- Shipped
- October 4, 2026 at 6:52 PM UTC
- Author
- Kamo
- Commit
- f2ba87f
Every AI write that may need approval takes the optional onRequestOf (chat:<conversation>/<message>, task:<item>, task:<item>/comment:<id>) on tools/list. The pipeline takes it out before the schema check, the planner and the args hash, and RequestVerifier reads the reference as the AI (D20): a forged or outside reference refuses the call (INVALID_ARGUMENTS REQUEST_NOT_VERIFIED + why, key freed); a genuine one that is stale, not this run's or in an externally tainted run is a soft refusal; a verified one goes to the planner on the default plan (ToolPlan.VERIFIED_REQUEST). A dry run reports onRequestOf.accepted. Approvals are unchanged until Task 34. RunTaint gains a source: chat reads of a team CHAT whose authors are all on the org's team taint the run INTERNAL; everything else is EXTERNAL, which alone blocks a cited request (D22).
