← All extensions
Policy banner

Policy

ivyx✓

See the rules this project enforces, what each one did today, and what a call would get

Policy

See the rules this project enforces, what each one did today, and what a call would get.

This panel defines nothing. The rules are the ones the substrate loaded from .punica/policy.yaml into the kernel at boot; what each rule did is a group-by over the audit trail; and the test form asks the kernel's own evaluator, with the same agent-mode profile the gate applies, for the actor the call would carry.

What you can do

  • See the rules — one row per rule in the file's order, with what it selects (an id, an action, everything), its own sentence, and what it did today: held, denied, allowed.
  • Open a rule — its conditions on the arguments, its approval, its scope, and when it last fired.
  • Test a call — a capability id and arguments, as the agent or as a person, and the verdict the gate would give with the rule that decided it. Nothing is dispatched.
  • See the mode — whether the kernel is in suggest or execute, and the sentence that matters: project rules apply in every mode.
  • Reload or open the file — the header reloads .punica/policy.yaml into the kernel, or opens it in the editor.
  • Ask programmatically — policy.explain returns the same verdict through the capability gateway.

Getting started

Open the panel from the palette (Policy: Open), through the policy.open capability, or from the Policy row in the agent window's rail. Without a .punica/policy.yaml the panel says so and ivyx init writes one.

What it does not do

It does not edit rules. A rule that travels in the commit is a rule that shows up in the diff and gets reviewed, so the file is edited as a file; the panel opens it and reloads it.

It does not run the call it tests. The verdict comes from the kernel's evaluator and the agent-mode profile, the two things the gate reads, and the test never reaches the gateway.