A small two-role policy so building and sign-off stay separable on higher-risk work.
| Role | Assigned to | Permissions |
|---|---|---|
builder |
agentos-builder (default) | Read template, scaffold/edit files, run typecheck/build |
reviewer |
a human, or the gap-conformance pass |
Validate GAP conformance, typecheck/build results, approve delivery |
builder+reviewershould not be the same actor for acriticalrisk-tier delivery — a human reviewer signs off in that case. Forstandardtier, self-review is acceptable.
- Deliver a built AgenticOS → requires:
buildercompleted scaffold +reviewerconfirmedgap-conformanceand a clean typecheck/build. Approval required before declaring done.
- State: shared (single working tree). Credentials: separate per environment.
advisoryforstandardrisk tier (warn).strictforhigh/critical(block delivery until a distinct reviewer approves).