@runbooks/supervise
v0.1.1
Published
Supervisor core: pure decision logic. No I/O, no network.
Readme
@runbooks/supervise
The reference supervisor — the implementation of the execution contract.
Normative: RUNBOOK.md §13
The one sentence that defines scope
A runner performs the steps. A supervisor permits them, blocks them, and records what happened. The supervisor does no work of its own and holds no credentials of its own.
Test every proposed feature against it. A feature requiring the supervisor to do work, or to hold a secret, is out of scope by construction rather than by preference — and the moment this becomes something we host, NG1 is dead.
What it enforces
Derived from the document, never authored separately (§13.2):
| Document element | Runtime meaning |
|---|---|
| capabilities[] | the allowlist |
| current step's tool | the scope — only this step's declaration, not the run's union |
| risk + requires_approval | a gate, decided by a human who is not the agent |
| expect | a postcondition the supervisor evaluates |
| on_fail | a route the supervisor takes |
| retry(n) | a counted budget |
| terminals | the stop conditions |
| anything else | a deviation: blocked, recorded, escalated |
Per-step scope is the row that does the most work. Granting an agent the union of a procedure's capabilities for the whole run is how a diagnostic session ends in a deletion.
Where it runs
In the operator's environment, between their agent and their tools. No telemetry, no callback, no network dependency. Reports and attestations are opt-in, per run, and default to emitting nowhere.
What it is not
Not a sandbox, not a general agent policy engine, not a replacement for the client's own allowlist, and not a guarantee. It bounds what the runbook authorizes — a real reduction, not a total one (§13.5).
