SOAPSUPER OPERATIONS AI PROCEDURES
← Evidence library

Governance
Fresh local tests

A model can propose an action. Authority decides execution.

I separate what a model recommends from what its role is allowed to do, using tool policies and confirmations tied to the actual action.

TypeScriptPolicy contractsSigned confirmationsSQL aggregation

01 THE PROBLEM

What needed to change

An assistant that produces useful text should not automatically receive authority to change records or perform an external action.

02 THE IMPLEMENTATION

What I built and directed

I developed a control plane with role/tool policies, HMAC-bound confirmations, prompt and output filters, provider interfaces and template resolution. An analytics path fixes organisation scope before canonicalisation and cache-key generation, then calls a fixed aggregation interface rather than arbitrary generated SQL.

03 THE CHECK

What the evidence establishes

140 control-plane tests, 13 model-tier selection tests and 32 analytics-contract tests passed locally on 9 October 2026. Provider-registry and stream checks use mocked dependencies.

Scope of this example

Focused local policy and analytics tests with mocked provider dependencies.

04 THE LESSON

The judgement behind the code

The control must sit outside the prompt. Negative fixtures matter as much as the successful path.

Public references

I can walk through a sanitised example without sharing private source archives or client material.

The development roadmap →