{"_id":"@decionis/agent-safe-pipeline","_rev":"11-8aabe3737d3809a4b34f15535b821e78","name":"@decionis/agent-safe-pipeline","dist-tags":{"next":"0.1.3-rc.2","latest":"0.3.5"},"versions":{"0.1.2":{"name":"@decionis/agent-safe-pipeline","version":"0.1.2","author":{"name":"Decionis, Inc."},"license":"Apache-2.0","_id":"@decionis/agent-safe-pipeline@0.1.2","maintainers":[{"name":"decionis","email":"festus@binariesfort.com"}],"homepage":"https://github.com/decionis/agent-safe-pipeline/tree/master/packages/pipeline#readme","bugs":{"url":"https://github.com/decionis/agent-safe-pipeline/issues"},"dist":{"shasum":"e91e066f800f76fe313edbb97542c4c965e6c1d4","tarball":"https://registry.npmjs.org/@decionis/agent-safe-pipeline/-/agent-safe-pipeline-0.1.2.tgz","fileCount":72,"integrity":"sha512-SvgrJhpVHzX9gGUo4BJ3q7Ae1UGmhL4RMJD7NLImVSUh73xx2cHrNMqmgT6fjV0VSG0z4H+3iBWvW3cTqprnxQ==","signatures":[{"sig":"MEUCIEVcw2BOK8zrwQhUyp33e7b5HYoc4zljRBDIRCApaG66AiEA6j++YDlxQALWuXVQBbjgcbAJ5he0QwdU/p0t653Z4H8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@decionis%2fagent-safe-pipeline@0.1.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":117140},"main":"./dist/Index.js","type":"module","_from":"file:/home/runner/work/_temp/npm-bootstrap/decionis-agent-safe-pipeline-0.1.2.tgz","types":"./dist/Index.d.ts","engines":{"node":">=22.14.0"},"exports":{".":{"types":"./dist/Index.d.ts","import":"./dist/Index.js"}},"scripts":{"test":"vitest run --coverage","build":"node ../../scripts/CleanBuildOutput.mjs && tsc -p tsconfig.build.json","typecheck":"tsc -p tsconfig.json --noEmit","test:mutation":"stryker run","test:performance":"vitest run test/performance"},"_npmUser":{"name":"decionis","email":"festus@binariesfort.com"},"_resolved":"/home/runner/work/_temp/npm-bootstrap/decionis-agent-safe-pipeline-0.1.2.tgz","_integrity":"sha512-SvgrJhpVHzX9gGUo4BJ3q7Ae1UGmhL4RMJD7NLImVSUh73xx2cHrNMqmgT6fjV0VSG0z4H+3iBWvW3cTqprnxQ==","repository":{"url":"git+https://github.com/decionis/agent-safe-pipeline.git","type":"git","directory":"packages/pipeline"},"_npmVersion":"11.16.0","description":"An execution architecture where AI agents may propose actions but cannot authorize their own execution.","directories":{},"sideEffects":false,"_nodeVersion":"24.18.0","dependencies":{"zod":"^4.4.3","jose":"^6.2.8","@decionis/presence-node":"^0.2.0"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","@vitest/coverage-v8":"^4.1.10","@stryker-mutator/core":"10.0.0","@stryker-mutator/vitest-runner":"10.0.0"},"_npmOperationalInternal":{"tmp":"tmp/agent-safe-pipeline_0.1.2_1786886699999_0.2634662482352723","host":"s3://npm-registry-packages-npm-production"}},"0.1.3-rc.2":{"name":"@decionis/agent-safe-pipeline","version":"0.1.3-rc.2","author":{"name":"Decionis, Inc."},"license":"Apache-2.0","_id":"@decionis/agent-safe-pipeline@0.1.3-rc.2","maintainers":[{"name":"decionis","email":"festus@binariesfort.com"}],"homepage":"https://github.com/decionis/agent-safe-pipeline/tree/master/packages/pipeline#readme","bugs":{"url":"https://github.com/decionis/agent-safe-pipeline/issues"},"dist":{"shasum":"a61d4f2c358e2f592887875ab3269890654c64a7","tarball":"https://registry.npmjs.org/@decionis/agent-safe-pipeline/-/agent-safe-pipeline-0.1.3-rc.2.tgz","fileCount":72,"integrity":"sha512-M3jH/bZeHEQu8iLfCVCe/c3FbgJo7jaznvt/kudgv8iiMWEvZhFh6HdpdltZyWs/oAQSC6uSDKzuynKKY5e5TQ==","signatures":[{"sig":"MEYCIQDJytWZVH1g5kokVoLjSno8eD1R2EJhFMU0Y8Kq7UYz7AIhAL2559/pWGahUJAEEFM5eKoB274XaYnDG5MOE6pH9dPR","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@decionis%2fagent-safe-pipeline@0.1.3-rc.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":117229},"main":"./dist/Index.js","type":"module","_from":"file:release/decionis-agent-safe-pipeline-0.1.3-rc.2.tgz","types":"./dist/Index.d.ts","engines":{"node":">=22.14.0"},"exports":{".":{"types":"./dist/Index.d.ts","import":"./dist/Index.js"}},"scripts":{"test":"vitest run --coverage","build":"node ../../scripts/CleanBuildOutput.mjs && tsc -p tsconfig.build.json","test:fuzz":"vitest run test/fuzz","typecheck":"tsc -p tsconfig.json --noEmit","test:mutation":"stryker run","test:performance":"vitest run test/performance"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a79ca30e-dc26-4c76-9ba4-16ccde48db68"}},"_resolved":"/home/runner/work/agent-safe-pipeline/agent-safe-pipeline/release/decionis-agent-safe-pipeline-0.1.3-rc.2.tgz","_integrity":"sha512-M3jH/bZeHEQu8iLfCVCe/c3FbgJo7jaznvt/kudgv8iiMWEvZhFh6HdpdltZyWs/oAQSC6uSDKzuynKKY5e5TQ==","repository":{"url":"git+https://github.com/decionis/agent-safe-pipeline.git","type":"git","directory":"packages/pipeline"},"_npmVersion":"11.16.0","description":"An execution architecture where AI agents may propose actions but cannot authorize their own execution.","directories":{},"sideEffects":false,"_nodeVersion":"24.18.0","dependencies":{"zod":"^4.4.3","jose":"^6.2.8","@decionis/presence-node":"^0.2.0"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"vitest":"^4.1.10","fast-check":"4.9.0","@vitest/coverage-v8":"^4.1.10","@stryker-mutator/core":"10.0.0","@stryker-mutator/vitest-runner":"10.0.0"},"_npmOperationalInternal":{"tmp":"tmp/agent-safe-pipeline_0.1.3-rc.2_1786891864082_0.9686205984708276","host":"s3://npm-registry-packages-npm-production"}},"0.1.3":{"name":"@decionis/agent-safe-pipeline","version":"0.1.3","author":{"name":"Decionis, Inc."},"license":"Apache-2.0","_id":"@decionis/agent-safe-pipeline@0.1.3","maintainers":[{"name":"decionis","email":"festus@binariesfort.com"}],"homepage":"https://github.com/decionis/agent-safe-pipeline/tree/master/packages/pipeline#readme","bugs":{"url":"https://github.com/decionis/agent-safe-pipeline/issues"},"dist":{"shasum":"b867379f224a84d1b4139e51c04267134483da78","tarball":"https://registry.npmjs.org/@decionis/agent-safe-pipeline/-/agent-safe-pipeline-0.1.3.tgz","fileCount":72,"integrity":"sha512-tBr0fAkszWu7gETQBe8IBIoUMDPZuvRvb1o6fi6QbO3WG3uZSXw3bao7F28AJPI1LKU30vkLaJXO2vQP6/bAhA==","signatures":[{"sig":"MEYCIQDL8NdBVsLwQX/H+JhMfq0GVfIYFFK21mVSlINTi1p5lgIhAPoPCt3wDOZbRG1o1ocqcFZ/Remh4y7E+vIfnOHCfkaw","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@decionis%2fagent-safe-pipeline@0.1.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":139530},"main":"./dist/Index.js","type":"module","_from":"file:release/decionis-agent-safe-pipeline-0.1.3.tgz","types":"./dist/Index.d.ts","engines":{"node":">=22.14.0"},"exports":{".":{"types":"./dist/Index.d.ts","import":"./dist/Index.js"}},"scripts":{"test":"vitest run --coverage","build":"node ../../scripts/CleanBuildOutput.mjs && tsc -p tsconfig.build.json","test:fuzz":"vitest run test/fuzz","typecheck":"tsc -p tsconfig.json --noEmit","test:mutation":"stryker run","test:performance":"vitest run test/performance"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a79ca30e-dc26-4c76-9ba4-16ccde48db68"}},"_resolved":"/home/runner/work/agent-safe-pipeline/agent-safe-pipeline/release/decionis-agent-safe-pipeline-0.1.3.tgz","_integrity":"sha512-tBr0fAkszWu7gETQBe8IBIoUMDPZuvRvb1o6fi6QbO3WG3uZSXw3bao7F28AJPI1LKU30vkLaJXO2vQP6/bAhA==","repository":{"url":"git+https://github.com/decionis/agent-safe-pipeline.git","type":"git","directory":"packages/pipeline"},"_npmVersion":"11.16.0","description":"An execution architecture where AI agents may propose actions but cannot authorize their own execution.","directories":{},"sideEffects":false,"_nodeVersion":"24.18.0","dependencies":{"zod":"^4.4.3","jose":"^6.2.9","@decionis/presence-node":"^0.2.0"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.11","fast-check":"4.9.0","@vitest/coverage-v8":"^4.1.10","@stryker-mutator/core":"10.0.0","@stryker-mutator/vitest-runner":"10.0.0"},"_npmOperationalInternal":{"tmp":"tmp/agent-safe-pipeline_0.1.3_1788561106175_0.31723531618829237","host":"s3://npm-registry-packages-npm-production"}},"0.1.4":{"name":"@decionis/agent-safe-pipeline","version":"0.1.4","keywords":["execution-authority","ai-agents","agentic-ai","ai-agent-permissions","agent-guardrails","agent-security","ai-safety","ai-governance","authorization","policy-as-code","policy-enforcement","human-in-the-loop","human-approval","approval-workflow","decision-dossier","decision-evidence","audit-trail","fail-closed","single-use-grant","intent-binding","least-privilege","shadow-mode","mcp","model-context-protocol","tool-calling","llm-agents","reference-architecture","typescript","decionis","presence"],"author":{"name":"Decionis, Inc."},"license":"Apache-2.0","_id":"@decionis/agent-safe-pipeline@0.1.4","maintainers":[{"name":"decionis","email":"festus@binariesfort.com"}],"homepage":"https://github.com/decionis/agent-safe-pipeline/tree/master/packages/pipeline#readme","bugs":{"url":"https://github.com/decionis/agent-safe-pipeline/issues"},"dist":{"shasum":"83b7511bf26471c8c52569e2a7459be334ec9592","tarball":"https://registry.npmjs.org/@decionis/agent-safe-pipeline/-/agent-safe-pipeline-0.1.4.tgz","fileCount":88,"integrity":"sha512-lWTF2LHZrcfr1j0HePS1CZB8Ubpyuu0qwwR+rsDoqRS2/+fNVsudKT14hNn6H3DI5idm5W3+2fMLekD7x7i0hA==","signatures":[{"sig":"MEQCIEaKPr6cwECxJ1//4ggY3kHiKXi6t5pTeQ2skQ5hpgYOAiAH66BlUA27DQF6K300+m4JQRei0kYaJR4kE3k516+/CQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@decionis%2fagent-safe-pipeline@0.1.4","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":473521},"main":"./dist/Index.js","type":"module","_from":"file:release/decionis-agent-safe-pipeline-0.1.4.tgz","types":"./dist/Index.d.ts","engines":{"node":">=22.14.0"},"exports":{".":{"types":"./dist/Index.d.ts","import":"./dist/Index.js"},"./testing":{"types":"./dist/testing/Index.d.ts","import":"./dist/testing/Index.js"}},"scripts":{"test":"vitest run --coverage","build":"node ../../scripts/CleanBuildOutput.mjs && tsc -p tsconfig.build.json","test:fuzz":"vitest run test/fuzz","typecheck":"tsc -p tsconfig.json --noEmit","test:mutation":"stryker run","test:performance":"vitest run test/performance"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a79ca30e-dc26-4c76-9ba4-16ccde48db68"}},"_resolved":"/home/runner/work/agent-safe-pipeline/agent-safe-pipeline/release/decionis-agent-safe-pipeline-0.1.4.tgz","_integrity":"sha512-lWTF2LHZrcfr1j0HePS1CZB8Ubpyuu0qwwR+rsDoqRS2/+fNVsudKT14hNn6H3DI5idm5W3+2fMLekD7x7i0hA==","repository":{"url":"git+https://github.com/decionis/agent-safe-pipeline.git","type":"git","directory":"packages/pipeline"},"_npmVersion":"11.16.0","description":"Execution Authority for AI agents: agents propose, Decionis independently decides ALLOW / ESCALATE / BLOCK, Presence verifies human approval on escalation, and a SafeExecutor runs only on a single-use intent-bound grant. Every decision leaves a Decision D","directories":{},"sideEffects":false,"_nodeVersion":"24.18.0","dependencies":{"zod":"^4.5.4","jose":"^6.2.10","@decionis/presence-node":"^0.2.0"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.11","fast-check":"4.9.0","@vitest/coverage-v8":"^4.1.10","@stryker-mutator/core":"10.0.0","@stryker-mutator/vitest-runner":"10.0.0"},"_npmOperationalInternal":{"tmp":"tmp/agent-safe-pipeline_0.1.4_1789051893822_0.48566578750422273","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@decionis/agent-safe-pipeline","version":"0.2.0","keywords":["execution-authority","ai-agents","agentic-ai","ai-agent-permissions","agent-guardrails","agent-security","ai-safety","ai-governance","authorization","policy-as-code","policy-enforcement","human-in-the-loop","human-approval","approval-workflow","decision-dossier","decision-evidence","audit-trail","fail-closed","single-use-grant","intent-binding","least-privilege","shadow-mode","mcp","model-context-protocol","tool-calling","llm-agents","reference-architecture","typescript","decionis","presence"],"author":{"name":"Decionis, Inc."