Review calls with a policy
A grant fixes exact arguments, such as the repository a step may write to. A
policy covers what a grant cannot: intent, scope, and judgment. Give a step a
policy, and an independent reviewer checks each call the step proposes
before the broker adds credentials and sends it.
- fix:
reason: fix-and-open-pr.md
with: [trigger, triage]
can:
- github.write: {repo: triage.repo}
policy: "One new branch from the default branch, one PR, only files the fix needs. No force-push."A step's policy reviews the calls that change something. Reads are not reviewed.
The reviewer receives the proposed request, the policy instructions, what the
step was given (its inputs, which include the trigger only when the step reads
it), and the requests the same step invocation made before, one repository at
a time in a for_each. When a call replaces a file, such as a GitHub commit,
the reviewer also sees a diff against the file's current copy on the target
branch. It does not receive credentials. It answers with a decision
(allow, revise, or deny) and a reason. Missing, malformed, or non-allow
decisions fail closed. Policy instructions are included in the compiled
workflow revision.
Who reviews
The workflow's reasoning.review profile chooses the reviewer:
secrets:
anthropic: vault:anthropic/api-key
reasoning:
review: {model: anthropic/claude-sonnet-5, key: secrets.anthropic}model is <provider>/<model>, with provider anthropic or openai.
OutcomeCI attaches the proposal digest itself, so the model never copies it.
- With
key, reviews use the provider API key in that Vault secret, and your provider bills your account. The key stays in the Vault and is never included in the review prompt. Rotating it uses the new version on the next review. If the key or the workflow's access to it is revoked, reviews fail and the calls they would have checked are refused; OutcomeCI never switches to another key. - Without
key, OutcomeCI Cloud's key is used and the usage is metered to your workspace. - Without
review, cloud runs use the OutcomeCI default reviewer, set by your platform administrator, and local runs ask a short-lived invocation of the workflow's default agent, whose answer must echo the exactproposal_sha256of the request it reviewed.
A local run with review calls the model directly, using the key from your
local Vault, or ANTHROPIC_API_KEY or OPENAI_API_KEY without key.
Every refused request appears in the run's log with its reason, and the run list shows how many calls were refused. See Follow a run.
Boundaries and durability
- The reviewer cannot expand the step's grants, origin, methods, or budget.
- The run's private journal tracks proposals and confirmed effects. An identical confirmed request returns its saved receipt rather than executing again.
- An interrupted or uncertain request is not automatically replayed. Inspect its receipt before choosing a recovery action.
Policy-agent intent assessment is not a deterministic proof of recipient or content correctness. Origin, capability, method, credential isolation, and budget restrictions remain deterministic enforcement.