| Field | Type | Description |
|---|---|---|
preapproved_call_ids |
frozenset[str] |
Deprecated pre-approved call ids for compatibility. |
allow_all_destructive |
bool |
Destructive-operation bypass request. It is inert in prompt mode and is only honored after promotion to an explicit full-access mode. |
full_access_acknowledged |
bool |
Compatibility metadata recording that a higher-level caller acknowledged full-access semantics; it is not sufficient by itself to bypass approval. |
permission_mode |
PermissionMode |
Active permission mode for call evaluation. |
approval_store |
`ApprovalPresetStore | None` |
multi_sig_config |
MultiSigQuorumConfig |
Quorum requirements for high-risk approvals. |
agent_id |
str |
Agent identifier for quorum operations. |
workspace_root |
str |
Workspace root used in approval coordination. |
| Field | Type | Description |
|---|---|---|
READ_ONLY |
str |
Blocks destructive/write tool execution. |
WORKSPACE_WRITE |
str |
Allows workspace writes with governance checks. |
PROMPT |
str |
Requires approval prompt for destructive calls. |
ALLOW |
str |
Allows destructive calls without prompt. |
DANGER_FULL_ACCESS |
str |
Full-access mode for trusted automation. |
ApprovalPolicy.assert_allowed(*, tool_name: str, call_id: str, destructive: bool, arguments: dict[str, Any] | None = None, jit_state: JITApprovalState | None = None, plan_contract: Any = None, read_only: bool | None = None, description: str = '', handler: Any | None = None) -> None
Location: teaagent/policy.py:88
Pre-condition: Call metadata and policy context are provided.
Post-condition: Returns None if allowed; raises permission/policy exception if denied.
Location: teaagent/policy.py:531
Pre-condition: value is permission-mode text.
Post-condition: Returns enum on valid input; raises ValueError listing supported values otherwise.