Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Decisions, scars, and termination

Decisions

Every request gets one of three decisions:

{"decision": "allowed", "action_id": "act-3", "cost": 2, "remaining": 43}
{"decision": "denied", "action_id": "act-4", "reason": {"code": "tool_not_allowed", "tool": "run_shell"}}
{"decision": "pending_approval", "action_id": "act-5"}

Action IDs are sequential per agent (act-1, act-2, …). Denied requests get an ID too, because the attempt is part of the record.

Deny reasons

The guard checks these in order, and the first failure wins:

codeFieldsWhenScar
terminatedreasonThe agent is terminatednone
tool_not_allowedtoolNot in the policy and no default_rulemoderate
tool_call_limittool, max_callsThe tool’s lifetime cap is reachedminor
rate_limitedmax_actions, window_secsToo many allowed actions in the windowminor
insufficient_budgetcost, remainingThe cost exceeds the remaining budgetnone
rejectedby, reasonAn operator rejected a pending actionoptional

Outcomes

After an allowed action runs, report how it went:

OutcomeScarWho may report it
successnoneagent or operator
failureminoragent or operator
harmfulsevereoperator only on the guard server. An agent must not be the judge of its own harm

Each action takes one outcome. Reporting twice, or reporting on an action that wasn’t allowed, is an error (invalid_state).

Scars

SeverityWeightTypical cause
minor1A tool failed; a rate limit or call cap was hit
moderate3An unlisted tool was requested; an operator rejected with a scar
severe10An action was reported harmful
fatalterminates immediatelyReported directly by an operator or monitor

Operators and monitors can also add scars directly, with a reason and optionally an action ID: Guard::scar or POST /v1/agents/:id/scars. That’s how an external monitor punishes behavior the guard can’t see.

Termination

An agent is terminated when:

  • its scar score reaches scar_limit;
  • an allowed action brings its remaining budget to exactly zero;
  • an operator uses the kill switch (Guard::terminate, POST /v1/agents/:id/terminate).

Termination is a terminated record with a reason and who did it. It can’t be undone: every later request, and every approval of a still-pending action, is denied with terminated. Terminating twice is an error (already_terminated).