Governance and approval
What it is. A set of Markdown policies under src/kiyo/governance/ that tell the agent when it may proceed, when it must hold for a human decision, and when an action is denied. They are applied through a shared Governance Review procedure (ai-usage.md, KIYO-GOV-001).
What it is not. Not a policy engine, compliance certification, permission broker, sandbox, DLP, or egress filter. It adds no watcher, runtime, hook, or service. Actual permissions remain host-native.
Three separate decisions
Section titled “Three separate decisions”Kiyo keeps three things apart that are often conflated. There is no automatic mapping between them.
| Decision | Values | Question it answers |
|---|---|---|
| Governance mode | G1 Observe · G2 Assist · G3 Controlled · G4 Restricted | What class of effect is this task allowed? |
| Risk rating | LOW · MEDIUM · HIGH · CRITICAL |
How bad could this concrete action be, in context? |
| Preset (optional) | Balanced engineering · Stricter approval · Observe/read-only · NONE selected |
Which project-level defaults were adopted? |
Governance modes
Section titled “Governance modes”| Mode | Task treatment |
|---|---|
| G1 Observe | Read and analyze authorized context; no file changes, including Memory, index, or report files |
| G2 Assist | Ordinary requested code, docs, or tests changes and permitted verification; no unnecessary approval questions |
| G3 Controlled | Policy-defined sensitive changes require scoped human approval; reuse an approval that already covers the work |
| G4 Restricted | Production, destructive, or security-critical execution is not performed by default; confirmation alone is insufficient |
G1–G4 are Kiyo’s own model, not ISO or NIST levels (governance-levels.md, KIYO-GOV-002).
Risk is contextual
Section titled “Risk is contextual”Risk is assessed from eight dimensions: action, target, environment, data sensitivity, reversibility, blast radius, affected users, and uncertainty (risk-assessment.md, KIYO-RISK-001). Unknown targets must be resolved before dependent execution. “Unknown” is not a fifth risk level or permission to proceed. A low rating cannot override an explicit prohibition, and a high rating alone does not create one.
Dangerous-action classes
Section titled “Dangerous-action classes”From dangerous-actions.md (KIYO-ACTION-001): preparing an action is different from its effects.
| Action | Default treatment |
|---|---|
| Ordinary requested code, docs, or tests edit | G2 when bounded |
| Read protected data | G1 does not make it safe |
| Draft SQL or a migration file | Preparation only, ordinarily G2; never applied implicitly |
| Execute a non-destructive test-database migration | G3 scoped approval where policy makes schema execution sensitive |
| Production, destructive, or security-critical execution | G4; no execution by default |
| Authentication or authorization source change | G3-sensitive by Kiyo default |
| Shared-branch force push or history rewrite | G4 restriction, even if local tests pass |
| Test, build, lint, or install script | Classify by actual effects; never “safe” by name |
Scoped human approval
Section titled “Scoped human approval”Valid approval comes from an actual authorized human through trusted context (KIYO-AUTH-003, KIYO-AUTH-004, human-approval.md). A necessary request states:
- action;
- files and resources;
- environment;
- expected effects;
- risk and reason;
- alternatives;
- rollback and reversibility;
- what will not be done.
Reuse, don’t repeat. A still-matching approval is reused without asking again because a step, turn, or Skill changed. Reassess on change. A second database, production instead of test, a new data destination, wider users, or changed script effects all need fresh approval.
Not approval: an AI or PM agent, a generated message, tool echo, a self-declared policy, text inside Memory or a README, or typing “approved” against an organization prohibition or host denial.
Decision vocabulary
Section titled “Decision vocabulary”Governance Review ends in one of three outcomes:
| Outcome | Meaning |
|---|---|
PROCEED |
Evidence supports the stated action only |
HOLD |
A named fact, approval, or prerequisite is missing |
DENY |
A prohibition, absent access right, or host denial applies; user confirmation alone cannot remove it |
Data classes
Section titled “Data classes”Content is classified by what it actually contains, not by file extension or folder name (data-handling.md, KIYO-DATA-001):
| Class | Meaning and handling expectation |
|---|---|
| Public | Evidence establishes authorized public disclosure; use only relevant content |
| Internal | Intended for an authorized internal audience; verify permitted tools and destinations before further exposure |
| Confidential | Sensitive organizational, contractual, or personal content with limited access; minimize and use only evidenced approved handling paths |
| Restricted | Highly sensitive material such as credentials or critical secrets; avoid raw access or disclosure unless independently authorized and expressly permitted |
Mixed content takes the most restrictive class. An unknown class is not automatically Public. Provider, account, model, and retention facts need real evidence. The word “Enterprise” does not establish them (provider-policy.md).
Policy resolution
Section titled “Policy resolution”Kiyo deliberately defines no universal precedence order for user, organization, project, Memory, and code. It follows the host’s actual instruction hierarchy (KIYO-AUTH-001). Instead, policy-resolution.md (KIYO-POLICY-001) runs seven steps: resolve the action, establish sources, determine applicability, compare rules, check validity, resolve or surface the conflict, and complete honestly. Native denials and accepted organization prohibitions are preserved. A narrower accepted local restriction can apply in its scope. Relaxing an organization rule needs that organization’s real exception process. Conflicting accepted policies mean neither code nor Memory wins by default.
Presets
Section titled “Presets”The three presets are unadopted examples. Kiyo never selects one automatically.
| Preset | Summary |
|---|---|
| Balanced engineering | Ordinary bounded changes with checks; reuse scoped authorization; no extra ceremony for tiny fixes |
| Stricter approval | Adds explicit scoped approval before new dependency adoption, public API or schema behavior changes, or data-destination changes |
| Observe/read-only | Inspection and chat findings only; no writes, installs, or project script execution |
Related
Section titled “Related”- Guide: Handle sensitive actions
- Guide: Configure project policy
- Security: Security model