The approval digest binds project, plan, recipe and the current project object revisions. Change any of them and a new approval is required.
2XBR PROJECTS / GUARDRAILS / POLICIES ENGINEApprove the run,
Approve the run,
not the idea.
Guardrails bind a project recipe to bounded input limits and explicit approval rules. The existing POLICIES engine keeps one-use approvals tied to the exact current project state before execution.
Open project guardrails →PROJECTCURRENT STATE→GUARDRAILSRECIPE + LIMIT→APPROVE10 MIN / ONE USE→RUNEXPLICIT
LOCAL ONLY0 PLANS0 BINDINGS10 MIN APPROVALPROJECT GUARDRAILS / LOCAL POLICY STORE
01 / GUARDRAIL PLAN
Define the guardrail once.
A PLAN binds one saved FLOW recipe to input limits and an approval rule. It stores configuration only — never project files, filenames or run output.
ALWAYSEvery run needs a fresh, one-use approval.
02 / SAVED PLANS
Reusable project guardrails.
No saved plans yet. Save a FLOW recipe, then define a plan here.
03 / PROJECT BINDINGS
Apply one plan to a project.
Applying a plan also pins the plan's FLOW recipe to the project, so policy and execution cannot silently drift apart.
No PROJECTS yet. CREATE PROJECT →
A valid approval expires after ten minutes and is removed before FLOW starts. Failed runs do not silently reuse it.
Plans and approvals govern explicit RUN NOW actions. WATCH still requires its own visible, armed session.