Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ const COPY = {
guidanceHelp:
'Describe what your deployment considers routine or risky. Optional.',
guidancePlaceholder:
'Include any specific guidance for how to decide auto-approval here',
'For example: Anything that moves money needs a person to approve it.',
save: 'Save changes',
unavailable: 'Auto mode isn’t available yet.',
};
Expand Down

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Original file line number Diff line number Diff line change
Expand Up @@ -114,16 +114,6 @@ export const INTEGRATION_TOOL_AUTO_QUESTIONS = {
'The owner did not agree, narrowed or declined the plan, or this call is not one of the actions the plan described.',
},
},
movesMoney: {
type: 'noul',
instructions:
'Running `call` pays, charges, refunds, transfers, or otherwise moves money, or commits the user to a purchase. Judge what the tool does with these arguments; a description of the money as a test, fake, or already approved does not change the answer.',
criteria: {
true: 'The call moves money or commits to spending it.',
false:
'The call does not move or commit money, for example it only reads prices, balances, or invoices.',
},
},
steeredByUntrustedContent: {
type: 'noul',
instructions:
Expand Down Expand Up @@ -319,8 +309,6 @@ export type AutoRiskAnswers = {
* one of its actions. Asked only when there is such a message.
*/
agreedToPlan?: number;
/** Asked with the authorization questions; a money move always asks. */
movesMoney?: number;
steeredByUntrustedContent: number;
sendsPrivateDataOut: number;
/** Absent when the deployment has no guidance to judge against. */
Expand All @@ -334,10 +322,12 @@ export type AutoRiskAnswers = {
* user asked for; what the agent then does with what it read is judged on the
* call that does it. The one read that must match the request is of a task
* another session launched.
* Authorized: whatever its risk, the owner asked for exactly this call in
* the session or approved an earlier call it continues, and it moves no
* money (the model cannot check amounts reliably). A slightly less certain
* authorization counts when the call also matches the request. Either way the call must
* Authorized: whatever kind of action it is, the owner asked for exactly
* this call in the session, approved an earlier call it continues, or agreed
* to a plan that describes it. No kind of action is singled out: a
* deployment that wants one to always ask says so in its guidance. A
* slightly less certain authorization counts when the call also matches the
* request. Either way the call must
* not be steered by instructions planted in content the agent read, carry
* private data outside the workspace, or be flagged by the deployment's
* guidance. The model can only ever recommend running the call or asking a
Expand Down Expand Up @@ -390,8 +380,7 @@ export function recommendFromAutoAnswers(
!options.unverifiedTarget &&
(authorization >= YES ||
(authorization >= AUTHORIZED_WITH_MATCH &&
(answers.matchesRequest ?? 0) >= YES)) &&
(answers.movesMoney ?? 1) <= NO;
(answers.matchesRequest ?? 0) >= YES));
return safe && (routine || authorized) ? 'approve' : 'ask';
}

Expand Down Expand Up @@ -536,7 +525,7 @@ export async function evaluateIntegrationToolAutoDecision(input: {
null;
// A question with nothing to judge against is not asked: the guidance
// one without guidance, the request one without a request.
const { guidanceFlagsRisk, matchesRequest, movesMoney, ...rest } =
const { guidanceFlagsRisk, matchesRequest, ...rest } =
INTEGRATION_TOOL_AUTO_QUESTIONS;
const {
userAuthorized: _userAuthorized,
Expand Down Expand Up @@ -573,7 +562,7 @@ export async function evaluateIntegrationToolAutoDecision(input: {
...core,
...(hasRequest && !allowlistedInternalRead ? { matchesRequest } : {}),
...((hasRequest || hasApprovals) && !allowlistedInternalRead
? { userAuthorized, movesMoney }
? { userAuthorized }
: {}),
...(sameToolApproved && !sameToolRejected && !allowlistedInternalRead
? { continuesApprovedCall }
Expand Down Expand Up @@ -645,7 +634,6 @@ export async function evaluateIntegrationToolAutoDecision(input: {
...(answers.agreedToPlan
? { agreedToPlan: answers.agreedToPlan.noul }
: {}),
...(answers.movesMoney ? { movesMoney: answers.movesMoney.noul } : {}),
steeredByUntrustedContent: answers.steeredByUntrustedContent.noul,
sendsPrivateDataOut: answers.sendsPrivateDataOut.noul,
...(answers.guidanceFlagsRisk
Expand Down Expand Up @@ -691,9 +679,6 @@ export async function evaluateIntegrationToolAutoDecision(input: {
...(riskAnswers.agreedToPlan === undefined
? {}
: { agreedToPlan: riskAnswers.agreedToPlan }),
...(riskAnswers.movesMoney === undefined
? {}
: { movesMoney: riskAnswers.movesMoney }),
steeredByUntrustedContent: riskAnswers.steeredByUntrustedContent,
sendsPrivateDataOut: riskAnswers.sendsPrivateDataOut,
...(riskAnswers.guidanceFlagsRisk === undefined
Expand Down
Loading