import { type PolicyAuthorityReceipt, type VerifiedPolicyAuthority } from "./authority.js"; import { type OrgPolicy } from "./schema.js"; /** * Assertions a detector made about a completed scan. A severe label is * evidence, not a verdict, so the accountable administrator decides each one: * reject the candidate, record a false positive, or accept the residual risk * with an attributable signed reason. */ export declare const DISPOSITIONABLE_POLICY_FINDING_CODES: readonly ["malicious-code", "prompt-injection", "auto-executing-hook", "hidden-unicode", "secrets", "unpinned-source", "dependency-confusion", "unsafe-path"]; /** * Prerequisites AIH needs before it can evaluate or project at all. Each marks * something absent or untrustworthy rather than something a detector asserted, * so no signature substitutes for it and approval cannot invent it. */ export declare const FENCED_POLICY_PREREQUISITE_CODES: readonly ["mandatory-detector-failed", "evidence-identity-drift", "missing-projector", "unsupported-target", "normalized-collision", "ownership-conflict"]; /** * The partition's union — the same 14 codes, none renamed or added. Resolution * still blocks on every one of them: separating the halves is what lets a * consumer tell a disposable finding from a hard prerequisite, and is not by * itself the administrator disposition flow, which does not exist yet. */ export declare const UNWAIVABLE_POLICY_DANGER_CODES: readonly ["malicious-code", "prompt-injection", "auto-executing-hook", "hidden-unicode", "secrets", "unpinned-source", "dependency-confusion", "unsafe-path", "mandatory-detector-failed", "evidence-identity-drift", "missing-projector", "unsupported-target", "normalized-collision", "ownership-conflict"]; export type DispositionableFindingCode = (typeof DISPOSITIONABLE_POLICY_FINDING_CODES)[number]; export type FencedPrerequisiteCode = (typeof FENCED_POLICY_PREREQUISITE_CODES)[number]; export type PolicyDangerCode = (typeof UNWAIVABLE_POLICY_DANGER_CODES)[number]; /** True for a detector finding the accountable administrator may dispose of. */ export declare function isDispositionableFinding(value: string): value is DispositionableFindingCode; /** True for a missing or untrustworthy prerequisite that no approval can waive. */ export declare function isFencedPrerequisite(value: string): value is FencedPrerequisiteCode; export type ResolutionBlockCode = PolicyDangerCode | "lifecycle-not-supported" | "evidence-missing" | "evidence-failed" | "authority-receipt-unverified" | "authority-receipt-mismatch" | "approval-missing" | "approval-ambiguous" | "approval-expired" | "approval-not-yet-valid" | "approval-revoked" | "approval-signer-untrusted" | "approval-digest-mismatch" | "approval-scope-mismatch" | "approval-clarification-missing" | "authority-target-coverage-mismatch" | "approval-policy-version-mismatch" | "approval-duration-invalid" | "framework-contract-unavailable"; type Governance = NonNullable; type Candidate = Governance["catalog"]["reviewed"][number]; type Approval = Governance["authority"]["approvals"][number]; type EvidenceRecord = PolicyAuthorityReceipt["evidence"][number]; /** The immutable, action-significant identity of an AIH-shipped reviewed control. */ export type AiReviewedControl = Pick; /** Built only from the live AIH catalog and owned adapter records at runtime. */ export interface RuntimeReviewedControl { control: AiReviewedControl; controlDigest: string; } export interface RuntimeMcpIdentity { subject: string; projectable: boolean; /** Whether the rendered runtime entry has a Kiro-supported stdio transport. */ kiroProjectable?: boolean; } export interface RuntimeHookIdentity { scriptDigest: string; projectable: boolean; } export interface EffectivePolicyContext { now?: Date; /** Branded only after the fixed receipt passes `gh attestation verify`. */ authority?: VerifiedPolicyAuthority; /** Actual adapter target set for this invocation; omitted means Claude's leaf-command default. */ targets?: readonly string[]; /** Whether this invocation can emit managed adapter actions at all. */ projectorsEnabled?: boolean; /** Exact runtime reason when projectors are intentionally unavailable. */ projectorDisabledReason?: "vibe-posture"; mcpIdentities?: Readonly>; hookIdentities?: Readonly>; /** Exact AIH-shipped control identities, built from live catalog + owned hooks. */ aihReviewedControls?: Readonly>; projectorFindings?: Readonly>; } export interface CandidateProjectionState { projector: string; requestedTargets: string[]; supportedTargets: string[]; availableTargets: string[]; coverage: "complete" | "blocked"; ownership: "managed-settings-receipt" | "kiro-mcp-receipt" | "managed-settings-and-kiro-mcp-receipt" | "usage-hook-receipt" | "hook-registrar-receipt" | "unavailable"; receipt: "pending-projection" | "unavailable"; } export interface EffectivePolicyCandidate { id: string; origin: "reviewed" | "custom"; kind: "mcp" | "hook" | "framework"; requested: boolean; effective: boolean; sourceDigest: string; source: Candidate["source"]; evidence: "verified" | "approved" | "missing" | "failed"; evidenceRecord?: EvidenceRecord; approval?: { id: string; issuer: string; repository: string; attestationId: string; reason: string; clarification?: string; scope: string[]; notBefore: string; expiresAt: string; subjectDigest: string; }; revocation?: { issuer: string; revokedAt: string; reason: string; }; dangerCodes: PolicyDangerCode[]; blockingCodes: ResolutionBlockCode[]; /** Actionable resolver diagnostics; danger codes remain the stable policy fence. */ resolutionReasons: string[]; clarification?: string; annotation?: string; lifecycle: "supported" | "deprecated" | "retired"; projection: CandidateProjectionState; } export interface EffectiveOrgPolicy { capabilityPackages?: { catalog: { provider: "github"; repository: string; }; roots: string[]; }; policyVersion?: string; candidates: EffectivePolicyCandidate[]; activeMcpServerIds: string[]; frameworkSelections: Array<{ id: string; framework: "ecc" | "superpowers"; }>; /** * Admin-authored external framework curation. It is deliberately surfaced * only as report metadata: AIH has no installer or projector for it. */ externalCuration: Array<{ framework: "ecc" | "superpowers"; items: Array<{ kind: "agent" | "skill" | "command"; id: string; source: { repository: string; commit: string; path: string; }; audit: { record: string; digest: string; }; clarification?: string; }>; status: "external-guidance"; }>; /** * Admin-requested intent over externally-owned inventory whose audit evidence * does not exist yet. It is reported so a target repository can see exactly * what was asked for; it is never a candidate and never becomes effective. */ externalSelections: Array<{ framework: "ecc" | "superpowers"; items: Array<{ kind: string; id: string; source: { repository: string; commit: string; path: string; }; }>; status: "requested-evidence-needed"; }>; blocking: boolean; authority: { verified: boolean; receiptDigest?: string; problem?: string; }; } export declare function stableJson(value: unknown): string; /** Digest only immutable source identity, never catalog wording or an activation flag. */ export declare function candidateIdentityDigest(candidate: Pick): string; /** Digest every action-significant field; catalog prose and annotations remain report metadata. */ export declare function reviewedControlDigest(control: AiReviewedControl): string; /** * Full approval subject, deliberately excluding only its post-signing transport * locator (`github.attestationId`) and its derived digest (`subjectDigest`). */ export declare function approvalAttestationDigest(approval: Pick): string; /** Resolve requested candidates against externally verified authority and live adapters. */ export declare function resolveEffectiveOrgPolicy(policy: OrgPolicy, context?: EffectivePolicyContext): EffectiveOrgPolicy; /** Exact, mechanically compared schema-leaf consumer contract. */ export declare const POLICY_ENGINE_FIELD_CONSUMERS: Readonly>; export {};