Skip to content

Let named operators assign the agent work, when the operator opts them in - #847

Merged
jeremy merged 11 commits into
connect-rolefrom
connect-assignments
Oct 7, 2026
Merged

jeremy merged 11 commits into
connect-rolefrom
connect-assignments

Conversation

@jeremy

@jeremy jeremy commented Oct 6, 2026 •

Copy link
Copy Markdown
Member

Ports --allow-assignments-from-authorized from basecamp-local-agent-connector. Stacked on #843 (base connect-role): the two touched the same trust code and setup text, so this is rebased onto #843 with the conflicts resolved. It retargets to main once #843 merges. On #843 the opt-in also covers operators named beside --trust project, and a test holds that the project's members still can't assign.

Why the local connector's caution doesn't carry over

The local connector keeps assignments operator-only by default because it reads the assigner from a webhook payload it can't corroborate, so there the opt-in rests on a secret URL path. Here the assigner is the account feed's creator_id / performed_by_id. Basecamp writes that from the session that made the change; no payload carries it, and the gate already trusts it for every other trigger.

So naming someone and opting them in trusts that person, not text claiming to be them. Admission still reads the recording's events to confirm this assignment added the agent, and that the agent is still assigned (invariant 2).

What changes

  • connect.json gains trust.allow_assignments.
  • Gate: Policy.Validate refuses allow_assignments when the allowlist names nobody. The gate opens the assigned rule to a performer the allowlist names only when the opt-in is on. Project members, strangers and agents gain nothing.
  • Setup: connect setup --allow-assignments-from-authorized turns it on, and =false turns it off. Leaving the flag out keeps what the file has. Setting it with nobody named is refused, and a run that leaves nobody named drops it, so the file never carries an opt-in nobody can use. It's added to guided setup's policy flags.
  • Docs: connect show says "they may assign". The setup help, the admission invariants and the skill's phrase table follow.

Tests

Each fails without the change:

  • TestNamedOperatorsMayAssignWhenOptedIn (admission)
  • TestApplyAssignmentOptIn (setup)
  • TestConnectSetupOptsNamedOperatorsInToAssignments (command)

make check passes on linux.


Summary by cubic

Lets named operators assign the agent work, when the operator opts them in.

  • --allow now works with --trust project, and the assignment opt-in (--allow-assignments-from-authorized) rides with --allow: a run that passes --allow restates it, off unless the flag is passed again, and a run that passes neither keeps both.
  • The opt-in is recorded as trust.allow_assignments. Setting it with nobody named is refused, as is an allowlist naming only the operator; a run that leaves nobody named drops it. The assigner is the account feed's performer, which Basecamp writes, so naming someone trusts that person.
  • Admission still confirms the recording's events show this assignment added the agent and that the agent is still assigned.

Written for commit 1f5ed62. Summary will update on new commits.

Review in cubic Turn on auto-fix

@jeremy
jeremy requested a review from a team as a code owner October 6, 2026 05:23
Copilot AI balanced review requested due to automatic review settings October 6, 2026 05:23
@jeremy

jeremy commented Oct 6, 2026

Copy link
Copy Markdown
Member Author

@codex review

@github-actions github-actions Bot added commands CLI command implementations tests Tests (unit and e2e) skills Agent skills labels Oct 6, 2026
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-06T23:45:17.941056Z 1f5ed62 Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 11 files

Reply with feedback, questions, or to request a fix.

Re-trigger cubic

Comment thread skills/basecamp-connect/SKILL.md Outdated
Comment thread internal/connector/admission/matrix.go Outdated
Comment thread internal/commands/connect.go Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: dcb8127086

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread skills/basecamp-connect/SKILL.md Outdated
Comment thread internal/commands/connect.go Outdated
Copilot AI balanced review requested due to automatic review settings October 6, 2026 05:41

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@jeremy

jeremy commented Oct 6, 2026

Copy link
Copy Markdown
Member Author

@codex review

@jeremy

jeremy commented Oct 6, 2026

Copy link
Copy Markdown
Member Author

@cubic-dev-ai review

@jeremy
jeremy requested a balanced review from Copilot October 6, 2026 05:44
@cubic-dev-ai

cubic-dev-ai Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review

@jeremy I have started the AI code review. It will take a few minutes to complete.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 11 files

Re-trigger cubic

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Hooray!

Reviewed commit: e944b9f5bd

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@jeremy

jeremy commented Oct 6, 2026 •

Copy link
Copy Markdown
Member Author

Review state at head cbc0db1

How the opt-in behaves across setup runs. Four review rounds each found a case where inferring "someone new was named" went wrong, so there's now one history-free rule:

  • It rides with --allow. A run that passes --allow restates the opt-in: off unless it passes the flag too. A run that passes neither keeps both.
  • One asked for with nobody to cover is refused. If this run passes the flag and the allowlist names nobody besides the operator, setup refuses. If a kept opt-in is left covering nobody, it's dropped (setup.SetOperator).
  • It needs someone besides the operator. Validate requires the allowlist to name someone other than the operator.

The help, the field contract and the skill all say this. The skill presents the opt-in as covering the whole allowlist, to be confirmed with the person.

Declined earlier: .surface regeneration. basecamp connect is hidden.

Copilot AI balanced review requested due to automatic review settings October 6, 2026 19:49
@jeremy
jeremy force-pushed the connect-assignments branch from e944b9f to b5cf878 Compare October 6, 2026 19:49

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 15 files (changes from recent commits).

Reply with feedback, questions, or to request a fix.

Turn on auto-fix | Re-trigger cubic

Comment thread skills/basecamp-connect/SKILL.md Outdated
Comment thread internal/connector/setup/apply_test.go
Comment thread internal/connector/handoff_test.go Outdated
@jeremy
jeremy changed the base branch from main to connect-role October 6, 2026 19:54
@jeremy
jeremy requested a balanced review from Copilot October 6, 2026 22:26
@cubic-dev-ai

cubic-dev-ai Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review

@jeremy I have started the AI code review. It will take a few minutes to complete.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Keep it up!

Reviewed commit: cbc0db1eae

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 11 files

Turn on auto-fix | Re-trigger cubic

jeremy added 11 commits October 6, 2026 16:38
…m in

The local agent connector's --allow-assignments-from-authorized lets the
people named with --allow trigger the agent by assignment, not only the
operator. basecamp connect kept assignments the operator's alone in
every mode, and there was no way to say otherwise.

The local connector's caution doesn't carry over. It reads the assigner
from a webhook payload it cannot corroborate, so there the opt-in rests
on a secret URL path. Here the assigner is the account feed's performer,
which Basecamp writes from the session that made the change; no payload
carries it, and the gate trusts that id. Opting a named person in trusts
that person, not text claiming to be them. Admission still reads the
recording's events to confirm this assignment added the agent, and that
the agent is still assigned.

setup takes --allow-assignments-from-authorized (=false to undo) and
records it as trust.allow_assignments. It rides with the allowlist:
setting it with nobody named is refused, and a run that leaves nobody
named drops it. Project members, strangers and agents gain nothing.
Rebased onto #843: the gate settles a performer's role once, so the
opt-in reads that role instead of searching the allowlist again, and a
test holds that it covers operators named beside project trust while
the project's members still cannot assign.
…ery named operator

An allowlist naming only the operator gives the opt-in nobody to cover,
and setup's refusal of an opt-in now checks connect.json is unchanged.
The skill presents the opt-in as what it is, every named operator at
once, so asking for one person's assignments confirms who else gains
them.
The opt-in was given for the people named then. A later run that names
others now leaves their assignments off unless it passes the opt-in
again, so nobody newly named gains assignments unasked. The skill says
the opt-in covers the whole allowlist setup leaves, and tests cover it
set over a kept list and refused under project trust with nobody named.
Only someone newly named could gain assignments unasked, so the same
list again, or a shorter one, keeps the opt-in; a list adding anyone
still turns it off unless it is restated.
Making the allowlist's one person the operator left the opt-in nobody to
cover, and connect.json then refused to validate over a change setup
itself made. Setting the operator now drops an opt-in with nobody left.
…nly a kept one

Settle when the opt-in has nobody to cover with one rule, decided once
the run's operator is known: asked for in this run, it is refused so the
person learns it does nothing; kept from an earlier run, it is dropped.
The refusal names the allowlist rather than --allow, since the list can
come from connect.json.
Four rounds of review each found a case where deciding whether a new
list named someone new went wrong: the same list again, a former
operator retained, an operator promoted. Drop the comparison. A run that
passes --allow restates the opt-in with the list, off unless it passes
the flag too; a run that passes neither keeps both. The help, the field
contract and the skill say so.
@jeremy
jeremy force-pushed the connect-assignments branch from cbc0db1 to 1f5ed62 Compare October 6, 2026 23:38
@jeremy

jeremy commented Oct 6, 2026

Copy link
Copy Markdown
Member Author

@codex review

@jeremy

jeremy commented Oct 6, 2026

Copy link
Copy Markdown
Member Author

@cubic-dev-ai review

@jeremy
jeremy requested a balanced review from Copilot October 6, 2026 23:42
@cubic-dev-ai

cubic-dev-ai Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review

@jeremy I have started the AI code review. It will take a few minutes to complete.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. More of your lovely PRs please.

Reviewed commit: 1f5ed625da

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 11 files

Turn on auto-fix | Re-trigger cubic

@jeremy
jeremy added this pull request to stack #858 October 7, 2026 03:46
@jeremy
jeremy merged commit c97b3ef into main Oct 7, 2026
30 of 31 checks passed
@jeremy
jeremy deleted the connect-assignments branch October 7, 2026 03:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

commands CLI command implementations skills Agent skills tests Tests (unit and e2e)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants