← Frontier InfraCONTENT HISTORYWHAT CHANGED · RULE-BASED ANALYSIS
Update to Frontier Infra
Snapshot Sep 30, 2026 · 23:14 UTC · version 0.3.2
Collection source: not recorded for this historical snapshot.
First saved snapshot
No earlier snapshot is available to establish a change.
Compare saved observations
Download comparison JSONFull technical diff · 0 changed fields
Full snapshot data
{
"name": "design-agent-governance",
"description": "Design or review governance for an AI harness, including authority ceilings, verifier trust and freshness, mutation-path coverage, reversibility, human gates, operator override, audit receipts, budgets, escalation, and policy tests.",
"included_files": [
{
"relative_path": "agents/openai.yaml",
"size_in_bytes": 217
}
],
"skill_md_contents": "---\nname: design-agent-governance\ndescription: Design or review governance for an AI harness, including authority ceilings, verifier trust and freshness, mutation-path coverage, reversibility, human gates, operator override, audit receipts, budgets, escalation, and policy tests.\n---\n\n# Design agent governance\n\nGovern the target application's runtime principals and effects. Do not treat\nthe coding assistant, its host permissions, or its implementation process as\npart of that governance plane unless the user explicitly asks for a developer-\nworkflow integration.\n\nRead `../../references/system-architecture.md`, `../../references/threat-model.md`, and `../../docs/runtime-health-contract.md`. Use `../../assets/governance-policy.yaml` and `../../assets/runtime-health-manifest.yaml` as starting artifacts.\n\n## Workflow\n\n1. Inventory every durable mutation, including message sends, model calls with spend, queue creation, filesystem writes, database updates, background jobs, and reads with side effects.\n2. Assign each action a scope, base trust requirement, reversibility status, verified rollback reference when applicable, and human-gate rule when irreversible.\n3. Define `effective_autonomy = min(operator_dial, contract_ceiling, scoped_verifier_trust)` and calculate the required trust before every effect.\n4. Make missing/stale/unqualified verifier trust zero and missing reversibility irreversible.\n5. Route every path through one gate or an expiring scope-bound gate token. Prohibit durable admin bypasses.\n6. Define contract ratification, hash, scope, expiry, revocation, and immutable acceptance enforcement at the driver boundary.\n7. Provide out-of-band operator halt and dial-down with an independent receipt sink and a measured effect SLO.\n8. Define append-only governance events, budgets, ACK escalation, quarantine, health, and anomaly policies.\n9. Model runtime health as four layers: `process`, `scheduler`, `execution`, and `governance`. Aggregate health must fail closed unless all four layers have fresh passing checks; a green process heartbeat must not mask a dead scheduler, blocked provider execution, or missing gate.\n10. Validate sample health contracts with the published reducer when a JSON health artifact exists (`npm install @frontier-infra/protocol` in the project):\n\n ```sh\n node -e \"import('@frontier-infra/protocol').then(async ({evaluateRuntimeHealth}) => console.log(JSON.stringify(evaluateRuntimeHealth(JSON.parse(require('fs').readFileSync(process.argv[1],'utf8'))), null, 2)))\" <health-contract.json>\n ```\n\n11. Write allow, deny, expired-verifier, forged-rollback, expired-human-gate, direct-bypass, and dead-workforce health tests.\n\n## Output\n\nReturn the governance policy, mutation matrix, trust-role matrix, event schema, runtime health contract, override runbook, and negative-test plan. Distinguish policy prose from deterministic enforcement.\n"
}SHA-256: 476b731a537b65ec485bb0f1d003f79ad2378de4dcb3b39116ea4e98a9808beb