export { AIH_ORG_POLICY_FILE } from "../org-policy/constants.js"; import type { PlanContext } from "../internals/plan.js"; import type { AihConfig } from "./marker.js"; export type Posture = "vibe" | "enterprise"; export declare const POSTURES: readonly ["vibe", "enterprise"]; export type PostureSource = "flag" | "marker" | "env" | "default" | "org-floor"; export type PolicyVerdict = "allow" | "warn" | "deny"; export type GovernanceControl = "secrets" | "path-portability" | "contract-freshness" | "command-policy" | "risk-gates" | "mcp" | "ca-trust" | "verify" | "trust-danger" | "trust-origin"; export interface ResolvedPosture { posture: Posture; postureSource: PostureSource; } interface OrgPolicyFloor { minimumPosture: Posture; contractRef?: string; path: string; } interface ResolvePostureInput { root: string; env: NodeJS.ProcessEnv; flag?: unknown; flagSource?: string; marker?: AihConfig; skipOrgPolicyFloor?: boolean; } /** Resolve the v2 two-valued posture dial, defaulting only when no value is supplied. */ export declare function asPosture(value: unknown): Posture; export declare function parsePostureInput(value: unknown, source: "--posture" | "AIH_POSTURE"): Posture; export declare function postureFromContext(ctx: PlanContext): Posture; /** * The posture spine reads the org floor through the authoritative org-policy * schema/path resolver, so malformed policy files fail closed and AIH_ORG_POLICY * uses the same env-exclusive precedence as the full org-policy projection. */ export declare function readOrgPolicyFloor(root: string, env: NodeJS.ProcessEnv): OrgPolicyFloor | undefined; export declare function resolvePosture(input: ResolvePostureInput): ResolvedPosture; /** * Convert a control finding into the active posture's governance verdict. `risk-gates` * deliberately stays advisory/ask even at enterprise; aih never upgrades it to a * deny because the consuming CLI owns the ask-at-runtime seam. */ export declare function gradeVerdict(finding: PolicyVerdict, control: GovernanceControl, posture: Posture): PolicyVerdict;