Skip to content

Allow maintained local authority fallbacks when global guidance is inaccessible - #19

Merged
iteathen merged 2 commits into
mainfrom
docs/accessible-local-authority
Sep 15, 2026
Merged

iteathen merged 2 commits into
mainfrom
docs/accessible-local-authority

Conversation

@iteathen

Copy link
Copy Markdown
Owner

The unconditional thin-local/no-duplication rule prevented accessibility-constrained agents from keeping operative engineering guidance. Global AGENTS remains canonical when available; designated self-contained AGENT_LOCAL fallbacks are now permitted, with explicit provenance, synchronization, and protection from redundancy cleanup. README routing and the config comment use the same policy. No runtime configuration or unrelated doctrine changes.

Qualification: re-read the complete AGENTS and reviewed routing, hierarchy, context, cleanup, compatibility and local-file clauses. Ordinary thin locals remain valid; fallback duplication is optional, identified and deliberately maintained. node tools/verify-community.mjs passed (22 files); git diff --check passed.

Access assessment (2026-09-14):

  • Public repository; owner iteathen is the only listed collaborator, with admin access.
  • GitHub connector read AGENTS, created this branch from 86ed1f4, and committed AGENTS as c0b9199. Owner CLI independently read, cloned and pushed the companion changes.
  • Connector installation 146535278 selects all repositories. App chatgpt-codex-connector (1144995) declares contents write, pull_requests write and metadata read; observed operations establish effective read/branch-write access here. Other declared app capabilities were not added or changed.
  • CLI uses existing owner OAuth scopes repo/workflow/read:org/gist. Its user/installations request returns 403 because that endpoint requires GitHub App authentication; that is an inspection-token mismatch, not a repository read/write failure.
  • Historical agent read/write failures cannot be reproduced in this environment. No repository-side denial was found. There is no justified permission expansion or required owner change for this tested connection. Other environments' tokens/sandboxes remain unverified.
  • For an affected installation, the exact owner configuration surface is https://github.com/settings/installations/146535278 : ensure the intended installation includes .github and approved Contents write / Pull requests write (Metadata read is implicit). A separate fine-grained token should select only required repositories and those capabilities; no administration/workflow grant is needed for these documentation changes. Do not weaken main protection. See https://docs.github.com/en/apps/using-github-apps/reviewing-and-modifying-installed-github-apps .
  • No permissions, collaborator grants, rulesets, or protection configuration changed. Main retains enforced-admin strict Community quality, linear history, conversation resolution, no force push/deletion. PR review rules retain existing owner/App exceptions only through pull requests; required CI has no bypass. Workflow token remains read-only and cannot approve PR reviews.

Known fallback assessment: Connect4 research/frontier-negamax-conformance AGENT_LOCAL explicitly declares its fallback purpose and matches the accessible/inaccessible routing intent. Preserve it. It still needs an explicit source revision or synchronization-assessment marker under the new provenance rule; no Connect4 content changed in this global-only PR. Other consumers were not exhaustively inventoried. Existing optimization PR #18 remains untouched.

@iteathen
iteathen merged commit fe80701 into main Sep 15, 2026
4 checks passed
@iteathen
iteathen deleted the docs/accessible-local-authority branch September 15, 2026 06:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant