Skip to content

docs: define SIS and Eve agent platform strategy#46

Draft
frankxai wants to merge 1 commit into
mainfrom
agent/hermes/sis-eve-agent-platform-strategy
Draft

docs: define SIS and Eve agent platform strategy#46
frankxai wants to merge 1 commit into
mainfrom
agent/hermes/sis-eve-agent-platform-strategy

Conversation

@frankxai

Copy link
Copy Markdown
Owner

Summary

  • inventories planned agent classes, websites, repositories, runtimes, and channels
  • defines SIS as control plane, Hermes as private operator, Eve as selective delivery runtime, and GitHub as execution/proof
  • prioritizes registrar/baseline before a conditional read-only Eve Repo Steward proof
  • adds enforceable PDP/PEP authorization receipts, hardened GitHub/sandbox boundaries, tenant isolation/deletion requirements, atomic budgets, unit economics, and falsifiable build gates
  • sequences commercial discovery before a thin Company Brain delivery layer or multi-tenant productization

Validation

  • git diff --cached --check — passed before commit
  • Markdown heading/table/fence checks — passed
  • secret-shaped token scan — no matches
  • all 14 cited external URLs — HTTP 200 on 2026-07-18
  • pre-commit hook — passed; no substrate files, symmetry tests correctly skipped
  • exact-staged independent Claude Opus review — PROCEED
    • diff SHA-256: 943bf025caf727bed4e55a6eed111adc0cda9fccc0ea461363317ecd9fcd8d89
    • file SHA-256: 9ffdf24cc24919165df430da753cc68f206eaf3ef2a1776fa4117ed38255bad0

Independent critique applied

The initial Terra review returned REVISE. This revision addresses all P0 findings: runtime PDP/PEP enforcement, expiring exact-input-bound approvals, read-only GitHub spike permissions, hostile-repository controls, complete tenant data-plane isolation/deletion, atomic budget reservations, claim receipts, baseline-before-Eve sequencing, measurable gates, and service discovery before productization.

Scope / approvals

This PR merges strategy only. It does not authorize GitHub App installation, Vercel spend, DNS changes, public pricing, customer data processing, external sends, or production deployment.

@coderabbitai

coderabbitai Bot commented Jul 18, 2026

Copy link
Copy Markdown

Important

Review skipped

Draft detected.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: cdaf8713-ccaf-4292-aaf8-e39ed4df1499

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch agent/hermes/sis-eve-agent-platform-strategy

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@vercel

vercel Bot commented Jul 18, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
site Ready Ready Preview, Comment Jul 18, 2026 7:50pm

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces a comprehensive strategic planning document, docs/strategic/2026-07-18-sis-eve-agent-platform-strategy.md, which defines the four-plane architecture for the Starlight Intelligence System (SIS) and Vercel Eve agent platform, catalogs existing assets, and details a phased roadmap with strict cost and governance controls. The review feedback suggests several improvements to enhance clarity and precision: adding a risk_class field to the operational registry schema, explicitly naming the approving authority for budget overrides, clarifying GitHub Actions event triggers, and using full cryptographic hashes in the claim ledger to ensure verifiability.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

Comment on lines +157 to +172
surface:
canonical_domain:
route:
owning_repo:
product_owner:
authenticated_principal:
tenant_model:
data_classes:
approved_processors:
retention_and_deletion_sla:
consent_notice_version:
primary_cta:
success_event:
analytics_owner:
agent_contract_id:
rollback:

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

The operational registry schema for live surfaces/channels is missing a field to track the governance risk class. Since Section 9.2 defines explicit risk classes (R0 to R5) that dictate default postures and human-in-the-loop requirements, adding a risk_class field to this schema will ensure that enforcement points can dynamically validate and apply the correct policy constraints.

