Policy
ivyx✓
See the rules this project enforces, what each one did today, and what a call would get
Policy
See the rules this project enforces, what each one did today, and what a call would get.
This panel defines nothing. The rules are the ones the substrate loaded from
.punica/policy.yaml into the kernel at boot; what each rule did is a group-by
over the audit trail; and the test form asks the kernel's own evaluator, with
the same agent-mode profile the gate applies, for the actor the call would
carry.
What you can do
- See the rules — one row per rule in the file's order, with what it selects (an id, an action, everything), its own sentence, and what it did today: held, denied, allowed.
- Open a rule — its conditions on the arguments, its approval, its scope, and when it last fired.
- Test a call — a capability id and arguments, as the agent or as a person, and the verdict the gate would give with the rule that decided it. Nothing is dispatched.
- See the mode — whether the kernel is in suggest or execute, and the sentence that matters: project rules apply in every mode.
- Reload or open the file — the header reloads
.punica/policy.yamlinto the kernel, or opens it in the editor. - Ask programmatically —
policy.explainreturns the same verdict through the capability gateway.
Getting started
Open the panel from the palette (Policy: Open), through the policy.open
capability, or from the Policy row in the agent window's rail. Without a
.punica/policy.yaml the panel says so and ivyx init writes one.
What it does not do
It does not edit rules. A rule that travels in the commit is a rule that shows up in the diff and gets reviewed, so the file is edited as a file; the panel opens it and reloads it.
It does not run the call it tests. The verdict comes from the kernel's evaluator and the agent-mode profile, the two things the gate reads, and the test never reaches the gateway.