},"license":"Apache-2.0","_id":"@decionis/agent-safe-pipeline@0.2.0","maintainers":[{"name":"decionis","email":"festus@binariesfort.com"}],"homepage":"https://github.com/decionis/agent-safe-pipeline/tree/master/packages/pipeline#readme","bugs":{"url":"https://github.com/decionis/agent-safe-pipeline/issues"},"dist":{"shasum":"4daf3d86867b0c5e29ca0131280ed16f9bf4632f","tarball":"https://registry.npmjs.org/@decionis/agent-safe-pipeline/-/agent-safe-pipeline-0.2.0.tgz","fileCount":124,"integrity":"sha512-2KpzvJRFrIOtm5EGdtKiQn34CWEijSVA0JVOG+lIdxO66QGtW4z9R3s9m0DO+KwNRXYSQrLIH7MpZiiyFtdONA==","signatures":[{"sig":"MEYCIQC9CZPTnUY6qVl7eXzvMOgc2wWNNFqGZ0PvdEhMMqjTMAIhAKC3QHVNpvDvxvEMtW8xa9POUpvmn7K5KUK+gbILUboW","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCIEl7Q2LbcPkFIImhNTnOe5uOEJeFmTZS88yGRkqTEUnTAiBkYLwoeXtG6hsg22ApVyic7x7jTKzQ2gZmGuBn5ajt3w==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@decionis%2fagent-safe-pipeline@0.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":650932},"main":"./dist/Index.js","type":"module","_from":"file:release/decionis-agent-safe-pipeline-0.2.0.tgz","types":"./dist/Index.d.ts","engines":{"node":">=22.14.0"},"exports":{".":{"types":"./dist/Index.d.ts","import":"./dist/Index.js"},"./testing":{"types":"./dist/testing/Index.d.ts","import":"./dist/testing/Index.js"}},"scripts":{"test":"vitest run --coverage","build":"node ../../scripts/CleanBuildOutput.mjs && tsc -p tsconfig.build.json","test:fuzz":"vitest run test/fuzz","typecheck":"tsc -p tsconfig.json --noEmit","test:mutation":"stryker run","test:performance":"vitest run test/performance"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a79ca30e-dc26-4c76-9ba4-16ccde48db68"}},"_resolved":"/home/runner/work/agent-safe-pipeline/agent-safe-pipeline/release/decionis-agent-safe-pipeline-0.2.0.tgz","_integrity":"sha512-2KpzvJRFrIOtm5EGdtKiQn34CWEijSVA0JVOG+lIdxO66QGtW4z9R3s9m0DO+KwNRXYSQrLIH7MpZiiyFtdONA==","repository":{"url":"git+https://github.com/decionis/agent-safe-pipeline.git","type":"git","directory":"packages/pipeline"},"_npmVersion":"11.16.0","description":"Execution Authority for AI agents: agents propose, Decionis independently decides ALLOW / ESCALATE / BLOCK, Presence verifies human approval on escalation, and a SafeExecutor runs only on a single-use intent-bound grant. Every decision leaves a Decision D","directories":{},"sideEffects":false,"_nodeVersion":"24.18.0","dependencies":{"zod":"^4.5.4","jose":"^6.2.10","@decionis/presence-node":"^0.2.0"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.11","fast-check":"4.9.0","@vitest/coverage-v8":"^4.1.10","@stryker-mutator/core":"10.0.0","@stryker-mutator/vitest-runner":"10.0.0"},"_npmOperationalInternal":{"tmp":"tmp/agent-safe-pipeline_0.2.0_1789711118141_0.9006469211452073","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@decionis/agent-safe-pipeline","version":"0.3.0","keywords":["execution-authority","ai-agents","agentic-ai","ai-agent-permissions","agent-guardrails","agent-security","ai-safety","ai-governance","authorization","policy-as-code","policy-enforcement","human-in-the-loop","human-approval","approval-workflow","decision-dossier","decision-evidence","audit-trail","fail-closed","single-use-grant","intent-binding","least-privilege","shadow-mode","mcp","model-context-protocol","tool-calling","llm-agents","reference-architecture","typescript","decionis","presence"],"author":{"name":"Decionis, Inc."},"license":"Apache-2.0","_id":"@decionis/agent-safe-pipeline@0.3.0","maintainers":[{"name":"decionis","email":"festus@binariesfort.com"}],"homepage":"https://github.com/decionis/agent-safe-pipeline/tree/master/packages/pipeline#readme","bugs":{"url":"https://github.com/decionis/agent-safe-pipeline/issues"},"dist":{"shasum":"bc8824c6677b435a41ea85189ef7e6539c9e79db","tarball":"https://registry.npmjs.org/@decionis/agent-safe-pipeline/-/agent-safe-pipeline-0.3.0.tgz","fileCount":124,"integrity":"sha512-oDoyacg0K5gtZd570CkZQ7Yhf8oA1YBtUWCLxHUDyJHCJ9d8QUMJTNoCTOfnWHSnqZXlJcHnyc9ustDMSiQAtg==","signatures":[{"sig":"MEYCIQCKTk+1zm+uoAu6oRJqsyiKI58Yy4Hq5fyfoeJCSv1Z6AIhAKr9E/Y9oLUKdT5Z8EO1Uy/gGpFnaxm2Hr//cm/j4wJ2","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIQDL0r0MtTUC7f3oFie/Ux7YpiKx1NoBdrOPYWHy3o7FYgIgOWOmb+NMGHJjLHGiFIuYGLHq5HCRJcxmYAx5dgSyVhM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@decionis%2fagent-safe-pipeline@0.3.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":678901},"main":"./dist/Index.js","type":"module","_from":"file:release/decionis-agent-safe-pipeline-0.3.0.tgz","types":"./dist/Index.d.ts","engines":{"node":">=22.14.0"},"exports":{".":{"types":"./dist/Index.d.ts","import":"./dist/Index.js"},"./testing":{"types":"./dist/testing/Index.d.ts","import":"./dist/testing/Index.js"}},"scripts":{"test":"vitest run --coverage","build":"node ../../scripts/CleanBuildOutput.mjs && tsc -p tsconfig.build.json","test:fuzz":"vitest run test/fuzz","typecheck":"tsc -p tsconfig.json --noEmit","test:mutation":"stryker run","test:performance":"vitest run test/performance"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a79ca30e-dc26-4c76-9ba4-16ccde48db68"}},"_resolved":"/home/runner/work/agent-safe-pipeline/agent-safe-pipeline/release/decionis-agent-safe-pipeline-0.3.0.tgz","_integrity":"sha512-oDoyacg0K5gtZd570CkZQ7Yhf8oA1YBtUWCLxHUDyJHCJ9d8QUMJTNoCTOfnWHSnqZXlJcHnyc9ustDMSiQAtg==","repository":{"url":"git+https://github.com/decionis/agent-safe-pipeline.git","type":"git","directory":"packages/pipeline"},"_npmVersion":"11.16.0","description":"Execution Authority for AI agents: agents propose, Decionis independently decides ALLOW / ESCALATE / BLOCK, Presence verifies human approval on escalation, and a SafeExecutor runs only on a single-use intent-bound grant. Every decision leaves a Decision D","directories":{},"sideEffects":false,"_nodeVersion":"24.18.0","dependencies":{"zod":"^4.5.4","jose":"^6.2.10","@decionis/presence-node":"^0.2.0"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.11","fast-check":"4.9.0","@vitest/coverage-v8":"^4.1.10","@stryker-mutator/core":"10.0.0","@stryker-mutator/vitest-runner":"10.0.0"},"_npmOperationalInternal":{"tmp":"tmp/agent-safe-pipeline_0.3.0_1789841872101_0.8200152016398756","host":"s3://npm-registry-packages-npm-production"}},"0.3.1":{"name":"@decionis/agent-safe-pipeline","version":"0.3.1","keywords":["execution-authority","ai-agents","agentic-ai","ai-agent-permissions","agent-guardrails","agent-security","ai-safety","ai-governance","authorization","policy-as-code","policy-enforcement","human-in-the-loop","human-approval","approval-workflow","decision-dossier","decision-evidence","audit-trail","fail-closed","single-use-grant","intent-binding","least-privilege","shadow-mode","mcp","model-context-protocol","tool-calling","llm-agents","reference-architecture","typescript","decionis","presence"],"author":{"name":"Decionis, Inc."},"license":"Apache-2.0","_id":"@decionis/agent-safe-pipeline@0.3.1","maintainers":[{"name":"decionis","email":"festus@binariesfort.com"}],"homepage":"https://github.com/decionis/agent-safe-pipeline/tree/master/packages/pipeline#readme","bugs":{"url":"https://github.com/decionis/agent-safe-pipeline/issues"},"dist":{"shasum":"6fed19389b823417d6c5eaf2bab3de6eb4193218","tarball":"https://registry.npmjs.org/@decionis/agent-safe-pipeline/-/agent-safe-pipeline-0.3.1.tgz","fileCount":128,"integrity":"sha512-YG8ecfFlSAx3nHsWYRPpf0ucxcnRlnnj/UNyv9s/L4T89M8gvPyO5LNZ6zKwlHyFc1CWzLN9uBQ9QBS2U2+x3g==","signatures":[{"sig":"MEYCIQCYDLxySZ0OUP5OS3SHdsJwLbmvInH1tl1rUx4TDTS/RwIhANBJMSOrWKmo2DoQ3/n3TyAe37JU2aLdZlKQE+1ku29X","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEYCIQDC8aNAFWI9RybkUpSWO//eGQn6uUjvPjG9BUKcs5FIZwIhAIoUK0nSPsmzMcnYQjJKI/FSiGqm+g16xYrrey6uWFXT","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@decionis%2fagent-safe-pipeline@0.3.