Policy & protection MVP2 / foundation

One-time approvals

A review decision authorizes one exact pending invocation, within its deadline.

Development previewMVP2 foundation complete. Live hooks, enforcement, and Anthropic BYOK are pending. Planned behavior is labeled separately from working features.

What Allow once means

Allow once permits the exact waiting tool call past TraceRook’s review gate. It does not authorize the session, approve similar future commands, skip the host’s own permissions, or prove execution.

The fingerprint binds provider, session, turn when available, source tool-call ID, tool name, working directory, and canonical original input. When the host lacks a call identifier, a local invocation nonce distinguishes attempts. A redacted summary or command substring is not sufficient authorization.

Terminal state is written once

StateMeaning
pendingWaiting on a live, bound invocation before its deadline
approved_onceThe exact pending invocation was released past TraceRook
deniedThe pending invocation was denied
expiredThe review deadline passed; high-risk request denies
abortedThe invocation was invalidated by disconnect, end, or mismatch

A transaction or compare-and-set operation must accept at most one terminal transition. Double-clicks, notification replays, and simultaneous UI responses cannot create multiple permissions.

Deadlines and disconnects

The default approval window is 45 seconds from the pre-tool event, bounded by the host callback deadline. The proposed outer hook timeout is 75 seconds; exact versions and behavior must be verified on real hosts.

Disconnecting the bridge, ending the session, expiring the invocation, or changing its fingerprint invalidates the request. A late approval cannot release a later retry. Expired UI must show No longer pending and disable live approval controls.

Notifications are entry points

A native notification offers Review and, where supported, Block. Review opens the focused detail panel. Critical denials offer details rather than a quick in-flight allow. Notification text must omit full commands, credentials, source, and private repository names.

Focus mode or denied permissions can prevent delivery. The menu bar and approvals queue remain mandatory; the service must resolve the deadline even if the user never sees a notification or the UI exits.

Try the sample state machine

The current app supports a synthetic review with a 45-second deadline, terminal-response rejection, and a native panel. This local sample is useful for the interaction and foundation tests.

Authenticated service mutations, durable transitions, bridge disconnect handling, and real-host waiting calls remain MVP2.1–MVP2.4 acceptance work. Read the preview guide to try the sample safely.

Based on the MVP1 specification, the additive MVP2 specification, and the acceptance matrix · October 8, 2026.