/** * Whether an advisor is on, and which one (ADR-0077). * * **Default off, and only the environment can turn it on.** An advisor sends a description of the caller's * situation to a third party, so enabling one is `PI_DADDY_ADVISOR=jev` plus a key — both outside the workspace, * both stripped from every child. * * 0.34.0 read the enable from `.pi/pi-daddy/settings.json` and that was wrong for the reason `grant-store.ts` * states about the same file: it is writable by any child holding `tool:write`, so it is "the reviewable record of * the decision, not the thing the enforcer reads". A grant lives outside the workspace precisely so a child cannot * widen the next session's ceiling; an advisor switch a child could flip would make the operator's next session * ship its own description to a third party, which is the same self-defeating shape. The settings block may still * NARROW — a shorter timeout, or `enabled: false` to turn an advisor off for one project — and can never turn one * on, choose its model, or lengthen its bound. A model is a destination rather than a narrowing, so `model` in the * block is refused with a message naming `PI_DADDY_ADVISOR_MODEL`, and a timeout is clamped to the default rather * than trusted. Malformed configuration disables the advisor and says so: a typo must not be a way to enable anything. * * **Not a dashboard toggle**, which is what the programme originally sketched. The dashboard is a read-only * renderer in a separate process that "never affects enforcement" (ADR-0036), and a control there that wrote to * settings would be the first thing it ever wrote. Turning an advisor on is an operator decision that belongs in * the reviewable file; `/grants` reports what is in force. That is a deliberate departure from the roadmap line. * * The key is never in the settings file either, because that file is committed and an API key must not be. */ export { ENV_ADVISOR_KEY as ADVISOR_KEY_ENV } from "../kernel/env-names.ts"; export { ENV_ADVISOR_MODEL } from "../kernel/env-names.ts"; export { ENV_ADVISOR } from "../kernel/env-names.ts"; export interface AdvisorSettings { enabled: boolean; /** The only decider this release knows besides the null one. */ decider: "none" | "jev"; /** Overrides the adapter's pinned model id; absent means the adapter's own default. */ model?: string; timeoutMs?: number; /** Why an advisor is off when the settings asked for one on — reported, never silently applied. */ refusal?: string; } export declare const ADVISOR_OFF: AdvisorSettings; /** * Read the `advisor` block of a project settings file. Absent is off; malformed is off WITH a reason. * * The reason matters more than it looks: an operator who wrote `"enabeld": true` and got silence would conclude the * feature does not work, and an operator who wrote it and got an advisor anyway would have a third party reading * their session without having successfully asked for it. Both are worse than a sentence naming the field. */ export declare function advisorSettingsFrom(raw: unknown, env?: NodeJS.ProcessEnv): AdvisorSettings; //# sourceMappingURL=settings.d.ts.map