# Agent Safety Rules

> Hard rules for the managed-agent runtime. Binding on any AI agent operating in this project.

_Governance layer. Verified 2026-07-23. See [`../03-ai-agents/`](../03-ai-agents/) and [`../01-architecture/ai-architecture.md`](../01-architecture/ai-architecture.md)._

---

## Agents MUST
- **Respect `ActionPolicyService`.** An action executes only per the resolved policy (`always_allow` / `needs_approval` / `blocked`), resolved as runtime override → designed policy → default `blocked` ([`../03-ai-agents/decisions.md`](../03-ai-agents/decisions.md)).
- **Validate expected state.** Honor `ExpectedStateValidator` (TD-005) — reject a decision if the entity's group/status changed since the proposal.
- **Respect permissions.** Both gates apply: policy/approval for agents, and Sanctum ability + Spatie permission for the connector ([`../03-ai-agents/permissions.md`](../03-ai-agents/permissions.md)).
- **Maintain idempotency.** One decision per `agent_run_id`; replays return the prior outcome. Execution slots use key `agent-run-{id}:{slug}`.
- **Use registered actions only.** Actions must map to an agent's configured `allowed_actions` (`config/agent_runtime.php`) and resolve to a real `action` `LabelOption`, applied via the canonical `Startup/InvestorLabelActionService` ([`../03-ai-agents/actions.md`](../03-ai-agents/actions.md)). MCP tools must exist in `McpToolRegistry` ([`../03-ai-agents/tools.md`](../03-ai-agents/tools.md)).

## Agents MUST NOT
- **Bypass approval flows.** `needs_approval` requires a human decision via `ApprovalService` / `AgentApprovalRequest` before execution.
- **Execute unknown actions.** No free-form or unregistered actions; the structured-output validator fails closed.
- **Assume production deployment.** The runtime is **implemented but deployment status requires confirmation** ([`../03-ai-agents/agents.md`](../03-ai-agents/agents.md)); planned agents (AUTO-027…031) do not exist.
- **Modify production data outside defined workflows.** All writes go through the canonical services and the decision pipeline — never direct DB or ad-hoc mutation. Respect the runtime pause/disable gate (`AgentRuntimeService`, global `*` override).

## Execution ownership (locked — DR-001)
Approved actions are **executed by Numu** (`AgentActionExecutor` → canonical action service). Make.com orchestrates and reasons only. The precise Make re-validation split is **`Unknown - requires confirmation`**.

## Notes
- Agent `allowed_actions` enums are annotated in config as "pending authoritative confirmation" → treat exact membership as **`Unknown - requires confirmation`**.
- Agents produce **proposals only**; they never decide or execute directly.
