[{"data":1,"prerenderedAt":92},["ShallowReactive",2],{"search-en":3,"content-en-developer\u002Fdecisions\u002F051-ordered-autonomy-gates":4,"surround-en-\u002Fdeveloper\u002Fdecisions\u002F051-ordered-autonomy-gates":83},[],{"id":5,"title":6,"body":7,"description":75,"extension":76,"meta":77,"navigation":78,"path":79,"seo":80,"stem":81,"__hash__":82},"content_en\u002F3.developer\u002Fdecisions\u002F14.051-ordered-autonomy-gates.md","ADR-051: Ordered Restrict-Only Autonomy Gates",{"type":8,"value":9,"toc":68},"minimark",[10,27,32,36,40,52,55,59],[11,12,13,21],"ul",{},[14,15,16,20],"li",{},[17,18,19],"strong",{},"Status:"," Accepted",[14,22,23,26],{},[17,24,25],{},"Date:"," 2026-07-17",[28,29,31],"h2",{"id":30},"context","Context",[33,34,35],"p",{},"Auto-send already depended on an ordered set of safety checks. A plugin policy must be able to hold a reply without moving a core check, creating a new approval source, or changing an installation that has no plugin gates.",[28,37,39],{"id":38},"decision","Decision",[33,41,42,43,47,48,51],{},"All core final gates run first in their fixed order. Bundled plugin gates append afterward in generated catalog order. The public result is exactly ",[44,45,46],"code",{},"{ outcome: 'no-objection' }"," or ",[44,49,50],{},"{ outcome: 'objection', reason }","; there is no approval or send result.",[33,53,54],{},"The host reauthorizes immediately before each invocation and supplies only a copied, frozen mail projection plus an abort signal. Missing, disabled, revoked, stale, timed-out, failed, or malformed gates object and route the reply to human review. Plugin text is bounded and scrubbed and never enters audit metadata.",[28,56,58],{"id":57},"consequences","Consequences",[33,60,61,62,67],{},"Plugins can only narrow autonomy. Core order and dispatch-time reference monitoring remain host-owned, and an empty gate catalog preserves prior behavior. See ",[63,64,66],"a",{"href":65},"\u002Fdeveloper\u002Fplugin-capabilities","Capabilities & Trust",".",{"title":69,"searchDepth":70,"depth":70,"links":71},"",2,[72,73,74],{"id":30,"depth":70,"text":31},{"id":38,"depth":70,"text":39},{"id":57,"depth":70,"text":58},"Plugin gates append after immutable core controls and can only object to unattended sending.","md",{},true,"\u002Fdeveloper\u002Fdecisions\u002F051-ordered-autonomy-gates",{"title":6,"description":75},"3.developer\u002Fdecisions\u002F14.051-ordered-autonomy-gates","uIh2ipL_d4DLqUGRkLwmR7pKKPtJt6aYg0pa6MNqSKo",[84,88],{"title":85,"path":86,"stem":87,"children":-1},"ADR-050: Host-Owned Draft Strategy Registry","\u002Fdeveloper\u002Fdecisions\u002F050-draft-strategy-registry","3.developer\u002Fdecisions\u002F13.050-draft-strategy-registry",{"title":89,"path":90,"stem":91,"children":-1},"ADR-052: Connected Apps and Signed Hooks","\u002Fdeveloper\u002Fdecisions\u002F052-connected-apps-and-signed-hooks","3.developer\u002Fdecisions\u002F15.052-connected-apps-and-signed-hooks",1786915101565]