RT-GATE
14 rules. Part II of the specification.
- RT-GATE-1A gated node never executes without consent for that exact call
- RT-GATE-2Consent is consumed exactly once, declines included
- RT-GATE-3Consent binds to the node and its exact resolved arguments
- RT-GATE-4A declined node routes a structured verdict out its error port
- RT-GATE-5A declined tool call is model-recoverable, never run-fatal
- RT-GATE-6A gate pause leaves no phantom failure in the tool trail
- RT-GATE-7Whether a node asks is a governance decision, resolved in order
- RT-GATE-8Governance can revoke a waiver already stored
- RT-GATE-9Dynamic escalation can add an approval but never remove one
- RT-GATE-11A gated node whose executor cannot be resolved never executes
- RT-GATE-12A resolved secret never persists in the gate prompt
- RT-GATE-13A gate question belongs to the initiator, and an ownerless one is findable
- RT-GATE-14Confirmation governance is its own grant
- RT-GATE-15A shipped side-effecting node type states its policy