forge
Clone forge-starter
Permissions authorizemay this Builder use this Capability?
Policies governis this run allowed here, now?
Your app's gateallow · needs-approval · deny

Policies & Permissions — two levels of gate

platform level · every capability call · src/core/runtime.tsrequestPermissionsthis Builder, this Capability?Policiesplatform ok? Docker present?executeaudit403 permission_denied403 policy_blockedapp level · your own actions · the C29 policy engineyour app“send this email?”POST /authorizepolicy engine{owner, role, action, high_risk}rules · deny wins · high-risk floorallowneeds-approvaldenyrecordsevent logauthz.decisiona Builder's rules are written with set-policy / POST /policies · the platform's gates are code, not configuration
Two gates at two levels. The platform decides whether a capability may run at all; your app asks the engine whether its action may proceed — and “needs-approval” is a first-class answer, not a failure.