import { type Action, type PlanContext } from "../internals/plan.js"; import { type EffectiveOrgPolicy } from "./effective.js"; import { type RuntimeOrgPolicyResolution } from "./runtime.js"; import { type OrgPolicy } from "./schema.js"; export declare const ORG_POLICY_HOOK_RECEIPT_PATH = ".aih/org-policy-hook-receipt.json"; /** * The registry note, only when a blocked candidate's own codes depend on it. * * `verifyPolicyAuthorityReceipt` runs on every invocation, so its "registry * unavailable" problem was appended to EVERY blocked-candidate refusal regardless of * why the candidate blocked. An operator whose candidates were merely target-unselected * got sent chasing `AIH_POLICY_AUTHORITY_REPOSITORY`, then watched the note vanish once * the selection was fixed — not because the registry became available, but because * nothing threw. That reads as a prerequisite when it is a cascade. */ export declare function authoritySuffix(runtime: RuntimeOrgPolicyResolution): string; /** Read-only receipt/drift state shared by policy evaluation, reports, and doctor. */ export declare function orgPolicyHookReceiptState(ctx: PlanContext, effective: EffectiveOrgPolicy): { state: "absent" | "active" | "retained" | "drifted" | "invalid" | "unowned"; detail: string; }; /** Read-only managed-MCP ownership/drift status for policy report and doctor. */ export declare function orgPolicyMcpReceiptState(ctx: PlanContext, effective: EffectiveOrgPolicy): { state: "not-requested" | "clean" | "retained" | "missing" | "altered" | "revoked" | "malformed" | "unsafe-path"; detail: string; }; /** Read-only Kiro workspace-MCP ownership/drift state for policy report and doctor. */ export declare function orgPolicyKiroMcpReceiptState(ctx: PlanContext, effective: EffectiveOrgPolicy): { state: "not-requested" | "clean" | "retained" | "absent" | "altered" | "missing" | "unsafe-path" | "revoked" | "malformed"; detail: string; }; /** Governed projection: authority is verified before any policy-selected action is emitted. */ export declare function verifiedOrgPolicyProjectionActions(ctx: PlanContext, policy: OrgPolicy): Promise; /** * Legacy internal projection seam retained for pre-governance callers/tests. * It refuses governance inventories so a synchronous caller cannot accidentally * bypass external authority verification. */ export declare function orgPolicyProjectionActions(ctx: PlanContext, policy: OrgPolicy): Action[];