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":688023},"main":"./dist/Index.js","type":"module","_from":"file:release/decionis-agent-safe-pipeline-0.3.1.tgz","types":"./dist/Index.d.ts","engines":{"node":">=22.14.0"},"exports":{".":{"types":"./dist/Index.d.ts","import":"./dist/Index.js"},"./testing":{"types":"./dist/testing/Index.d.ts","import":"./dist/testing/Index.js"}},"scripts":{"test":"vitest run --coverage","build":"node ../../scripts/CleanBuildOutput.mjs && tsc -p tsconfig.build.json","test:fuzz":"vitest run test/fuzz","typecheck":"tsc -p tsconfig.json --noEmit","test:mutation":"stryker run","test:performance":"vitest run test/performance"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a79ca30e-dc26-4c76-9ba4-16ccde48db68"}},"_resolved":"/home/runner/work/agent-safe-pipeline/agent-safe-pipeline/release/decionis-agent-safe-pipeline-0.3.1.tgz","_integrity":"sha512-YG8ecfFlSAx3nHsWYRPpf0ucxcnRlnnj/UNyv9s/L4T89M8gvPyO5LNZ6zKwlHyFc1CWzLN9uBQ9QBS2U2+x3g==","repository":{"url":"git+https://github.com/decionis/agent-safe-pipeline.git","type":"git","directory":"packages/pipeline"},"_npmVersion":"11.16.0","description":"Execution Authority for AI agents: agents propose, Decionis independently decides ALLOW / ESCALATE / BLOCK, Presence verifies human approval on escalation, and a SafeExecutor runs only on a single-use intent-bound grant. Every decision leaves a Decision D","directories":{},"sideEffects":false,"_nodeVersion":"24.18.0","dependencies":{"zod":"^4.5.4","jose":"^6.2.10","@decionis/presence-node":"^0.2.0"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.11","fast-check":"4.9.0","@vitest/coverage-v8":"^4.1.10","@stryker-mutator/core":"10.0.0","@stryker-mutator/vitest-runner":"10.0.0"},"_npmOperationalInternal":{"tmp":"tmp/agent-safe-pipeline_0.3.1_1789890181893_0.010519945012078757","host":"s3://npm-registry-packages-npm-production"}},"0.3.2":{"name":"@decionis/agent-safe-pipeline","version":"0.3.2","keywords":["execution-authority","ai-agents","agentic-ai","ai-agent-permissions","agent-guardrails","agent-security","ai-safety","ai-governance","authorization","policy-as-code","policy-enforcement","human-in-the-loop","human-approval","approval-workflow","decision-dossier","decision-evidence","audit-trail","fail-closed","single-use-grant","intent-binding","least-privilege","shadow-mode","mcp","model-context-protocol","tool-calling","llm-agents","reference-architecture","typescript","decionis","presence"],"author":{"name":"Decionis, Inc."},"license":"Apache-2.0","_id":"@decionis/agent-safe-pipeline@0.3.2","maintainers":[{"name":"decionis","email":"festus@binariesfort.com"}],"homepage":"https://github.com/decionis/agent-safe-pipeline/tree/master/packages/pipeline#readme","bugs":{"url":"https://github.com/decionis/agent-safe-pipeline/issues"},"dist":{"shasum":"95e2f0d55aeeba29e63f501abbeb19ad665dded7","tarball":"https://registry.npmjs.org/@decionis/agent-safe-pipeline/-/agent-safe-pipeline-0.3.2.tgz","fileCount":128,"integrity":"sha512-msz27filVU0hKOlC1oFsk7OrPu/pniDWjuxIydcMGXt2PHNhjak8yknUOCt6KegQv9oJ81bgeAECJ2Td/liCGg==","signatures":[{"sig":"MEQCIFm2J9a50X39AxKKc4FSkdg2zNPb1mbxXGfz/q41lWq2AiBkdhQnS4NnpOSVXn9wvv6r7FWYOI6/PWLgtlm32JxgtQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEYCIQCjmjFKUKA/LyjJQHAGLKJmNDZ5ieZGDDymrsDz9XarzQIhAJ6I1gS+ux4b+NFJgj6ly1GjU19wVnemkttm7Fzpzs1Q","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@decionis%2fagent-safe-pipeline@0.3.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":688023},"main":"./dist/Index.js","type":"module","_from":"file:release/decionis-agent-safe-pipeline-0.3.2.tgz","types":"./dist/Index.d.ts","engines":{"node":">=22.14.0"},"exports":{".":{"types":"./dist/Index.d.ts","import":"./dist/Index.js"},"./testing":{"types":"./dist/testing/Index.d.ts","import":"./dist/testing/Index.js"}},"scripts":{"test":"vitest run --coverage","build":"node ../../scripts/CleanBuildOutput.mjs && tsc -p tsconfig.build.json","test:fuzz":"vitest run test/fuzz","typecheck":"tsc -p tsconfig.json --noEmit","test:mutation":"stryker run","test:performance":"vitest run test/performance"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a79ca30e-dc26-4c76-9ba4-16ccde48db68"}},"_resolved":"/home/runner/work/agent-safe-pipeline/agent-safe-pipeline/release/decionis-agent-safe-pipeline-0.3.2.tgz","_integrity":"sha512-msz27filVU0hKOlC1oFsk7OrPu/pniDWjuxIydcMGXt2PHNhjak8yknUOCt6KegQv9oJ81bgeAECJ2Td/liCGg==","repository":{"url":"git+https://github.com/decionis/agent-safe-pipeline.git","type":"git","directory":"packages/pipeline"},"_npmVersion":"11.16.0","description":"Execution Authority for AI agents: agents propose, Decionis independently decides ALLOW / ESCALATE / BLOCK, Presence verifies human approval on escalation, and a SafeExecutor runs only on a single-use intent-bound grant. Every decision leaves a Decision D","directories":{},"sideEffects":false,"_nodeVersion":"24.18.0","dependencies":{"zod":"^4.5.4","jose":"^6.2.10","@decionis/presence-node":"^0.2.0"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.11","fast-check":"4.9.0","@vitest/coverage-v8":"^4.1.10","@stryker-mutator/core":"10.0.0","@stryker-mutator/vitest-runner":"10.0.0"},"_npmOperationalInternal":{"tmp":"tmp/agent-safe-pipeline_0.3.2_1789930668705_0.617228293921182","host":"s3://npm-registry-packages-npm-production"}},"0.3.3":{"name":"@decionis/agent-safe-pipeline","version":"0.3.3","keywords":["execution-authority","ai-agents","agentic-ai","ai-agent-permissions","agent-guardrails","agent-security","ai-safety","ai-governance","authorization","policy-as-code","policy-enforcement","human-in-the-loop","human-approval","approval-workflow","decision-dossier","decision-evidence","audit-trail","fail-closed","single-use-grant","intent-binding","least-privilege","shadow-mode","mcp","model-context-protocol","tool-calling","llm-agents","reference-architecture","typescript","decionis","presence"],"author":{"name":"Decionis, Inc."},"license":"Apache-2.0","_id":"@decionis/agent-safe-pipeline@0.3.3","maintainers":[{"name":"decionis","email":"festus@binariesfort.com"}],"homepage":"https://github.com/decionis/agent-safe-pipeline/tree/master/packages/pipeline#readme","bugs":{"url":"https://github.com/decionis/agent-safe-pipeline/issues"},"dist":{"shasum":"13995b3020e921a2e025ae3628e0dc3f86250530","tarball":"https://registry.npmjs.org/@decionis/agent-safe-pipeline/-/agent-safe-pipeline-0.3.3.tgz","fileCount":128,"integrity":"sha512-+BItqLWcR2gyHchOR0Drl5y9/dqDZ8sE3+hRJcdb9q5c/2QKi5qmdnz3JgOs3LN7NncW2Q3hUGbNVPo62n+U9w==","signatures":[{"sig":"MEUCIFNCC/3KxfVfMIP7vfU4sV9Pf0b4woVtnvrGQ0jHkoYPAiEAqYjWtfdrUX0vdn7f77IDfwEga9o7ioBA+9Up0xnQ9VE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIQC31TSe68hc7vkzmPuLVKWC2rq9broAnoQ8sfNh62jYIQIgDpncVfIyIuu7mjL5W572cOjeMWvkjgs0OkBokn/nEzo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@decionis%2fagent-safe-pipeline@0.3.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":688023},"main":"./dist/Index.js","type":"module","_from":"file:release/decionis-agent-safe-pipeline-0.3.3.tgz","types":"./dist/Index.d.ts","engines":{"node":">=22.14.0"},"exports":{".":{"types":"./dist/Index.d.ts","import":"./dist/Index.js"},"./testing":{"types":"./dist/testing/Index.d.ts","import":"./dist/testing/Index.js"}},"scripts":{"test":"vitest run --coverage","build":"node ../../scripts/CleanBuildOutput.mjs && tsc -p tsconfig.build.json","test:fuzz":"vitest run test/fuzz","typecheck":"tsc -p tsconfig.json --noEmit","test:mutation":"stryker run","test:performance":"vitest run test/performance"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a79ca30e-dc26-4c76-9ba4-16ccde48db68"}},"_resolved":"/home/runner/work/agent-safe-pipeline/agent-safe-pipeline/release/decionis-agent-safe-pipeline-0.3.3.tgz","_integrity":"sha512-+BItqLWcR2gyHchOR0Drl5y9/dqDZ8sE3+hRJcdb9q5c/2QKi5qmdnz3JgOs3LN7NncW2Q3hUGbNVPo62n+U9w==","repository":{"url":"git+https://github.com/decionis/agent-safe-pipeline.git","type":"git","directory":"packages/pipeline"},"_npmVersion":"11.16.0","description":"Execution Authority for AI agents: agents propose, Decionis independently decides ALLOW / ESCALATE / BLOCK, Presence verifies human approval on escalation, and a SafeExecutor runs only on a single-use intent-bound grant. Every decision leaves a Decision D","directories":{},"sideEffects":false,"_nodeVersion":"24.18.0","dependencies":{"zod":"^4.5.4","jose":"^6.2.10","@decionis/presence-node":"^0.2.0"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.11","fast-check":"4.9.0","@vitest/coverage-v8":"^4.1.10","@stryker-mutator/core":"10.0.0","@stryker-mutator/vitest-runner":"10.0.0"},"_npmOperationalInternal":{"tmp":"tmp/agent-safe-pipeline_0.3.3_1790016676086_0.7895139394044031","host":"s3://npm-registry-packages-npm-production"}},"0.3.4":{"name":"@decionis/agent-safe-pipeline","version":"0.3.4","keywords":["execution-authority","ai-agents","agentic-ai","ai-agent-permissions","agent-guardrails","agent-security","ai-safety","ai-governance","authorization","policy-as-code","policy-enforcement","human-in-the-loop","human-approval","approval-workflow","decision-dossier","decision-evidence","audit-trail","fail-closed","single-use-grant","intent-binding","least-privilege","shadow-mode","mcp","model-context-protocol","tool-calling","llm-agents","reference-architecture","typescript","decionis","presence"],"author":{"name":"Decionis, Inc."},"license":"Apache-2.0","_id":"@decionis/agent-safe-pipeline@0.3.4","maintainers":[{"name":"decionis","email":"festus@binariesfort.com"}],"homepage":"https://github.com/decionis/agent-safe-pipeline/tree/master/packages/pipeline#readme","bugs":{"url":"https://github.com/decionis/agent-safe-pipeline/issues"},"dist":{"shasum":"58a1fb68405c239de0737bb332faeeb0803039af","tarball":"https://registry.npmjs.org/@decionis/agent-safe-pipeline/-/agent-safe-pipeline-0.3.4.tgz","fileCount":128,"integrity":"sha512-HXMDhNv8LPC68JVRlvC6ZYUK5l3QWh+5h6UbfCDhZBljPGtShvkrfJuO8zfoJy7KyAPCiGga5GNQiGt2dC2eMg==","signatures":[{"sig":"MEQCIDY/UyaLLXa/+WnNfcZg3WRveR2pfyQz6ZQbTBU3RP+QAiA88z00oDsx3MYI6kvjyJPog8CUIvzfiXe4+qBX/EdR6A==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCIGYBb9cHsExZW1uw1KtdONkldV9MYrILAuRigOWBlrdQAiBr95lG/9DwxvFtvgS3edE9VJr+tpfKLUxB6dOWCGOVvA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@decionis%2fagent-safe-pipeline@0.3.4","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":688023},"main":"./dist/Index.js","type":"module","_from":"file:release/decionis-agent-safe-pipeline-0.3.4.tgz","types":"./dist/Index.d.ts","engines":{"node":">=22.14.0"},"exports":{".":{"types":"./dist/Index.d.ts","import":"./dist/Index.js"},"./testing":{"types":"./dist/testing/Index.d.ts","import":"./dist/testing/Index.js"}},"scripts":{"test":"vitest run --coverage","build":"node ../../scripts/CleanBuildOutput.mjs && tsc -p tsconfig.build.json","test:fuzz":"vitest run test/fuzz","typecheck":"tsc -p tsconfig.json --noEmit","test:mutation":"stryker run","test:performance":"vitest run