Repository navigation
ADR 0005 AI Authorization Boundary
- Status: Accepted
- Date: 2026-07-30
StackCendra will analyze untrusted repositories and telemetry while proposing operations against sensitive environments. Model output is probabilistic and vulnerable to misleading evidence and prompt injection.
AI may plan evidence collection, summarize, generate hypotheses, and draft actions. It cannot authorize commands, retrieve unrestricted credentials, or invoke production runners directly.
Execution requires:
- a versioned action;
- deterministic parameter validation;
- policy evaluation;
- required human approvals;
- a short-lived capability for a constrained runner;
- audit recording and health verification.
- AI remains useful without becoming a security principal.
- More deterministic contracts and policy work are required.
- User interfaces must distinguish hypotheses from observed facts.
- Evidence collection and prompt construction require strict minimization and redaction.
- Fully autonomous production remediation is outside the product's safety model.
- Give an agent unrestricted shell access.
- Rely on prompt instructions for safety.
- Allow the AI service to retrieve production credentials.
These alternatives cannot provide reliable authorization or resistance to untrusted input.
This invariant is not expected to be removed. Specific low-risk automation may reduce approval friction only when deterministic policy and bounded effects make it safe.
StackCendra is currently in Phase 0. The complete Phase 0–13 plan is versioned in the main repository under docs/wiki; later-phase pages describe intended behavior, not current implementation.
- Phase 0 foundation
- Phase 0 backlog
- Release 0.1 discovery
- Phase delivery framework
- Roadmap
- Wiki review guide
- Risks and decisions