CR-AR-001: Risk-Tiered Deferred Human Review - #153
Conversation
Add CR-AR-001 as a proposed, unauthorized CR document defining a deferred-terminal-review authorization mode: an R0-R5 risk-tier scheme, monotonic escalation, cumulative/compositional risk budgets, risk floors, untrusted-input escalation, a capability-claim extension, eleven runtime requirements (AR-001..AR-011), a mechanically-derived terminal evidence bundle, and required tests/acceptance criteria for a future Initial Implementation Slice. Status: Proposed. Implementation Authority: Not authorized. Accepting this document approves the governance/design proposal only; the Initial Implementation Slice requires its own separate approval and bounded file allowlist, matching the CR-DD-012B and CR-OC-001C-E sequencing pattern. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
✅ Deploy Preview for poetic-quokka-0fd859 ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
|
Pushed `b8c1810`: a documentation-only revision of CR-AR-001 responding to a read-only adversarial design review (chat-only memo, not committed anywhere in the repo). No implementation, schema, test, or runtime change — The review found the design's problems were specification gaps at the CR-YK-002 integration boundary, not evidence the deferred-review concept itself is unsound. Four items were treated as genuine blockers (one reframed) and resolved in this revision:
Also addressed, not labeled blockers: risk-classification evidence now records which rule/floor produced the tier (new Full diff and per-finding mapping in the session record. Suggested next step: a second, narrower review of just this revision — whether B1–B4 are genuinely closed and whether the new language introduces any contradictions — before any implementation-authorization discussion. |
Scope
Exactly one new documentation file. 506 insertions, zero other changes.
docs/change/requests/CR-AR-001-risk-tiered-deferred-human-review.mddocs/current_backlog.md,docs/backlog.md,docs/futures/futures_register.md,docs/change/change_log.md, and everything undertriage_core/,schemas/,tests/.mainatc86a117and does not carry that commit. Independent docs-only slice, independent review.Status of the CR itself
Status: ProposedImplementation Authority: Not authorizedMerging this PR approves the governance/design proposal recorded in the document — nothing more. It does not authorize the Initial Implementation Slice described in the CR; that slice requires its own separate approval and bounded file allowlist, the same sequencing already used for CR-DD-012B and CR-OC-001C through CR-OC-001E. No source code, schema, CLI, ledger, or runtime change is authorized by this document or by merging it.
What the CR proposes
A deferred-terminal-review authorization mode for TriageCore's agentic execution control plane, addressing approval fatigue from requiring human sign-off before every low-risk tool call.
CAPABILITY_ESCALATION_REQUIREDresult the agent cannot reason its way past.review_mode,effect_ceiling, budgets,reversibility,terminal_review,evidence) building on the existing atomic capability-claim work.Terminology invariant preserved throughout
Deferred human review ≠ deferred authorization. Runtime authorization and enforcement remain contemporaneous — on every tool call, regardless of review mode — even when the human review step itself moves to the workflow boundary. This distinction is stated explicitly in the Status, Design Principle, Runtime Requirements, and Security Invariants sections so it can't be read as "review is deferred, therefore enforcement is too."
Structural notes
##-heading CR format used by larger existing CRs (e.g.CR-YK-002) rather than a numbered-list style.current_backlog.mdorfutures_register.md: an earlier proposed-only CR (CR-004) was never listed in either backlog document while inProposedstatus, so a standalone CR doc with no backlog entry is an established pattern, not an omission.Verification
git diff --cached --statgit diff --cached --checkgit status --shortAentry, no residueTests not run: no executable, schema, or test surface changed. No effect on the open daily-use evidence window.
🤖 Generated with Claude Code