test/performance"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a79ca30e-dc26-4c76-9ba4-16ccde48db68"}},"_resolved":"/home/runner/work/agent-safe-pipeline/agent-safe-pipeline/release/decionis-agent-safe-pipeline-0.3.4.tgz","_integrity":"sha512-HXMDhNv8LPC68JVRlvC6ZYUK5l3QWh+5h6UbfCDhZBljPGtShvkrfJuO8zfoJy7KyAPCiGga5GNQiGt2dC2eMg==","repository":{"url":"git+https://github.com/decionis/agent-safe-pipeline.git","type":"git","directory":"packages/pipeline"},"_npmVersion":"11.16.0","description":"Execution Authority for AI agents: agents propose, Decionis independently decides ALLOW / ESCALATE / BLOCK, Presence verifies human approval on escalation, and a SafeExecutor runs only on a single-use intent-bound grant. Every decision leaves a Decision D","directories":{},"sideEffects":false,"_nodeVersion":"24.18.0","dependencies":{"zod":"^4.5.4","jose":"^6.2.10","@decionis/presence-node":"^0.2.0"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.11","fast-check":"4.9.0","@vitest/coverage-v8":"^4.1.10","@stryker-mutator/core":"10.0.0","@stryker-mutator/vitest-runner":"10.0.0"},"_npmOperationalInternal":{"tmp":"tmp/agent-safe-pipeline_0.3.4_1790036937932_0.015004454796492706","host":"s3://npm-registry-packages-npm-production"}},"0.3.5":{"_id":"@decionis/agent-safe-pipeline@0.3.5","bugs":{"url":"https://github.com/decionis/agent-safe-pipeline/issues"},"dist":{"shasum":"1a622af11aafba7671080284bfc1868c215458a6","tarball":"https://registry.npmjs.org/@decionis/agent-safe-pipeline/-/agent-safe-pipeline-0.3.5.tgz","fileCount":132,"integrity":"sha512-eK1OR4M2TT0DrPfBg23azf/jpJIqJ62ihjgOUKMdnSaemOGX4HyYv9DrK4Xw5U1D/3kJB06/PkfzmH8prcvJtg==","signatures":[{"sig":"MEUCIDfTL7AqZ61AbaEACDaHm8iCkG3nx1fzShRpzlh1EAd8AiEA75D3AJdLVTeeFpOPtPsS3fJdQMiCLZjOojtJ1LxRXeI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQD9iGm9JjeYvUUtG4X1OzoiW4VUl6aGR+RF1Ag6rQkESQIgT+ateA1YEEMHLiEIIHEO85ciEmU4PBj+1lIrcmDnaZ4="}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@decionis%2fagent-safe-pipeline@0.3.5","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":710454},"main":"./dist/Index.js","name":"@decionis/agent-safe-pipeline","type":"module","_from":"file:release/decionis-agent-safe-pipeline-0.3.5.tgz","types":"./dist/Index.d.ts","author":{"name":"Decionis, Inc."},"engines":{"node":">=22.14.0"},"exports":{".":{"types":"./dist/Index.d.ts","import":"./dist/Index.js"},"./testing":{"types":"./dist/testing/Index.d.ts","import":"./dist/testing/Index.js"}},"license":"Apache-2.0","scripts":{"test":"vitest run --coverage","build":"node ../../scripts/CleanBuildOutput.mjs && tsc -p tsconfig.build.json","test:fuzz":"vitest run test/fuzz","typecheck":"tsc -p tsconfig.json --noEmit","test:mutation":"stryker run","test:performance":"vitest run test/performance"},"version":"0.3.5","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a79ca30e-dc26-4c76-9ba4-16ccde48db68"}},"homepage":"https://github.com/decionis/agent-safe-pipeline/tree/master/packages/pipeline#readme","keywords":["execution-authority","ai-agents","agentic-ai","ai-agent-permissions","agent-guardrails","agent-security","ai-safety","ai-governance","authorization","policy-as-code","policy-enforcement","human-in-the-loop","human-approval","approval-workflow","decision-dossier","decision-evidence","audit-trail","fail-closed","single-use-grant","intent-binding","least-privilege","shadow-mode","mcp","model-context-protocol","tool-calling","llm-agents","reference-architecture","typescript","decionis","presence"],"_resolved":"/home/runner/work/agent-safe-pipeline/agent-safe-pipeline/release/decionis-agent-safe-pipeline-0.3.5.tgz","_integrity":"sha512-eK1OR4M2TT0DrPfBg23azf/jpJIqJ62ihjgOUKMdnSaemOGX4HyYv9DrK4Xw5U1D/3kJB06/PkfzmH8prcvJtg==","repository":{"url":"git+https://github.com/decionis/agent-safe-pipeline.git","type":"git","directory":"packages/pipeline"},"_npmVersion":"11.16.0","description":"Execution Authority for AI agents: agents propose, Decionis independently decides ALLOW / ESCALATE / BLOCK, Presence verifies human approval on escalation, and a SafeExecutor runs only on a single-use intent-bound grant. Every decision leaves a Decision D","directories":{},"maintainers":[{"name":"decionis","email":"festus@binariesfort.com"}],"sideEffects":false,"_nodeVersion":"24.18.0","dependencies":{"zod":"^4.5.4","jose":"^6.2.10","@decionis/presence-node":"^0.2.0"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.11","fast-check":"4.9.0","@vitest/coverage-v8":"^4.1.10","@stryker-mutator/core":"10.0.0","@stryker-mutator/vitest-runner":"10.0.0"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/agent-safe-pipeline_0.3.5_1790110635976_0.6930779955685988"}}},"time":{"created":"2026-08-16T13:24:59.812Z","modified":"2026-09-22T20:57:16.440Z","0.1.2":"2026-08-16T13:25:00.170Z","0.1.3-rc.2":"2026-08-16T14:51:04.242Z","0.1.3":"2026-09-04T22:31:46.299Z","0.1.4":"2026-09-10T14:51:33.964Z","0.2.0":"2026-09-18T05:58:38.242Z","0.3.0":"2026-09-19T18:17:52.178Z","0.3.1":"2026-09-20T07:43:02.014Z","0.3.2":"2026-09-20T18:57:48.831Z","0.3.3":"2026-09-21T18:51:16.182Z","0.3.4":"2026-09-22T00:28:58.060Z","0.3.5":"2026-09-22T20:57:16.113Z"},"bugs":{"url":"https://github.com/decionis/agent-safe-pipeline/issues"},"author":{"name":"Decionis, Inc."},"license":"Apache-2.0","homepage":"https://github.com/decionis/agent-safe-pipeline/tree/master/packages/pipeline#readme","keywords":["execution-authority","ai-agents","agentic-ai","ai-agent-permissions","agent-guardrails","agent-security","ai-safety","ai-governance","authorization","policy-as-code","policy-enforcement","human-in-the-loop","human-approval","approval-workflow","decision-dossier","decision-evidence","audit-trail","fail-closed","single-use-grant","intent-binding","least-privilege","shadow-mode","mcp","model-context-protocol","tool-calling","llm-agents","reference-architecture","typescript","decionis","presence"],"repository":{"url":"git+https://github.com/decionis/agent-safe-pipeline.git","type":"git","directory":"packages/pipeline"},"description":"Execution Authority for AI agents: agents propose, Decionis independently decides ALLOW / ESCALATE / BLOCK, Presence verifies human approval on escalation, and a SafeExecutor runs only on a single-use intent-bound grant. Every decision leaves a Decision D","maintainers":[{"name":"decionis","email":"festus@binariesfort.com"}],"readme":"# `@decionis/agent-safe-pipeline`\n\n[![npm version](https://img.shields.io/npm/v/@decionis/agent-safe-pipeline.svg)](https://www.npmjs.com/package/@decionis/agent-safe-pipeline)\n[![Continuous integration](https://github.com/decionis/agent-safe-pipeline/actions/workflows/deploy.yml/badge.svg?branch=master)](https://github.com/decionis/agent-safe-pipeline/actions/workflows/deploy.yml)\n[![OpenSSF Scorecard](https://api.scorecard.dev/projects/github.com/decionis/agent-safe-pipeline/badge)](https://scorecard.dev/viewer/?uri=github.com/decionis/agent-safe-pipeline)\n[![OpenSSF Best Practices](https://www.bestpractices.dev/projects/14098/badge)](https://www.bestpractices.dev/projects/14098)\n[![License: Apache-2.0](https://img.shields.io/badge/license-Apache--2.0-blue.svg)](https://github.com/decionis/agent-safe-pipeline/blob/master/LICENSE)\n\n**Let agents propose. Let policy decide.**\n\n`@decionis/agent-safe-pipeline` is the TypeScript reference implementation of the Execution\nAuthority architecture. An AI agent may reason, plan, and propose a consequential action. It cannot\nauthorize that action, hold the credentials that perform it, or choose which trusted code runs. The\nexact proposal is captured as an immutable, short-lived intent, evaluated independently by Decionis,\nescalated to a verified human when policy requires it, and executed only through a single-use grant\nbound to that one intent. Every decision leaves a Decision Dossier, so the record of what was\nauthorized, under which policy, and on whose approval compounds over time.\n\n```text\nAgent -> immutable intent -> Decionis -> ALLOW / ESCALATE / BLOCK -> SafeExecutor -> downstream API\n                                      |\n                                      +-> Presence -> verified human approval -> Decionis re-evaluation\n                                      |\n                                      +-> Decision Dossier -> compounding decision record\n```\n\nThe package is a library, not a hosted service. It supplies the boundary; Decionis supplies the\ndecision. Its safety claims hold only when the documented trust boundary is preserved: the agent\nruntime never sees Decionis credentials, downstream credentials, or the handler registry.\n\n## Why an execution boundary\n\nModel-level controls shape what an agent says. They cannot prove, after the fact, that a specific\nside effect was authorized by a specific policy at the moment it happened. Prompt filtering,\nfine-tuning, and evaluation all sit before the action; the gap is at execution. This package closes\nit structurally:\n\n- **The agent's input is only the proposal.** Action, target, and parameters. Tenant, actor,\n  downstream system, and credentials come from trusted server configuration and cannot be injected.\n- **The decision is made elsewhere.** Decionis evaluates the canonical intent hash and returns\n  `ALLOW`, `ESCALATE`, or `BLOCK` with a decision identifier and a Decision Dossier identifier.\n- **Approval is evidence, never authority.** Presence proves that a real person approved that exact\n  intent. Decionis verifies the receipt and re-evaluates current policy before any grant exists.\n- **Execution consumes a grant, not a callback.** `SafeExecutor` accepts a captured intent and a\n  decision. It claims the grant atomically, then invokes a handler from a sealed registry.\n- **Everything else fails closed.** A network error, a malformed response, a missing grant, an\n  expired intent, a replayed token, or a binding mismatch all result in no execution.\n\n## Requirements\n\n- Node.js 22.14 or later. The package is ESM-only and ships its own TypeScript declarations.\n- A server-side process that holds the Decionis credentials. Never load this package into a\n  browser, an agent sandbox, or any runtime the model can influence.\n- `zod` v4 for handler parameter schemas (installed as a dependency).\n\n## Install\n\n```bash\nnpm install @decionis/agent-safe-pipeline\n```\n\nStable releases publish under the `latest` tag with npm provenance. Prereleases publish under the\n`next` tag and are never installed by default:\n\n```bash\nnpm install @decionis/agent-safe-pipeline@next\n```\n\nDecionis credentials belong only in the trusted executor process:\n\n```text\nDECIONIS_API_URL=https://api.decionis.com\nDECIONIS_API_KEY=server-side-secret\n```\n\n`DecionisGate` and `DecionisGrantVerifier` accept `apiKey` as a string or as a function read at\neach request. A deployment whose credential rotates inside a process's life gives the function: the\nnext request carries the new value, a request already in flight keeps the one it sent, and nothing\nhas to be rebuilt to make that true. A credential that does not rotate stays a string.\n\n```ts\nconst gate = new DecionisGate({\n  baseUrl: process.env.DECIONIS_API_URL!,\n  apiKey: () => secrets.current(\"DECIONIS_API_KEY\"),\n});\n```\n\n## Quick start: enforcement\n\nThe complete production path in one file. The proposal comes from the agent; everything else comes\nfrom trusted configuration.\n\n```ts\nimport {\n  ActionRegistry,\n  DecionisGate,\n  DecionisGrantVerifier,\n  IntentCapture,\n  SafeExecutor,\n} from \"@decionis/agent-safe-pipeline\";\nimport { z } from \"zod\";\n\n// 1. Capture the exact proposal. The agent supplies only action, target, and parameters.\nconst captured = new IntentCapture().capture(\n  {\n    action: \"refund_order\",\n    target: \"shopify:order:1001\",\n    parameters: { orderId: \"1001\", amountMinor: 35_000 },\n  },\n  {\n    tenantId: config.tenantId,\n    actor: { id: \"refund-agent\", type: \"AI_AGENT\" },\n    downstreamTarget: { system: \"shopify\", operation: \"refund\", environment: \"production\" },\n    idempotencyKey: \"refund-1001-v1\",\n  },\n);\n\n// 2. Ask Decionis. The gate never returns an executable decision without a grant.\nconst gate = new DecionisGate({\n  baseUrl: process.env.DECIONIS_API_URL!,\n  apiKey: process.env.DECIONIS_API_KEY!,\n});\nconst decision = await gate.evaluate(captured);\n\n// 3. Register trusted handlers once, then seal the registry so nothing can be added at runtime.\nconst registry = new ActionRegistry()\n  .register(\"refund_order\", {\n    parametersSchema: z.object({ orderId: z.string(), amountMinor: z.number().int() }).strict(),\n    execute: ({ parameters }) => shopify.refund(parameters),\n  })\n  .seal();\n\n// 4. Execute only through a claimed single-use grant bound to this intent.\nconst executor = new SafeExecutor(\n  registry,\n  new DecionisGrantVerifier({\n    baseUrl: process.env.DECIONIS_API_URL!,\n    apiKey: process.env.DECIONIS_API_KEY!,\n  }),\n);\nconst result = await executor.run(captured, decision);\n\nif (result.outcome === \"COMPLETED\") {\n  // result.result is the handler's return value.\n  // result.authorization carries the consumed { decisionId, dossierId, grantId, intentHash }.\n}\n```\n\nThe executor validates parameters against the handler's schema before the grant is claimed, and the\ngrant is claimed before the handler runs. If either step fails, the handler is never invoked.\n\nThe trusted context also accepts an optional `expectedEffectDigest` (`sha256:` plus 64 lowercase hex):\na digest-only commitment to the downstream state predicted before dispatch. It is bound into the\ncanonical intent hash and into the signed grant, and `DecionisGrantVerifier` refuses the authorization\nunless the returned grant echoes exactly that digest. The agent proposal can never carry it, and an\nintent that omits it hashes byte-identically to before the field existed. After the attempt, a trusted\nruntime that observed the effect may pass an `AuthorityEffectEvidence` record as `effectEvidence` to\n`DecionisGrantVerifier.finalize`, and read the authority's own `AuthorityEffectReport` back through\n`effectReport(authorization)`. See\n[execution intent](https://github.com/decionis/agent-safe-pipeline/blob/master/docs/execution-intent.md)\nand [execution outcomes](https://github.com/decionis/agent-safe-pipeline/blob/master/docs/execution-outcomes.md).\n\n## Outcomes\n\nDecionis returns one of three verdicts. The executor turns a verdict into exactly one execution\noutcome.\n\n| Verdict                               | Executor behavior                                                       |\n| ------------------------------------- | ----------------------------------------------------------------------- |\n| `ALLOW` with a valid single-use grant | Claim the grant atomically, then invoke the registered handler          |\n| `ESCALATE`                            | Stop. Resolve a DIRECT or MANAGED Presence escalation, then re-evaluate |\n| `BLOCK`, any error, any mismatch      | Fail closed. The handler is never invoked                               |\n\n`SafeExecutor.run` resolves to a discriminated result rather than throwing:\n\n| `outcome`                 | Meaning                                                                                                                                                                                   |\n| ------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |\n| `COMPLETED`               | The grant was consumed and the handler returned. `result` holds its value.                                                                                                                |\n| `BLOCKED`                 | Nothing ran. `reason` names the refusal: a non-authoritative or non-`ALLOW` decision, a missing or invalid grant, an intent binding or conformance failure, or an unavailable audit sink. |\n| `FAILED_BEFORE_DISPATCH`  | The grant was consumed but the handler failed before reaching the provider. Safe to reason about.                                                                                         |\n| `DEFINITELY_NOT_EXECUTED` | The provider was called and refused deterministically. `reason` is its own code. Nothing was effected and there is nothing to reconcile.                                                  |\n| `UNKNOWN_AFTER_DISPATCH`  | The provider was called and its outcome is unknown. A `recovery` reference supports reconciliation.                                                                                       |\n\nA handler reports that last-but-one case by throwing `ProviderRefusal` from inside `dispatch.run`,\nwith the provider's own reason code. Only a deterministic refusal belongs in it: a timeout, a 5xx\nor an unreadable answer is not a refusal, and reporting one as a refusal would turn \"nobody knows\"\ninto \"definitely not\".\n\nEvery outcome that consumed a grant also reports `finalization` (`RECORDED`, `PENDING`, or\n`UNSUPPORTED`). The executor records `COMMITTED`, `FAILED`, or `INDETERMINATE` with Decionis after\nthe attempt so commit evidence joins the Decision Dossier chain. Finalization is evidence, never\nauthority: it cannot change `outcome` or `executed`.\n\n### What each record establishes\n\nFluent summaries lose these distinctions first. Each row names the record or state, what it\nestablishes, and what it does not.\n\n| Record or state                                           | What it establishes                                                                                                                                                                                                                                                                                                                                                                                                                             | What it does not establish                                                                                                                                                                                                                                                                  |\n| --------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |\n| Captured intent (`IntentCapture`, `intentHash`)           | The exact action, target, and parameters the agent proposed, bound to trusted tenant, actor, and downstream context, hashed and expiring                                                                                                                                                                                                                                                                                                        | That the agent's facts, identities, or amounts are true; that anything may execute                                                                                                                                                                                                          |\n| Verified human approval (Presence `receiptDossierId`)     | A named person approved that exact intent hash under the assurance the receipt records                                                                                                                                                                                                                                                                                                                                                          | Permission to execute: Decionis re-evaluates policy with the receipt, and only that evaluation can issue a grant                                                                                                                                                                            |\n| Execution grant (`authorization` on an `ALLOW`)           | Permission for one attempt at one intent, claimed once through the `AuthorizationVerifier` immediately before the handler runs                                                                                                                                                                                                                                                                                                                  | Anything after expiry, for another intent hash, or on a second presentation; a dossier identifier, an invitation link, or an earlier `ALLOW` is not a substitute                                                                                                                            |\n| Decision Dossier (`decisionId`, `dossierId`)              | The record of why Decionis allowed, escalated, or blocked: policy snapshot, inputs, evidence, and