← Files AI PsychiatryARCHIVED FILE

docs/ai/approval-boundaries.md

1.71 KB · Oct 2, 2026 · 00:30 UTC

↓ Download file

# Approval Boundaries

Maximum autonomy is not unlimited authority. `never-stop` may proceed automatically on routine and material decisions (see [autonomous decision-making](autonomous-decision-making.md)), but a fixed set of conditions is always a hard approval gate: destructive or irreversible operations, deleting or irreversibly migrating user data, production deployment, public release or marketplace submission, a git push, merge, or PR when not already authorized, sending external messages, payment or financial commitment, permission or access-control changes, exposing secrets or credentials, production infrastructure changes, legal or regulatory decisions, security trade-offs with no safe inferable answer, a platform-enforced permission prompt, and a credential that genuinely does not exist.

Permission bypass is forbidden without exception: the framework never alters its own permissions, enables a permission-bypass mode, uses permission-skipping flags, silently authorizes a destructive or production action, fabricates a missing credential, uses a secret outside its authorized purpose, or treats the absence of permission as permission. A routine decision cannot be relabeled a hard gate to avoid deciding, and a hard gate cannot be relabeled routine to bypass approval — both are anti-gaming violations, not judgment calls.

Reaching a hard gate never stops the rest of the task: every independent piece of mandatory work finishes first, the exact pending action is prepared, and only the minimum required approval or missing value is requested. See [`never-stop`](../../skills/all-the-medicine/references/skills/never-stop/never-stop.md) and [`.ai/policies/approval-gates.json`](../../.ai/policies/approval-gates.json).

SHA-256: 5590470b496f42a4e1767a7fb118520b16cf6b6a6299b681540294687f29c4e4