Agents in the SDLC¶
must
AI may assist. AI may not authorize. Agents cannot approve knowledge, merge to protected branches, or waive gates.
| May | May not |
|---|---|
| Read approved claims via the kernel API with a purpose | Scrape this site as policy |
Propose patches, tests, threat-model drafts as candidate |
Set lifecycle=approved |
Use compiled SKILL.md that matches claim versions |
Use a stale skill after withdraw |
| Open a merge request | Self-merge |
Tool allowlists and classification ceilings belong on the agent identity, not in the model prompt alone.