grant metadata                                                                                                                                                                                                                                                                                                                                | An execution credential; proof that the underlying business judgement was right                                                                                                                                                                                                             |\n| Single claim, `COMPLETED`                                 | The grant was consumed once and the trusted handler returned a provider result                                                                                                                                                                                                                                                                                                                                                                  | An exactly-once downstream business effect or independent confirmation of settlement; whether an observation counts as `CONFIRMED` is the authority's judgement, not this package's                                                                                                         |\n| `UNKNOWN_AFTER_DISPATCH`, finalized `INDETERMINATE`       | Dispatch began and completion could not be proved                                                                                                                                                                                                                                                                                                                                                                                               | Permission to repeat the side effect: reconcile through provider idempotency and read-only lookup, never by a second dispatch                                                                                                                                                               |\n| `DEFINITELY_NOT_EXECUTED`, finalized `FAILED`             | Dispatch began, the provider refused it deterministically, and nothing was effected                                                                                                                                                                                                                                                                                                                                                             | Permission to try again: the refusal was about this attempt, and another needs a fresh decision and a fresh grant                                                                                                                                                                           |\n| Shadow observation (`ShadowPipeline`, `mode: \"SHADOW\"`)   | What Decionis would have decided about an action that already ran: a verdict and a dossier, no grant                                                                                                                                                                                                                                                                                                                                            | Enforcement, a grant, or a no-write test environment; the production write happened as before                                                                                                                                                                                               |\n| Library boundary (this package)                           | Intent capture, the gate, verification, and claim-before-handler dispatch inside the trusted integration                                                                                                                                                                                                                                                                                                                                        | Host isolation, IAM, network egress, credential storage, or incident response; see the [threat model](https://github.com/decionis/agent-safe-pipeline/blob/master/THREAT-MODEL.md) and [trust boundary](https://github.com/decionis/agent-safe-pipeline/blob/master/docs/trust-boundary.md) |\n| Trusted executor (`createTrustedExecutor`)                | What one process verifies about itself and enforces at its own door: the host posture `HostPosture` can observe, caller principals with roles and their own credentials, egress sealed to the origins `EgressPolicy` was configured with, a durable attempt journal reconciled by `StartupReconciler`, the ceilings in `HardLimits`, BEAP-vocabulary effect evidence, `HaltSwitch`, and hash-chained evidence with an offline-verifiable export | Node or kernel isolation, a CNI actually enforcing the NetworkPolicies the kit declares, an HSM or KMS, the authority's policy, or a bank's core correctness                                                                                                                                |\n| Executor evidence bundle (`agent-safe.evidence-bundle/1`) | What one executor process can say about an incident: both hash-chained streams as it still held them, the open attempts, the posture by check, the chain heads, a configuration digest, and every file's own digest                                                                                                                                                                                                                             | Origin, unless a signature over the manifest verifies against a key the reader brought; completeness, since it carries a bounded window and says how many lines it dropped; and it holds no parameter, no provider body, no secret and no digest of one                                     |\n\nThe sequence that produces both records, and two synthetic records side by side, are in\n[Decision Dossiers](https://github.com/decionis/agent-safe-pipeline/blob/master/docs/decision-dossiers.md).\n\n## Human approval through Presence\n\nWhen policy escalates, a person must approve that exact intent with independently signed evidence.\nPresence delivers the request to an enrolled device and returns a receipt bound to the intent hash.\nPresence never authorizes execution; Decionis verifies the receipt and re-evaluates policy. The\npackage supports two integration levels, and the executor's grant path is identical in both.\n\n| Mode      | Who coordinates Presence | Credentials in the executor | Entry point                                          |\n| --------- | ------------------------ | --------------------------- | ---------------------------------------------------- |\n| `DIRECT`  | Your trusted executor    | Decionis and Presence       | `PresenceApprovalCoordinator`                        |\n| `MANAGED` | Decionis                 | Decionis only               | `DecionisGate.evaluate` with an `escalation` request |\n\nIn MANAGED mode, pass routing and ceremony constraints outside the canonical intent, then poll\nDecionis only:\n\n```ts\nconst pending = await gate.evaluate(captured, undefined, {\n  escalation: {\n    mode: \"MANAGED\",\n    approver: { principal_id: approverId, role_id: \"APPROVER\" },\n    verification_requirements: { methods: [\"WEBAUTHN\"], level: \"HIGH_CONFIDENCE\" },\n  },\n});\n// pending.verdict === \"ESCALATE\"; pending.managedEscalation is set; no grant exists yet.\n\nconst authorized = await gate.waitForAuthorization(captured, pending, { signal });\nconst result = await executor.run(captured, authorized);\n```\n\n`waitForAuthorization` polls with capped exponential backoff and bounded jitter, and stops at the\nintent or escalation expiry. It returns a normal `ALLOW` decision with a grant only after Decionis\nhas verified the Presence evidence and re-evaluated current policy. Approval cannot revive an intent\nafter it expires. Presence transport or schema failures and Decionis re-authorization failures\nreturn stable fail-closed decisions; raw downstream error text never reaches the caller.\n\n## Shadow mode\n\nMeasure before you enforce. `ShadowPipeline` wraps an execution path you already run and records\nwhat Decionis would have decided, without the ability to stop, delay, or alter it.\n\n```ts\nimport { DecionisGate, ShadowPipeline } from \"@decionis/agent-safe-pipeline\";\n\nconst shadow = new ShadowPipeline(new DecionisGate({ baseUrl, apiKey, mode: \"SHADOW\" }), {\n  timeoutMs: 2_000,\n});\n\nconst run = await shadow.observe(captured, () => existingRefund(order));\n// run.production is your unchanged result, available as soon as production settles.\nconst observation = await run.observation;\n// The observation runs under its own timeout and never rejects; it reports the verdict\n// Decionis would have returned, the dossier identifier, and whether a grant was discarded.\n```\n\nA shadow observation carries no grant, is structurally distinct from a `GateDecision`, and is\nrejected by `SafeExecutor` at runtime. See\n[shadow mode](https://github.com/decionis/agent-safe-pipeline/blob/master/docs/shadow-mode.md).\n\n## Adoption path\n\nThe same `IntentCapture`, `ActionRegistry`, and handler code carry through every stage. Nothing is\nrewritten between them.