Skip to content

Configure project policy

Goal: persistent, project-local Kiyo preferences that agents can read, with authority that is real rather than self-declared. Specification: framework/project-configuration.md (KIYO-CONFIG-001) · Templates: project context, project policy, organization policy

New projects use .kiyo/policy.md by default. .kiyo/config.md is an accepted equivalent if you choose it explicitly. Create only one. An existing file is reused; Kiyo never renames or migrates it automatically.

You do not need to recreate or re-confirm this file for each task. A missing config is a scoped Unknown, not a universal blocker.

The project-context record uses these logical fields. They are content expectations, not a machine schema.

.kiyo/policy.md (illustrative)
# Kiyo project context
This record describes project-local Kiyo context. It does not override native
instructions, accepted organization policy or the user's actual authorization.
- Project/component scope: orders-service repository root
- Framework version reference: UNKNOWN
- Canonical Memory index: memory/index.md
- Setup authority/source: initialize request in session on 2026-09-29
- Selected profiles: dotnet (src/Orders), postgresql (db/)
- Profile evidence: global.json; src/Orders/Orders.csproj; db/migrations/
- Governance preferences: Balanced engineering — PROPOSED
- Approved policy references: none established in inspected scope
- Reporting language: English (user preference in session)
- Evidence output location: not configured
- Confirmed constraints: none established in inspected scope
- Unknowns/limitations: deployment topology; CI configuration not inspected

Paths are relative to the config file, so memory/index.md resolves to .kiyo/memory/index.md. Put durable facts in Memory entries; this file holds locators and preferences only.

Preset Choose when
Balanced engineering You want ordinary bounded changes with checks and minimal ceremony
Stricter approval You want explicit approval before new dependencies, public API or schema changes, or new data destinations
Observe/read-only Agents should only inspect and report in this project
NONE selected You have no preference; this is valid

A preset is recorded as a governance preference. It is never selected automatically, never inferred from your industry, and never enables host permissions. Preset, governance mode (G1–G4), and risk remain three separate decisions.

To make an organization or project policy authoritative, reference it with acceptance evidence:

Illustrative entries
- Approved policy references: docs/policies/ai-usage.md §3 — accepted by
engineering leadership, record ENG-POL-12 (scope: this repository)
- Candidate policy references: docs/policies/draft-data.md — PROPOSED

A bare link or an APPROVED label is insufficient. Policy authority comes from its actual source and acceptance, not from the file declaring itself authoritative (KIYO-AUTH-002).

  • Never weaken policy to make the current task pass.
  • A monorepo component’s exception does not apply to its siblings.
  • A moved or broken reference is unresolved. Kiyo does not fetch a replacement or choose by date.
  • Recheck after branch, worktree, or component switches, or revoked authority. There is no watcher.
  • No delta means no write or date refresh.
Check this selected policy for missing authority and conflicts.

The Security Skill’s governance submode reports completeness and conflicts read-only. It does not make the policy effective or fix it.