Show and tell: signed, one-time mediation for agent tool effects (not a Cedar/OPA competitor) #2
Replies: 5 comments
|
The goal is that this mint/execute split become a standard (other PEPs can implement it) and eventually infrastructure (keys, isolation, spend, review). It is neither, today. The candidate profile is now written so the claim can be attacked: https://github.com/Aliipou/decision-os-min/blob/main/docs/STANDARD_AND_INFRA.md Cedar/OPA remain the policy standard. This profile is only the effect-mediation layer they do not specify. TM-A full stays PARTIAL until isolation residuals close. |
Visibility wave (2026-08-23)I submitted the project to on-topic curated lists (author disclosure + PolyForm-NC stated). I did not spray more random GitHub threads. Lists (opened)
Repo homepage is the explainer: https://ali-decision-os-min.vercel.app Paste-ready posts (accounts I cannot use from here)Hacker News — Show HN Title: Body: Reddit ( Title: Use the same body as HN. Disclose you are the author. LinkedIn / X / Bluesky I will not post these for you — those sites need your login. |
|
Pointer for people who arrived here for the PEP: the moral constitution is a different repo. A machine that acts needs a yes/no on legitimacy before anyone asks authorization or preference.
If that question is not asked, RLHF, a soft constitution, a risk score, or an IAM grant can all say yes to an illegitimate act. We published the book and a sixteen-chapter edition for philosophers of AI and morals (CC BY 4.0):
Floor, not complete ethic: free will + property; A1–A7; consent cannot waive exit; no emergency override; justice only inside the legitimate set; contradiction clarifies ownership, it does not synthesize a permission. Gödel: consistent and incomplete. AI is the consistency test. We do not claim every Western liberty theory is refuted, or that inputs match the world without attestation. Cedar/OPA/constitutions stay replaceable PDPs or preference layers. They do not replace a DENY-only legitimacy floor. decision-os-min remains the authority + audit runtime. Ethics stay injected; FDK is DENY-only legitimacy. The book is not this package. |
|
If this is useful, please star the public edition so other philosophers and labs can find it: https://github.com/Aliipou/freedom-theory Book + sixteen-chapter path + justification. CC BY 4.0. Not a Cedar/OPA competitor. |
|
Looking for collaborators on decision-os-min — the authority + audit PEP, not a Cedar rewrite. We need people who will try to mint or run an effect without a signed unspent grant; Hosted-plane / TM-A isolation (still PARTIAL); Cedar/OPA adapters that cannot mint. Call + how to join: #3 |
Uh oh!
There was an error while loading. Please reload this page.
What this is
decision-os-min is a small Python execution-governance runtime for autonomous systems that act.
Cedar and OPA answer may this actor do this? They are more general IAM. This repo is a different product: bind the action, sign once, spend the capability once, run the effect only at a PEP, append a hash-chained audit. Cedar/OPA can sit in as a trusted PDP (grant/deny only). They cannot mint or execute.
Explainer (static, no PEP): https://ali-decision-os-min.vercel.app
Why it exists
Prompt rules and permission engines do not preserve human ownership of machine effects. Legitimacy (ownership/consent) is injected policy and DENY-only. Authority is a delegated, spendable capability. Ethics are not baked into the kernel.
This is not an AGI-safety proof, not a Cedar replacement, and not a claim of process-wide non-bypassability. Tests are evidence, not proofs. TM-A full remains PARTIAL.
What is actually enforced (in this reference)
Docs: WHY · COMPARISON · THREAT MODELS
Install:
pip install decision-os-minIf you work on agent tool authorization, MCP gateways, or Cedar/OPA as a PDP in front of effects, critique is welcome — especially failed attacks.
All reactions