\n\n| Stage       | Authority                                                     | What it proves                                                                   |\n| ----------- | ------------------------------------------------------------- | -------------------------------------------------------------------------------- |\n| Development | `createFixtureAuthorityPair` (refuses `NODE_ENV=production`)  | The intent, registry, and executor wiring is correct                             |\n| Shadow      | `ShadowPipeline` over `DecionisGate` with `mode: \"SHADOW\"`    | What Decionis would have decided about actions that already run; no grant issued |\n| Enforcement | `DecionisGate` plus `DecionisGrantVerifier` in `SafeExecutor` | Nothing runs without an independent decision and a consumed single-use grant     |\n\n### Selecting the gate from the environment\n\n`createGate` moves an integration between those stages with configuration alone. It takes the\nauthority and verifier you already run, and reads one variable to decide whether Decionis runs\nbeside them:\n\n```ts\nimport { createFixtureAuthorityPair, createGate } from \"@decionis/agent-safe-pipeline\";\n\nconst gate = createGate({\n  local: createFixtureAuthorityPair(() => \"BLOCK\", { unsafeAllowDevelopmentFixture: true }),\n  tenantId: \"00000000-0000-4000-8000-000000000001\",\n});\nconst captured = new IntentCapture().capture(proposal, { tenantId: gate.tenantId, ...trusted });\nconst decision = await gate.authority.evaluate(captured);\nconst result = await new SafeExecutor(registry, gate.verifier).run(captured, decision);\n```\n\n| Variable                           | Default                    | Effect                                                                                                                                                                                                           |\n| ---------------------------------- | -------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |\n| `DECIONIS_API_KEY`                 | unset                      | Unset: `gate.authority` and `gate.verifier` are the `local` objects themselves, and no client is constructed. Set: `DecionisGate` runs beside `local` through `ShadowGate`.                                      |\n| `DECIONIS_TENANT_ID`               | required with the key      | The key's organization. Decionis binds every intent to it, so `gate.tenantId` returns it for the capture; without the key, `gate.tenantId` is the `tenantId` you passed.                                         |\n| `DECIONIS_MODE`                    | `SHADOW`                   | `SHADOW`: the local decision governs execution and the hosted one is recorded on `decision.hosted`. `ENFORCEMENT`: the hosted decision governs, claimed through `DecionisGrantVerifier`; local can only tighten. |\n| `DECIONIS_API_URL`                 | `https://api.decionis.com` | HTTPS only, unless `DECIONIS_ALLOW_INSECURE_LOOPBACK=true` names a loopback double.                                                                                                                              |\n| `DECIONIS_TIMEOUT_MS`              | `DecionisGate`'s default   | Budget for the hosted call. A call past it is recorded as fail-closed.                                                                                                                                           |\n| `DECIONIS_ALLOW_INSECURE_LOOPBACK` | unset                      | `true` permits `http://127.0.0.1` for `LocalAuthority`.                                                                                                                                                          |\n\n`ShadowGate` never returns a decision less restrictive than the local authority's, in either mode. A\nhosted timeout, network error, non-2xx response, malformed body, or binding mismatch is recorded on\n`decision.hosted` as `failClosed` with verdict `BLOCK`: in `SHADOW` that changes nothing about\nexecution, in `ENFORCEMENT` it blocks. A hosted variable that cannot be honoured (`DECIONIS_MODE`\noutside `SHADOW` and `ENFORCEMENT`, a missing `DECIONIS_TENANT_ID`, a non-HTTPS URL) throws at\nconstruction rather than falling back to local, so a misconfiguration is never mistaken for hosted\nmode.\n\n`DecionisGate` sends `User-Agent: agent-safe-pipeline/<version>` on every call, and `source`\n(`{ repo, example }`, on `createGate` or the gate itself) is appended to it as a comment. It is\nclient identification for the authority's own accounting, never decision input, and it is sent only\nwhen a call is made at all.\n\n`printDecision(decision, { out })` writes what Decionis said, when it was asked, and nothing when\nit was not: the governing verdict, the hosted verdict with its standing (`governs`, `recorded\nbeside the local verdict`, or `failed closed`), the dossier identifier, the page that verifies it\nwhen the authority attached one (`decision.hosted.verificationUrl`), and the command that verifies\nit offline. Pass `out: process.stderr` where stdout is a transport, as in a stdio MCP server, and\n`verifyCommand` to name your own verification step; the default names this repository's\n`pnpm decionis:verify <dossier-id>`, which fetches the signed record with your key and checks its\nEd25519 proof bundle against the authority's public JWKS offline.\n\n### One variable, a key issued in the run\n\n`createHostedGate` is `createGate` with one more way onto Decionis, for the moment a developer has\nnothing but a clone:\n\n```ts\nimport { createHostedGate, printHostedOutcome } from \"@decionis/agent-safe-pipeline\";\n\nconst gate = await createHostedGate({\n  local: createFixtureAuthorityPair(() => \"BLOCK\", { unsafeAllowDevelopmentFixture: true }),\n  tenantId: \"00000000-0000-4000-8000-000000000001\",\n  source: { repo: \"owner/name\", example: \"basic-agent\", surface: \"github\" },\n});\nconst decision = await gate.authority.evaluate(captured);\nawait printHostedOutcome(gate, decision);\n```\n\n| `DECIONIS_HOSTED` | `DECIONIS_API_KEY` | What runs                                                                                                                                                                                                                                  |\n| ----------------- | ------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |\n| unset             | unset              | The local pair, untouched; `printHostedOutcome` writes one hint line.                                                                                                                                                                      |\n| any               | set                | Exactly `createGate`: the key and `DECIONIS_TENANT_ID` from the environment, in `DECIONIS_MODE`.                                                                                                                                           |\n| `1`               | unset              | The credential this user keeps for this authority (`agentsafe login`, or an earlier run), else a free provisional workspace minted now from `POST /v1/public/agents/provision`, stored for the next run, and named on standard error once. |\n\nA provisional workspace needs no account, no email and no card; its key evaluates in `SHADOW`\nonly, so the local verdict still governs and the hosted decision and its signed Decision Dossier\nare recorded beside it. The credential lives in `$AGENTSAFE_HOME`, else\n`$XDG_CONFIG_HOME/agentsafe`, else `~/.config/agentsafe/credentials.json`, readable by its owner\nalone, the same file `agentsafe login` writes; `NODE_ENV=production` refuses the whole path, as\nit refuses every stored login. `resolveHostedCredentials` is the same resolution for a process\nthat is not a gate, such as the trusted executor. The provisioning call carries the client\nidentification (`repo`, `example`, `surface`) in its `User-Agent`, and nothing else about the\nmachine.\n\n`printHostedOutcome(gate, decision, { out })` is how an example ends: `printDecision`, then the\nsigned record itself, fetched with the run's own key from `GET /v1/protocol/dossiers/{id}`\n(`gate.fetchDossier`) and shown by its proof: the algorithm, the key, when it was issued, how many\nartifacts it covers, and the issuer tier, `provisional_anonymous` for a workspace without an\naccount. `fetchSignedDossier`, `summarizeDossier` and `printSignedDossier` are the parts.\n\n## Local testing\n\n`@decionis/agent-safe-pipeline/testing` ships `LocalPresence` and `LocalAuthority`: loopback doubles\nthat the production clients talk to unchanged. They enforce the structural intent-hash binding,\nverify receipts the way Decionis does, issue single-use grants, orchestrate managed escalations, and\nrecord finalization. The person's ceremony becomes a method call.\n\n```ts\nimport { DecionisGate, DecionisGrantVerifier } from \"@decionis/agent-safe-pipeline\";\nimport {\n  LocalAuthority,\n  LocalPresence,\n  LOCAL_AUTHORITY_API_KEY,\n} from \"@decionis/agent-safe-pipeline/testing\";\n\nconst presence = new LocalPresence({ autoComplete: \"MANUAL\", roles: { \"synthetic-cro\": \"CRO\" } });\nconst authority = new LocalAuthority({ presence });\nawait presence.start();\nawait authority.start();\n\nconst gate = new DecionisGate({\n  baseUrl: authority.baseUrl,\n  apiKey: LOCAL_AUTHORITY_API_KEY,\n  allowInsecureLoopback: true,\n});\n// ... evaluate, then complete the ceremony with presence.approve(requestId)\n// and assert on grants, receipts, and recorded commits.\n```\n\nBoth doubles bind to `127.0.0.1` on an ephemeral port and refuse to construct under\n`NODE_ENV=production`. The testing entry also exports the development fixture primitives\n(`createFixtureAuthorityPair`, `FixtureDecisionAuthority`, `FixtureAuthorizationVerifier`,\n`InMemoryReplayStore`). Those remain available at the package root until 1.0; new code should import\nthem from the testing entry. See\n[local testing](https://github.com/decionis/agent-safe-pipeline/blob/master/docs/local-testing.md).