数据库已连通已成功连接预发布数据库(DATABASE_URL_STAGING)。请确认该实例为非生产 Supabase 项目。应用层环境预发布 staging数据库连接变量DATABASE_URL_STAGING

治理层 / Governance

权限与治理观察工作台;不是权限后台、不是审批后台。

active agents4candidate agents2needs review1blocked0human gate required6denied actions tracked9

Governance 只读边界

本页只展示 Agent 权限、Human Gate、Denied Actions 与规则来源,不授予权限,不审批,不触发 Runner,不写 DB / Drive / production。

  • 不 grant / revoke / approve / active Agent / Skill
  • 不 auto merge、不触发 Runner
  • 不改变 /system/registry readiness

Agent Permission Matrix

主表;无 Approve / Grant / Revoke / Enable / Run / Auto merge 操作列。

agent_idrolestatusriskallowed_scopedenied_actionshuman_gatepolicy_sourcelast_reviewnext_action
task-plannertask classification / task package generationactivemedium
  • task-classify
  • task-pack-generate
  • risk-check
  • production write
  • auto merge
  • approval execute
requiredsystem-agent-pages-ia-matrix-v12026-05 snapshotkeep readonly dispatch boundary
dev-runnerlow-risk execution candidatecandidatehigh
  • evidence-check
  • lint
  • typecheck
  • deploy
  • DB mutation
  • runtime control
  • production write
requiredfrontend governance + runtime boundary2026-05 snapshotdo not enable until action governance exists
review-gatehuman review gate observeractivemedium
  • review-summary
  • acceptance-matrix-readonly
  • approval execute
  • auto merge
  • permission grant
requiredhb-os-frontend-governance-v12026-05 snapshotobserve review gate only; no execute
docops-agentdocument governance scan observeractivelow
  • governance-scan-readonly
  • artifact-index
  • Drive write
  • approval execute
  • production write
requireddocops readonly results boundary2026-05 snapshotkeep DocOps scan as readonly artifact
ops-monitor-agentruntime health observerneeds_reviewmedium
  • runtime-snapshot
  • health-readonly
  • restart
  • deploy
  • rollback
  • runtime control
requiredsystem-runtime-readonly-timeline-v12026-05 snapshotdefer live adapter to future task pack
content-agentcontent marketing staging observercandidatemedium
  • staging-readonly
  • draft-preview
  • production write
  • publish
  • DB mutation
requiredcm-production-readonly-gate2026-05 snapshotobserve staging only; no cutover
runtime-observeragent run timeline projectionactivelow
  • timeline-readonly
  • snapshot-projection
  • runner trigger
  • claim
  • complete
  • auto merge
not_requiredsystem-runtime-readonly-timeline-v12026-05 snapshotkeep timeline readonly

Human Gate / Review Gate

只读投影;不执行审批。

gate_idagent_idgate_typerequirementstatuspolicy_sourcelast_reviewnext_action
gate-task-plannertask-plannerhuman approval requiredrequiredobservedsystem-agent-pages-ia-matrix-v12026-05 snapshotkeep readonly dispatch boundary
gate-dev-runnerdev-runnerhuman approval requiredrequiredobservedfrontend governance + runtime boundary2026-05 snapshotdo not enable until action governance exists
gate-review-gatereview-gatehuman approval requiredrequiredobservedhb-os-frontend-governance-v12026-05 snapshotobserve review gate only; no execute
gate-docops-agentdocops-agenthuman approval requiredrequiredobserveddocops readonly results boundary2026-05 snapshotkeep DocOps scan as readonly artifact
gate-ops-monitor-agentops-monitor-agenthuman approval requiredrequiredopensystem-runtime-readonly-timeline-v12026-05 snapshotdefer live adapter to future task pack
gate-content-agentcontent-agenthuman approval requiredrequiredobservedcm-production-readonly-gate2026-05 snapshotobserve staging only; no cutover

Denied actions

边界提示,不是操作按钮。

permission grant deniedpermission revoke deniedapproval execute deniedauto merge deniedrunner trigger deniedDB write deniedDrive write deniedproduction write deniedruntime control denied

Policy Source / Evidence Source

source_idlabelpathscopestatuslast_review
ia-matrixSystem Agent Pages IA Matrixdocs/architecture/system-agent-pages-ia-matrix-v1.mdagent page boundariesactive2026-05 snapshot
frontend-governanceHB OS Frontend Governancedocs/frontend/hb-os-frontend-governance-v1.mdfrontend permission boundaryactive2026-05 snapshot
readonly-calloutReadonly Boundary Calloutdocs/frontend/readonly-boundary-callout-v1.mdreadonly UI boundaryactive2026-05 snapshot
runtime-timelineRuntime Readonly Timelinedocs/architecture/system-runtime-readonly-timeline-v1.mdruntime observer boundaryactive2026-05 snapshot
registry-observationRegistry Compatibility Observationdocs/architecture/system-registry-compatibility-observation-continuation-plan-v1.mdregistry readiness observationobservation2026-05 snapshot

Risk Boundary / Next Action

boundary_idlabelstatusnext
no-permission-mutationNo permission grant / revokeenforcedkeep readonly projection only
no-approval-executeNo approval executeenforcedhuman gate observe only
no-runner-triggerNo Runner triggerenforceddefer to execution task pack
no-registry-readiness-changeNo /system/registry readiness changeenforcedobservation cycle remains active

DocOps 深链(只读): /docops

低频说明:要点 / 边界 / 兼容 / v1 不做

本层要点

  • Governance 页为 Agent Permission Matrix readonly 投影,不是权限后台。
  • Human Gate 区仅展示需要人工闸门的 Agent,不执行审批。
  • Denied Actions 为明确禁止动作列表,不是操作按钮。

v1 不做

  • 权限授予 / 撤销
  • 审批执行
  • auto merge
  • Runner 触发
  • production 写入
  • registry redirect / archive / delete