Policy & protection MVP2 / foundation

The decision pipeline

Follow a supported proposal from local inspection to a host-format decision.

Development previewMVP2 foundation complete. Live hooks, enforcement, and Anthropic BYOK are pending. Planned behavior is labeled separately from working features.

1. A host hook presents the proposal

A compatible, configured, enabled, and trusted local agent runs a PreToolUse command hook. The signed TraceRook bridge reads the host’s JSON, applies bounded parsing, and sends a deadline-bound request to the per-user background service.

This point is the enforcement opportunity. PostToolUse is useful for observation but comes after execution. A host path that skips or fails to launch the hook cannot be blocked by this pipeline.

2. Inspect the original action locally

The policy engine derives command shape, sensitive-path references, intended network destinations, mutation scope, and task-related features in memory. It evaluates correlated evidence rather than treating every appearance of a command token as malicious.

Concrete catastrophic evidence yields an immediate deterministic denial. A routine cleanup inside disposable build output must not inherit the same decision as destructive changes outside the repository.

3. Ask Claude only when context is useful

Suspicious or ambiguous proposals may use direct Anthropic BYOK analysis after minimization, redaction, consent, and a second privacy preflight. The request contains a task anchor and selected event summaries rather than a full transcript.

Claude’s verdict is advisory and strictly validated. A model-only critical label routes to high-risk human review. An outage, malformed response, exhausted budget, or unsafe payload falls back to the local decision with an accurate provider status.

4. Bind review to the pending call

A high-risk decision persists a pending request with an exact action fingerprint and expiry. The native app receives the event through authenticated XPC. The user can allow once or deny; the service rejects stale, mismatched, repeated, or disconnected responses.

A default 45-second approval window sits within the outer host timeout, targeted at 75 seconds and subject to real-host verification. If a high-risk pending request expires, the callback returns a denial.

5. Return to the host and retain certainty

The bridge translates the decision into the host’s supported output. No TraceRook override uses empty stdout and a successful exit, preserving native agent permissions. A denial uses a validated host-compatible response.

The record distinguishes interception, blocking before execution, permission past TraceRook, observed execution, and execution unknown. The current development build exercises fixtures only; this live sequence remains a release gate.

Based on the MVP1 specification, the additive MVP2 specification, and the acceptance matrix · October 8, 2026.