\n\n## API overview\n\n| Concern        | Exports                                                                                           | Role                                                                                           |\n| -------------- | ------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------- |\n| Intent         | `IntentCapture`, `CanonicalIntentHasher`, `ExecutionIntentSchema`, `AgentProposalSchema`          | Build the immutable `agent-safe.intent/1` binding and its canonical SHA-256 hash               |\n| Decision       | `DecionisGate`, `DecisionAuthority`, `GateDecision`, `FailClosedDecision`                         | Obtain an independent `ALLOW` / `ESCALATE` / `BLOCK` decision with dossier identifiers         |\n| Selection      | `createGate`, `ShadowGate`, `SelectedGate`, `HostedEvaluation`, `printDecision`                   | Choose local, shadow, or enforcement from the environment; combine and report the two verdicts |\n| Human approval | `PresenceApprovalCoordinator`, `ManagedEscalationRequest`, `HumanApprovalEvidence`                | Coordinate DIRECT Presence ceremonies or request MANAGED orchestration by Decionis             |\n| Execution      | `SafeExecutor`, `ActionRegistry`, `DecionisGrantVerifier`, `AuthorizationVerifier`, `ReplayStore` | Claim the single-use grant, validate parameters, invoke a sealed handler, finalize the attempt |\n| Effect         | `AuthorityEffectEvidence`, `AuthorityEffectReport`, `DecionisGrantVerifier.effectReport`          | Forward a trusted runtime's downstream observation on finalize and read the authority's answer |\n| Observation    | `ShadowPipeline`, `ShadowObservation`                                                             | Record what the authority would have decided without granting execution                        |\n| Audit          | `AuditRecorder`, `AuditEventV1`, `AuditSink`                                                      | Emit immutable, redacted lifecycle records through one bounded sink call                       |\n| Testing        | `LocalPresence`, `LocalAuthority`, `createFixtureAuthorityPair` (from `/testing`)                 | Loopback doubles and fixture authorities for development and CI                                |\n\nThe seam between this package and Decionis is two interfaces, `DecisionAuthority` and\n`AuthorizationVerifier`, plus a published OpenAPI contract. Anyone can implement the interfaces; the\nlibrary checks no plan, key, or entitlement.\n\n## Production invariants\n\n1. Agent input contains only the proposed action, target, and parameters. Tenant, actor, downstream\n   target, and credentials come from trusted runtime configuration.\n2. The exact canonical intent is hashed and expires quickly.\n3. Decionis decides independently. Network errors, malformed responses, missing grants, and binding\n   mismatches fail closed.\n4. Presence proves a human approved that exact intent. It never authorizes execution; Decionis\n   verifies the receipt and re-evaluates policy.\n5. The grant is bound to the intent, decision, audience, and expiry, and is claimed atomically before\n   the handler runs. The attempt is finalized afterwards as evidence, never as authority.\n6. Downstream credentials exist only behind the trusted executor.\n7. Every decision is evidence-bearing. An `ALLOW` without a dossier identifier or grant is refused\n   as non-executable. A dossier identifier is never an execution credential.\n\nRead the [trust boundary](https://github.com/decionis/agent-safe-pipeline/blob/master/docs/trust-boundary.md)\nand the [threat model](https://github.com/decionis/agent-safe-pipeline/blob/master/THREAT-MODEL.md)\nbefore integrating a real downstream API.\n\n## Assurance and supply chain\n\nThe reviewer's route through all of it, with what each piece of evidence establishes and what it\ndoes not, is\n[EVALUATION-PATH.md](https://github.com/decionis/agent-safe-pipeline/blob/master/EVALUATION-PATH.md).\n\n- **Provenance.** Every release is published through npm trusted publishing with a provenance\n  attestation, from a keyless-signed release tag, and archived under Zenodo concept DOI\n  [`10.5281/zenodo.22312955`](https://doi.org/10.5281/zenodo.22312955).\n- **Release evidence.** Each GitHub release carries the tarball, a CycloneDX SBOM, Sigstore\n  provenance and SBOM attestations, and a checksum file. See\n  [reproducible builds](https://github.com/decionis/agent-safe-pipeline/blob/master/docs/reproducible-builds.md).\n- **Testing.** Coverage gates of 90% lines, functions, and statements and 85% branches; mutation\n  testing on the trust boundary; deterministic property-based fuzzing of canonical intent handling;\n  a loopback wire-contract harness that exercises the packed package over real HTTP.\n- **Adversarial proof.** The\n  [golden adversarial demo](https://github.com/decionis/agent-safe-pipeline/tree/master/examples/golden-adversarial-demo)\n  runs one legitimate path and eight attacks against the same boundary, offline, and exits 0 only\n  when exactly one action executes.\n- **Scanning.** CodeQL, secret scanning, OpenSSF Scorecard, and OpenSSF Best Practices, with\n  separate production and toolchain dependency audits. The control-to-artifact map is in\n  [SECURITY-EVIDENCE.md](https://github.com/decionis/agent-safe-pipeline/blob/master/SECURITY-EVIDENCE.md).\n\n## Examples\n\nRunnable, offline, and fixture-backed unless noted. Each one uses this package unchanged.\n\n- [`basic-agent`](https://github.com/decionis/agent-safe-pipeline/tree/master/examples/basic-agent): the smallest `BLOCK` flow.\n- [`shopify-refund-agent`](https://github.com/decionis/agent-safe-pipeline/tree/master/examples/shopify-refund-agent): amount-based `ALLOW` / `ESCALATE` / `BLOCK`.\n- [`github-deploy-agent`](https://github.com/decionis/agent-safe-pipeline/tree/master/examples/github-deploy-agent): environment and force-push controls.\n- [`procurement-agent`](https://github.com/decionis/agent-safe-pipeline/tree/master/examples/procurement-agent): an in-budget request held by policy.\n- [`mcp-tool-gate`](https://github.com/decionis/agent-safe-pipeline/tree/master/examples/mcp-tool-gate): a real stdio MCP server with a governed tool.\n- [`local-escalation`](https://github.com/decionis/agent-safe-pipeline/tree/master/examples/local-escalation): DIRECT and MANAGED Presence escalation against loopback doubles.\n- [`presence-live-approval`](https://github.com/decionis/agent-safe-pipeline/tree/master/examples/presence-live-approval): DIRECT Presence enforcement against the real services with a FIDO2 or FIDO2-plus-liveness ceremony (needs credentials).\n- [`presence-managed-approval`](https://github.com/decionis/agent-safe-pipeline/tree/master/examples/presence-managed-approval): Decionis-managed Presence orchestration against the real services (needs credentials).\n- [`golden-adversarial-demo`](https://github.com/decionis/agent-safe-pipeline/tree/master/examples/golden-adversarial-demo): one golden path, eight attacks, zero unauthorized executions.\n- [`whisper-boundary-demo`](https://github.com/decionis/agent-safe-pipeline/tree/master/examples/whisper-boundary-demo): the same proof for a shopping agent — six attacks, zero unauthorized effects.\n- [`crm-outreach-demo`](https://github.com/decionis/agent-safe-pipeline/tree/master/examples/crm-outreach-demo): who can approve a sales agent's CRM update or outbound message — six attacks, a lost provider response reconciled once, zero unauthorized effects.\n- [`infra-scale-demo`](https://github.com/decionis/agent-safe-pipeline/tree/master/examples/infra-scale-demo): the Compromised Principal Test — an infrastructure agent whose identity, credential and API are all valid proposes a `deployment.scale` nobody authorised; seven attacks, a post-authorization mutation failing the binding, zero unauthorized effects.\n- [`trusted-executor`](https://github.com/decionis/agent-safe-pipeline/tree/master/examples/trusted-executor): the proof of `@decionis/agentsafe`, the execution boundary as one deployable process — an HTTP trusted executor in front of these components — over real HTTP against the loopback doubles, and the adopter's template; the image, Kubernetes manifest and shadow-to-enforcement runbook are in the repository's [deployment kit](https://github.com/decionis/agent-safe-pipeline/blob/master/deploy/README.md).\n\n## Open core\n\nThis package and the repository's architecture, intent contract, execution boundary, client\nadapters, audit contract, shadow mode, conformance vectors, and examples are Apache-2.0. The sole\nlicense exception is the dedicated MIT-licensed Claude Desktop wrapper in\n`packages/commerce-mcp-claude-extension`; the CommerceGate runtime it bundles remains Apache-2.0.\nDecionis operates the policy control plane behind `DecionisGate`: policy evaluation, grant issuance\nand atomic consumption, Decision Dossier signing and retention, and Presence.\n[OPEN-CORE.md](https://github.com/decionis/agent-safe-pipeline/blob/master/OPEN-CORE.md) states the\nboundary and the commitments that keep it stable.\n\n## Research\n\nDecionis Research defines the architecture, this package demonstrates it as tested code, and the\nDecionis platform operates it as a hosted authority.\n\nThe banking profile of the protocol, whose reference runtime builds on this package, is published at\n[banking.decionis.com](https://banking.decionis.com) (BEAP v1.0, published 2026-09-15; the profile\nDecionis publishes and implements, not a standard approved by any body). The Commerce Gate this repository's MCP server fronts is at\n[commerce.decionis.com](https://commerce.decionis.com).\nThe proof-of-human infrastructure this package's `PresenceApprovalCoordinator` coordinates with is\ndescribed at [decionis.com/proof-of-human-infrastructure](https://decionis.com/proof-of-human-infrastructure)\nand runs at [presence.decionis.com](https://presence.decionis.com); production enforcement there is\nsales-assisted.\n\n- Jejelowo, Festus. \"The Execution Verifiability Gap: Why Model Governance Cannot Authorize\n  Consequential Actions.\" Decionis Research, version 1.0, 21 August 2026.\n  [Canonical article](https://decionis.com/research/execution-verifiability-gap) ·\n  [Archival PDF](https://decionis.com/research/execution-verifiability-gap-v1.0.pdf)\n\nTo cite the software, use the\n[CITATION.cff](https://github.com/decionis/agent-safe-pipeline/blob/master/CITATION.cff) in the\nrepository or the Zenodo record above.\n\n## Support and license\n\n- Vulnerabilities: [GitHub private vulnerability reporting](https://github.com/decionis/agent-safe-pipeline/security/advisories/new) or `security@decionis.com`. Never open a public issue for a security report.\n- Everything else: [GitHub Issues](https://github.com/decionis/agent-safe-pipeline/issues).\n- Architecture and full documentation: [Agent-Safe Pipeline README](https://github.com/decionis/agent-safe-pipeline#readme).\n\nApache-2.0. Trademark terms in\n[TRADEMARKS.md](https://github.com/decionis/agent-safe-pipeline/blob/master/TRADEMARKS.md).\n","readmeFilename":"README.md"}