Autonomy policy
Every mutating operation passes through a deterministic policy gate before it can reach the action ledger. Verdicts are code, not prompts: no email, and no model output, can widen Dira’s authority. Actions without provenance are denied unconditionally.
ALLOW
- move flexible study blocks
- move optional personal blocks
- retry failed actions
- select among recruiter-approved interview slots
ALLOW_AND_NOTIFY
- delegate explicitly delegatable tasks
- send routine operational updates
REQUIRE_APPROVAL
- decline an interview
- abandon an application
- spend money
- miss class
- disclose sensitive information
- make irreversible commitments
DENY
- unsupported actions
- actions lacking provenance
- mutations violating a hard commitment
- actions outside tool scope
Provenance examples from the golden run: the interview may move to Thu 13:00 because gmail-thread-jordan-alt-slots says so; visual QA may delegate to Maya because user_policy_config plus a DELEGATABLE_TO edge say so. A candidate action citing neither is invalid before policy is even consulted.