Problem
Teams using OpenShell need PR review that explains how a change affects an agent's declared authority, identifies missing evidence, and follows Agents Shipgate's existing merge-review contract. A base-policy YAML diff can miss defaults, selected-file changes and provider contributions. A native containment result alone does not establish current inputs or merge authority.
Product outcome
A reviewer can point Agents Shipgate at supported OpenShell policy inputs, see a concrete before/after authority explanation, understand exactly what was and was not evaluated, and receive the established control route with evidence bound to the reviewed Git state.
Primary users: platform engineers maintaining agent environments, security reviewers approving authority changes, and coding agents preparing those changes.
Delivery plan
MVP — P1: explicitly selected local policy → versioned inventory → conservative semantic diff → replayable Git/receipt identity → existing check/verify review route.
Follow-ups — P2: explicit provider/global-policy composition and optional native prover evidence. These extend the supported claim; they are not prerequisites for releasing the honestly scoped document-review MVP.
P1/P2 here indicate proposed delivery order, not incident severity or a committed release date. Owners and scheduling remain unassigned.
MVP delivery issues
Follow-up delivery issues
Dependency order
MVP acceptance and release criteria
Product and engineering guardrails
Target fixtures and semantics initially at OpenShell v0.1.2; policy schema version 1 alone is not a runtime compatibility promise. Integrate through the host-boundary pipeline with typed grants and coverage. Keep the actual coding-agent caller independent from the enclosing OpenShell runtime.
Preserve Agents Shipgate's existing control and release-decision vocabulary. Do not infer business effects, authority, approvals or agent bindings from network/MCP permissions. Protect an operator's maximum boundary independently from a candidate policy.
Out of scope
Live gateway monitoring, automatic policy generation/application, credential retrieval, runtime enforcement attestation, broad deployment orchestration, or implementing a second containment solver. The optional prover follow-up uses native evidence through a separate explicit trust boundary.
Alternatives considered
- Generic YAML/text diffs are useful context but do not establish authority direction.
- A callable-tool adapter does not represent the runtime's permission relationships.
- Native proof alone lacks the PR scope, protected-boundary review and current-input identity required by the merge workflow.
References
Surface areas: input reader, CLI, host schemas, control/receipts, documentation.
This epic tracks both increments; the MVP release gate is only the four MVP issues. Close the epic when the follow-ups are completed or explicitly deferred with recorded rationale.
Implementation pull requests
All six implementation pull requests were approved and merged to main in the order below. Each rebased head passed fresh CI, and the final merged Git tree exactly matches the reviewed implementation. Delivery issues #943–#948 are closed.
Final implementation commit: 0e58e6ff2. The remaining acceptance/release checklist above is retained for release tracking; this merge does not publish a package or attest runtime deployment.
| Issue |
Pull request |
Scope |
| #943 |
#949 |
Explicit policy registration and typed inventory |
| #944 |
#950 |
Conservative declared-authority comparison |
| #945 |
#951 |
Git inputs, receipts and current-control currency |
| #946 |
#952 |
Check, preflight and verifier routing |
| #947 |
#958 |
Global policy and provider composition |
| #948 |
#959 |
Optional trusted native containment evidence |
Problem
Teams using OpenShell need PR review that explains how a change affects an agent's declared authority, identifies missing evidence, and follows Agents Shipgate's existing merge-review contract. A base-policy YAML diff can miss defaults, selected-file changes and provider contributions. A native containment result alone does not establish current inputs or merge authority.
Product outcome
A reviewer can point Agents Shipgate at supported OpenShell policy inputs, see a concrete before/after authority explanation, understand exactly what was and was not evaluated, and receive the established control route with evidence bound to the reviewed Git state.
Primary users: platform engineers maintaining agent environments, security reviewers approving authority changes, and coding agents preparing those changes.
Delivery plan
MVP — P1: explicitly selected local policy → versioned inventory → conservative semantic diff → replayable Git/receipt identity → existing check/verify review route.
Follow-ups — P2: explicit provider/global-policy composition and optional native prover evidence. These extend the supported claim; they are not prerequisites for releasing the honestly scoped document-review MVP.
P1/P2 here indicate proposed delivery order, not incident severity or a committed release date. Owners and scheduling remain unassigned.
MVP delivery issues
Follow-up delivery issues
Dependency order
MVP acceptance and release criteria
Product and engineering guardrails
Target fixtures and semantics initially at OpenShell v0.1.2; policy schema version 1 alone is not a runtime compatibility promise. Integrate through the host-boundary pipeline with typed grants and coverage. Keep the actual coding-agent caller independent from the enclosing OpenShell runtime.
Preserve Agents Shipgate's existing control and release-decision vocabulary. Do not infer business effects, authority, approvals or agent bindings from network/MCP permissions. Protect an operator's maximum boundary independently from a candidate policy.
Out of scope
Live gateway monitoring, automatic policy generation/application, credential retrieval, runtime enforcement attestation, broad deployment orchestration, or implementing a second containment solver. The optional prover follow-up uses native evidence through a separate explicit trust boundary.
Alternatives considered
References
Surface areas: input reader, CLI, host schemas, control/receipts, documentation.
This epic tracks both increments; the MVP release gate is only the four MVP issues. Close the epic when the follow-ups are completed or explicitly deferred with recorded rationale.
Implementation pull requests
All six implementation pull requests were approved and merged to
mainin the order below. Each rebased head passed fresh CI, and the final merged Git tree exactly matches the reviewed implementation. Delivery issues #943–#948 are closed.Final implementation commit:
0e58e6ff2. The remaining acceptance/release checklist above is retained for release tracking; this merge does not publish a package or attest runtime deployment.