- README: orientation, doc map, target package layout (pointers only, no duplicated architecture content) - CLAUDE.md: agent operating manual — invariants as code-review rules, conventions, do-not list, task reading order - ROADMAP: M1-M5 with verifiable acceptance criteria, phase-2 fence - GLOSSARY: canonical Chinese-term → code-name mapping - docs/adr/: eight ADRs recording settled decisions and rejected alternatives - docs/open-questions.md: consolidated TODO(业务) tracker by owner and blocking milestone - .gitignore; untrack .DS_Store Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019u5SLNweVio6ozJX7yfxQr 🔮 View transcript: https://logs.lojong.info/s/e8u90k3t33w590r7b5y7yzqh
18 lines
821 B
Markdown
18 lines
821 B
Markdown
# ADR-0006: Envelope-based tiered autonomy
|
|
|
|
**Status**: accepted · 2026-09
|
|
|
|
**Context**: Per-action human approval contradicts the ≤3-min decision KPI and
|
|
daily bidding cadence; full autonomy contradicts the mandate that AI never
|
|
directly controls.
|
|
|
|
**Decision**: Humans approve *envelopes* (policy-level bounds with validity
|
|
windows, multi-level approval); in-envelope actions auto-pass after rule check +
|
|
simulation; out-of-envelope or simulation-flagged actions escalate to humans.
|
|
Envelopes start empty and widen only on L4 shadow/online evidence (docs/12 §3);
|
|
deviation streaks auto-suspend them. Precedent: AGC regulation-band delegation.
|
|
|
|
**Consequences**: Autonomy growth is itself auditable. Approval queue shrinks to
|
|
genuine anomalies — also the main countermeasure to approval complacency
|
|
(docs/13 §3).
|