docs(agent-builder): current-value pointers — CA-D11 VM boundary + CA re-scope + A1/A3/A7 decided; ordering superseded by claude-config GAMEPLAN
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01X9iCzmxK2zbb8H1Ld3f8AN
This commit is contained in:
@@ -1,5 +1,8 @@
|
||||
# Gameplan — Agent-Sudo + secrets-proxy to fully deployed
|
||||
|
||||
> **CURRENT VALUE (2026-09-08):** the **ordering in §5 is SUPERSEDED** by `~/Desktop/claude/claude-config/decisions/GAMEPLAN_security-infra-deploy.md` (Step 0 boot-recovery → Step 1 rotate row-192 key → S1/S2 → claude-runner VM → A1/A2/A7/A5). Decisions: **A1 = (a)**, **A3 = (c)**, **A7(A) = no**. Task definitions A1–A7/S1–S4 below remain valid.
|
||||
|
||||
|
||||
**Written:** 2026-07-15 20:10 · **Author:** Claude (Opus 4.8) · **Status:** ACTIVE PLAN
|
||||
**Why now:** 2026-07-15 is the LAST day dedicated to this work. After this, time goes to
|
||||
business development (revenue) + other projects. Everything here is scoped so a background
|
||||
|
||||
@@ -1,5 +1,8 @@
|
||||
# Constrained Autonomy for Claude Code — Design Decisions
|
||||
|
||||
> **CURRENT VALUE (2026-09-08):** two amendments DECIDED in `~/Desktop/claude/claude-config/decisions/DECISIONS.md`: **CA-D11** — the agent runs inside an **Incus KVM VM `claude-runner` on server-01** (autonomous runner first; brokers are the only host reach), and **CA re-scope** — the hook stays **deny-only + training log**; **D2 structural classifier, CA-P1-full, CA-P4 promotion are DROPPED** (Claude Code auto mode does the judgment half). CA-P3/CA-P5 stay. D1's tier-2/3→daemon routing is retained only as deterministic denies + broker calls. Executable plan: `claude-config/decisions/GAMEPLAN_security-infra-deploy.md`.
|
||||
|
||||
|
||||
**Status:** DESIGN LOCKED (grill-me 2026-07-14). Not yet built. Build = phased background agents (CA-P0…P5), mirroring the Agent-Sudo build model. Do NOT implement ad hoc — follow this record.
|
||||
|
||||
**Driving insight (user):** a permission prompt the human rubber-stamps — especially a truncated command they can't read or don't understand — adds *no* safety. It is the same theater as the NTFY approval gate we removed from Agent-Sudo. Kill the theater; replace it with an ENFORCED code constraint layer. Governing memory: `feedback_autonomous_security_constrain_not_gate` (constrain capability, don't gate access), `feedback_evolution_by_default`, `feedback_always_include_training_loop`, `feedback_secrets_via_proxy_only`.
|
||||
|
||||
Reference in New Issue
Block a user