Bounded actors
Agents
Each agent runs with an explicit allow-list; anything not granted is denied and recorded.
Discovery Agent
Allowed
extract_knownsgenerate_questionsupdate_domain_scoresForbidden
create_projectapprovewrite_evidencemodify_rulesEvidence Agent
Allowed
attach_evidenceclassify_evidencelink_truth_to_sourceForbidden
create_projectevaluate_rulesapprovemodify_rulesReporting Agent
Allowed
summarize_sessiongenerate_reportForbidden
create_projectmodify_session_scoresattach_evidenceapproveevaluate_rulesValidation Agent