Enforcement and audit
Mandatory transition check
Before product edits, opening any PR, or requesting review, read the relevant public protocol and inspect its actual evidence. Then call workflow_gate with transition product-edit, open-pr, or request-review; defect truthfully classifies reported-defect work; record is the public task document URL. Supply checks as named strings describing evidence or linking it. Record the result in the public task record. If allowed is false, do not cross the transition. An allowed result is necessary, never sufficient: stale, false, irrelevant or incomplete evidence still blocks action.
All transitions require policyVersion (versions actually read), owner, and goal. Defects additionally require baselineSha (full 40-hex), observableFailure, publicBaselineEvidence (hm/https URL), falsification, and applicableSurfaces. Requesting review additionally requires headSha (full 40-hex), verification, fullDiffSelfReview, performance, causalNarrative, and publicAfterEvidenceOrNonApplicability. Non-applicability must explain why; it is not a shortcut for GUI proof.
What is and is not enforced
The executable checker rejects absent checklist entries and malformed SHA/public-record fields. It does not verify media, fetch evidence, prove a test failed for the correct reason, authenticate an attestation, or check that a SHA belongs to the PR. Those are mandatory agent review responsibilities under the linked protocols.
Trigger prompts and their delegated-worker instructions require reading public policy and using the checker. The private startup file is a short pointer into this public system, rather than a competing policy copy. Headless delivery/claim machinery retains its existing deduplication and recovery behavior.
This is instruction-level enforcement plus an executable checklist, not a universal tool interceptor. Raw shell, GitHub and publishing tools can bypass it; older already-running sessions have not been rewritten. Hard denial of arbitrary product edits/PR calls would require runtime/tool-boundary changes through a reviewed code PR. Do not describe this system as that stronger guard.
The runtime exposes trigger-specific system prompts, but reports that the top-level agent definition is editable only by the user in the desktop. Consequently future ordinary sessions reach this protocol via the existing instruction to read ION.md; trigger sessions also carry direct public URLs. For a direct top-level prompt anchor, Eric can add: “Before actionable work, read hm://z6MkpVa5nMUR5ZaUEyV1SE48KTNbwTuHRd83RwLgMKc4nGU3/ion/workflows and follow the applicable protocols.”
Implementation contract
The callable tool is named workflow_gate. Its algorithm is deliberately small: select the required keys above; reject empty values; validate required SHA shape, public work-record shape and defect baseline evidence URL scheme; return allowed, missing, the transition/record and an explicit limitation. It performs no external mutations. Its source is inspectable through the tool contract. Policy changes affecting these fields must update the implementation and tests together.
Audit procedure
Test empty defect evidence rejection for both product edits and draft-PR admission; complete synthetic checklist acceptance; review rejection without performance/self-review; malformed SHA rejection; non-runtime justified review acceptance. Synthetic data is test input, not evidence of a real defect. Read back published protocols and live trigger configurations. Verify sources, schedules, event claims and delivery semantics are unchanged. Log test outcomes in a public migration record. Do not fire real feedback actions just to test wiring.
When a violation is found: stop further gated actions, publicly correct the task state, preserve evidence and identify whether policy, prompting, checklist validation or the runtime boundary failed. Never backfill an attestation to disguise an earlier violation.
Do you like what you are reading? Subscribe to receive updates.
Unsubscribe anytime