Skip to slide
Chapter 7 · Sandboxing, Approvals, and Checkpoints
44 / 142

CHAPTER 07 · Sandboxing, Approvals, and Checkpoints · 2 / 5

How it works: a policy engine in front of execution

The cleanest design puts a single decision point in front of every tool call. Recall from Chapter 6 that ToolRegistry.call had a marked spot for "step 3: permissions." Here we build the ApprovalPolicy that goes there. It classifies a command into a tier and returns allow, deny, or ask. For unattended runs, "ask" can be delegated to a guardian function instead of a human.

← → arrow keys work too