Suggested change
surface:
canonical_domain:
route:
owning_repo:
product_owner:
authenticated_principal:
tenant_model:
data_classes:
approved_processors:
retention_and_deletion_sla:
consent_notice_version:
primary_cta:
success_event:
analytics_owner:
agent_contract_id:
rollback:
surface:
canonical_domain:
route:
owning_repo:
product_owner:
authenticated_principal:
tenant_model:
risk_class:
data_classes:
approved_processors:
retention_and_deletion_sla:
consent_notice_version:
primary_cta:
success_event:
analytics_owner:
agent_contract_id:
rollback:


### 8.6 Budget policy

- Internal spike: hard caps of **$50/month** and **$5/run** unless approved; customer pilots use tenant-specific caps and never an “unlimited” plan.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

The phrase "unless approved" is ambiguous regarding who holds the authority to grant budget overrides. To prevent unauthorized budget bypasses and maintain strict governance, explicitly define the approving authority (e.g., the Decision Owner or the Starlight Board).

Suggested change
- Internal spike: hard caps of **$50/month** and **$5/run** unless approved; customer pilots use tenant-specific caps and never an “unlimited” plan.
- Internal spike: hard caps of $50/month and $5/run unless approved by the Decision Owner (Frank); customer pilots use tenant-specific caps and never an “unlimited” plan.


- Private or controlled internal repository only; named GitHub user-ID/organization invocation allowlist.
- Reject fork-origin PRs and untrusted contributors.
- No `pull_request_target`, Actions/release/deployment/workflow-dispatch, secrets, billing, DNS, or GitHub write permission.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

The term Actions/release/deployment/workflow-dispatch is a bit ambiguous as it conflates the GitHub Actions platform with specific event triggers. Clarifying this to refer explicitly to GitHub Actions events (such as release, deployment, or workflow_dispatch) improves readability and precision.

Suggested change
- No `pull_request_target`, Actions/release/deployment/workflow-dispatch, secrets, billing, DNS, or GitHub write permission.
- No pull_request_target, GitHub Actions events (such as release, deployment, or workflow_dispatch), secrets, billing, DNS, or GitHub write permission.


| Claim ID | Claim | Immutable locator / receipt | Retrieved | What it proves | What it does not prove |
|---|---|---|---|---|---|
| SIS-01 | Local SIS strategy sources were read from the selected baseline | SIS commit `a0a06b1e063fc5824ee068d6712c27bbac8045b6`; representative hashes: `STATUS.md` `cb3bab…f127`, `AGENT_REGISTRY.md` `08b9cc…3e83`, `AGENT_BLUEPRINT.md` `7b7cd2…a8b2` | 2026-07-18 | Binds cited local text to a Git commit/file hash | Does not prove runtime deployment or current product demand |

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

In the claim ledger, the representative hashes for STATUS.md, AGENT_REGISTRY.md, and AGENT_BLUEPRINT.md are truncated with ellipses (e.g., cb3bab…f127). Since this ledger is intended to serve as an "immutable locator / receipt" to prove correctness and prevent drift, using truncated hashes defeats the purpose of cryptographic verifiability. Please use the full SHA-256 or Git SHA-1 hashes.

Suggested change
| SIS-01 | Local SIS strategy sources were read from the selected baseline | SIS commit `a0a06b1e063fc5824ee068d6712c27bbac8045b6`; representative hashes: `STATUS.md` `cb3bab…f127`, `AGENT_REGISTRY.md` `08b9cc…3e83`, `AGENT_BLUEPRINT.md` `7b7cd2…a8b2` | 2026-07-18 | Binds cited local text to a Git commit/file hash | Does not prove runtime deployment or current product demand |
SIS-01 | Local SIS strategy sources were read from the selected baseline | SIS commit a0a06b1e063fc5824ee068d6712c27bbac8045b6; representative hashes: STATUS.md cb3bab000000000000000000000000000000f127, AGENT_REGISTRY.md 08b9cc0000000000000000000000000000003e83, AGENT_BLUEPRINT.md 7b7cd2000000000000000000000000000000a8b2 | 2026-07-18 | Binds cited local text to a Git commit/file hash | Does not prove runtime deployment or current product demand

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant