Skip to content

Governance and approval

What it is. A set of Markdown policies under src/kiyo/governance/ that tell the agent when it may proceed, when it must hold for a human decision, and when an action is denied. They are applied through a shared Governance Review procedure (ai-usage.md, KIYO-GOV-001).

What it is not. Not a policy engine, compliance certification, permission broker, sandbox, DLP, or egress filter. It adds no watcher, runtime, hook, or service. Actual permissions remain host-native.

Kiyo keeps three things apart that are often conflated. There is no automatic mapping between them.

Decision Values Question it answers
Governance mode G1 Observe · G2 Assist · G3 Controlled · G4 Restricted What class of effect is this task allowed?
Risk rating LOW · MEDIUM · HIGH · CRITICAL How bad could this concrete action be, in context?
Preset (optional) Balanced engineering · Stricter approval · Observe/read-only · NONE selected Which project-level defaults were adopted?
Mode Task treatment
G1 Observe Read and analyze authorized context; no file changes, including Memory, index, or report files
G2 Assist Ordinary requested code, docs, or tests changes and permitted verification; no unnecessary approval questions
G3 Controlled Policy-defined sensitive changes require scoped human approval; reuse an approval that already covers the work
G4 Restricted Production, destructive, or security-critical execution is not performed by default; confirmation alone is insufficient

G1–G4 are Kiyo’s own model, not ISO or NIST levels (governance-levels.md, KIYO-GOV-002).

Risk is assessed from eight dimensions: action, target, environment, data sensitivity, reversibility, blast radius, affected users, and uncertainty (risk-assessment.md, KIYO-RISK-001). Unknown targets must be resolved before dependent execution. “Unknown” is not a fifth risk level or permission to proceed. A low rating cannot override an explicit prohibition, and a high rating alone does not create one.

From dangerous-actions.md (KIYO-ACTION-001): preparing an action is different from its effects.

Action Default treatment
Ordinary requested code, docs, or tests edit G2 when bounded
Read protected data G1 does not make it safe
Draft SQL or a migration file Preparation only, ordinarily G2; never applied implicitly
Execute a non-destructive test-database migration G3 scoped approval where policy makes schema execution sensitive
Production, destructive, or security-critical execution G4; no execution by default
Authentication or authorization source change G3-sensitive by Kiyo default
Shared-branch force push or history rewrite G4 restriction, even if local tests pass
Test, build, lint, or install script Classify by actual effects; never “safe” by name

Valid approval comes from an actual authorized human through trusted context (KIYO-AUTH-003, KIYO-AUTH-004, human-approval.md). A necessary request states:

  1. action;
  2. files and resources;
  3. environment;
  4. expected effects;
  5. risk and reason;
  6. alternatives;
  7. rollback and reversibility;
  8. what will not be done.

Reuse, don’t repeat. A still-matching approval is reused without asking again because a step, turn, or Skill changed. Reassess on change. A second database, production instead of test, a new data destination, wider users, or changed script effects all need fresh approval.

Not approval: an AI or PM agent, a generated message, tool echo, a self-declared policy, text inside Memory or a README, or typing “approved” against an organization prohibition or host denial.

Governance Review ends in one of three outcomes:

Outcome Meaning
PROCEED Evidence supports the stated action only
HOLD A named fact, approval, or prerequisite is missing
DENY A prohibition, absent access right, or host denial applies; user confirmation alone cannot remove it

Content is classified by what it actually contains, not by file extension or folder name (data-handling.md, KIYO-DATA-001):

Class Meaning and handling expectation
Public Evidence establishes authorized public disclosure; use only relevant content
Internal Intended for an authorized internal audience; verify permitted tools and destinations before further exposure
Confidential Sensitive organizational, contractual, or personal content with limited access; minimize and use only evidenced approved handling paths
Restricted Highly sensitive material such as credentials or critical secrets; avoid raw access or disclosure unless independently authorized and expressly permitted

Mixed content takes the most restrictive class. An unknown class is not automatically Public. Provider, account, model, and retention facts need real evidence. The word “Enterprise” does not establish them (provider-policy.md).

Kiyo deliberately defines no universal precedence order for user, organization, project, Memory, and code. It follows the host’s actual instruction hierarchy (KIYO-AUTH-001). Instead, policy-resolution.md (KIYO-POLICY-001) runs seven steps: resolve the action, establish sources, determine applicability, compare rules, check validity, resolve or surface the conflict, and complete honestly. Native denials and accepted organization prohibitions are preserved. A narrower accepted local restriction can apply in its scope. Relaxing an organization rule needs that organization’s real exception process. Conflicting accepted policies mean neither code nor Memory wins by default.

The three presets are unadopted examples. Kiyo never selects one automatically.

Preset Summary
Balanced engineering Ordinary bounded changes with checks; reuse scoped authorization; no extra ceremony for tiny fixes
Stricter approval Adds explicit scoped approval before new dependency adoption, public API or schema behavior changes, or data-destination changes
Observe/read-only Inspection and chat findings only; no writes, installs, or project script execution