoff before
|
||||
prompt injection, so API payload builders may pass structured product
|
||||
context without turning raw resource identity into user-authored text or
|
||||
@@ -830,12 +834,14 @@ the canonical monitored-system blocked payload.
|
||||
explanation data and must not become saved user text or action authority. The
|
||||
backend may also carry structured
|
||||
pending-action and approval references from the investigation record into chat
|
||||
execution, but those references must omit raw proposed-fix commands, remain
|
||||
model-only review context, and leave approval/execution authority with the
|
||||
governed approval and remediation APIs. Chat execution may refresh approval
|
||||
status snapshots for those references from the canonical approval store, but
|
||||
that snapshot is read-only, org-scoped, and must not expose or infer the raw
|
||||
command. When the reference resolves to a governed action plan or action
|
||||
execution, and may recover the current live Patrol investigation-fix approval
|
||||
for the finding when the durable record has no current approval ID, but those
|
||||
references must omit raw proposed-fix commands, remain model-only review
|
||||
context, and leave approval/execution authority with the governed approval
|
||||
and remediation APIs. Chat execution may refresh approval status snapshots for
|
||||
those references from the canonical approval store, but that snapshot is
|
||||
read-only, org-scoped, and must not expose or infer the raw command. When the
|
||||
reference resolves to a governed action plan or action
|
||||
audit, chat execution must hydrate the canonical action ID, lifecycle state,
|
||||
requester, capability, approval policy, plan expiry, preflight/dry-run
|
||||
summary, and terminal success/failure state from the action-audit store so
|
||||
|
||||
@@ -107,13 +107,16 @@ Patrol-specific presentation helpers.
|
||||
only structured action references such as approval ID, fix ID, risk, target,
|
||||
and resource identity; approval and execution authority stays with the
|
||||
governed approval/remediation surfaces. Assistant may refresh the referenced
|
||||
approval's current status for review, but Patrol presentation must still keep
|
||||
command payloads inside governed approval/remediation context rather than
|
||||
rendering them as handoff copy. Assistant may also hydrate the referenced
|
||||
action plan or action audit so the handoff explains current action lifecycle
|
||||
state, requester, capability, approval policy, plan expiry, preflight/dry-run
|
||||
posture, and terminal success/failure without treating approval as execution
|
||||
authority or exposing raw command/execution payloads. Assistant may also
|
||||
approval's current status for review, and the backend handoff builder may
|
||||
recover a live pending Patrol investigation-fix approval by finding ID when
|
||||
the durable record lacks the current approval reference, but Patrol
|
||||
presentation must still keep command payloads inside governed
|
||||
approval/remediation context rather than rendering them as handoff copy.
|
||||
Assistant may also hydrate the referenced action plan or action audit so the
|
||||
handoff explains current action lifecycle state, requester, capability,
|
||||
approval policy, plan expiry, preflight/dry-run posture, and terminal
|
||||
success/failure without treating approval as execution authority or exposing
|
||||
raw command/execution payloads. Assistant may also
|
||||
enrich that same handoff with refreshed unified finding and
|
||||
investigation-record state, canonical resource-policy guidance, current
|
||||
canonical resource-state and capability context, canonical
|
||||
|
||||
@@ -424,7 +424,9 @@ bypass the API fail-closed execution gate.
|
||||
finding no longer resolves is adjacent AI/runtime invalidation, not a
|
||||
recovery freshness or restore-support decision. Structured action or
|
||||
approval references carried by that handoff are also adjacent AI/runtime
|
||||
review metadata only. Unified finding lifecycle facts, latest lifecycle
|
||||
review metadata only, including when Assistant recovers the current live
|
||||
Patrol approval by finding ID before building model-only action context.
|
||||
Unified finding lifecycle facts, latest lifecycle
|
||||
event briefing lines, and detailed lifecycle context carried by the same
|
||||
handoff remain Patrol/AI review metadata and must not become backup recency,
|
||||
restore support, or storage-local lifecycle state. Primary finding
|
||||
|
||||
Reference in New Issue
Block a user