You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
SETTExecutor.submit() now raises SETTConfigurationError if the
Executor is not attached to a SETTOrchestrator, or if the attached
memory has no EthicalFilter. Previously an unattached Executor would
run the real handler with no governance at all.
SETTAgent._publish_to_universal() and propose_action() now raise SETTConfigurationError instead of silently returning when the agent
is not wired. A misconfigured agent no longer looks like it worked.
UniversalMemory, the ethical audit log, the execution log, and
history now return defensive deep copies. External code can no longer
mutate internal state through a returned reference.
Memory history and both audit logs (ethical decisions and executed
actions) are now a sequenced SHA-256 hash chain, with a verify_chain()
helper. Tamper-evident within the running process, not an external
signature.
🧠 Safety semantics
Added SafetyAssessment, separating situation_urgency, action_harm_risk, omission_risk, and protective_action.
human_at_risk no longer inflates an action's harm score. The old
behavior pushed the score to reject_threshold - 0.01 any time a human
was flagged at risk, which meant a genuinely protective action (like
calling for help) could get rejected precisely because the situation
was severe. Domain analyzers now decide harm; urgency stays a separate
signal.
New conservative fallback: if human_at_risk is true, the action was
not classified as protective, and the base verdict is ALLOW, the
filter promotes it to WARN. The score is untouched, protective actions
are never affected, and existing REJECT/WARN verdicts are never
downgraded or relabeled. The audit entry records human_at_risk_without_protective_classification under decision_reason_codes.
🔧 Fixed
examples/with_ethics.py Scenario 2 now actually produces WARN,
matching its own comment. It previously printed "expected: WARN" and
returned ALLOW.
get_audit_log() / get_ethical_audit_log() no longer expose
internal dict references that could be mutated after the fact.
✅ Compatibility
This release intentionally turns previously silent behavior into
explicit errors. If your code builds a SETTExecutor or SETTAgent
outside a fully wired SETTOrchestrator, wire it explicitly or expect SETTConfigurationError. No other public signatures changed.
📝 Docs
MIGRATION_v0.8.md walks through every behavior change with
before/after examples.
docs/security_model.md documents the hash chain, defensive copies,
and the exact human_at_risk promotion rule.
docs/api_reference.md updated for the new audit log fields
(situation_urgency, action_harm_risk, omission_risk, protective_action, decision_reason_codes).
Status
264 tests passing (up from 244 in v0.7.0).
Wheel built and installed in a clean environment; validated against a
private reference application (709/709) built on top of this release.