[{"data":1,"prerenderedAt":290},["ShallowReactive",2],{"$foT8U9eLW7d1KHlKcia8IN-uMIL8rsVlYGB5HonhZ718":3},{"newThing":4,"project":5,"cycle":8,"sections":18,"threads":285,"otherDocs":286,"images":287,"archiveItems":288,"links":289},null,{"id":6,"label":7,"liveBase":4},"design","Design",{"id":9,"num":10,"dir":11,"name":12,"title":13,"focus":4,"status":14,"statusNote":4,"created":15,"completed":4,"mode":4,"recordless":16,"thumbnail":4,"imageCount":17,"artifactCount":17,"lastActivity":15,"hasPickup":16,"hasInitialPrompt":16},"c45",45,"c45.ai-agent-policy-pages","ai-agent-policy-pages","AI Agent Policy Pages","archived","2026-09-11",false,0,[19,33,52,157,241,251],{"key":20,"title":21,"empty":16,"ast":22},"why","Why",{"type":23,"children":24},"root",[25],{"type":26,"tag":27,"props":28,"children":29},"element","p",{},[30],{"type":31,"value":32},"text","The existing policy UI in bob-wire (c0, c1, c6, c10) was built around infrastructure-era security — data residency, vendor allowlists, PII compliance. The synthetic data powering those pages doesn't reflect the new reality: AI agents as autonomous actors with credential access, outbound network capability, and destructive command authority. The PocketOS incident (April 2026) crystallized six concrete intervention points into enforceable policies. The bob-wire policy pages need to tell that story with data that matches.",{"key":34,"title":35,"empty":16,"ast":36},"objective","Objective",{"type":23,"children":37},[38],{"type":26,"tag":27,"props":39,"children":40},{},[41,43,50],{"type":31,"value":42},"Replace the existing policy synthetic data in bob-wire's security\u002Fpolicy pages with AI agent security policies derived from the AI Policy Starter Pack (",{"type":26,"tag":44,"props":45,"children":47},"code",{"className":46},[],[48],{"type":31,"value":49},"brand\u002Fai_policy_starter_pack.md",{"type":31,"value":51},"). Update the wireframes and mockups to reflect the new policy model — new rule types, AI-specific violation scenarios, trust scoring, and the \"Lethal Trifecta\" enforcement progression.",{"key":53,"title":54,"empty":16,"ast":55},"scope","Scope",{"type":23,"children":56},[57,66,126,134],{"type":26,"tag":27,"props":58,"children":59},{},[60],{"type":26,"tag":61,"props":62,"children":63},"strong",{},[64],{"type":31,"value":65},"In scope:",{"type":26,"tag":67,"props":68,"children":69},"ul",{},[70,106,111,116,121],{"type":26,"tag":71,"props":72,"children":73},"li",{},[74,76,82,84,90,91,97,98,104],{"type":31,"value":75},"New synthetic data: 6 policies (POL-001 through POL-006) with AI-specific rule types (",{"type":26,"tag":44,"props":77,"children":79},{"className":78},[],[80],{"type":31,"value":81},"on_file_read",{"type":31,"value":83},", ",{"type":26,"tag":44,"props":85,"children":87},{"className":86},[],[88],{"type":31,"value":89},"on_net_connect",{"type":31,"value":83},{"type":26,"tag":44,"props":92,"children":94},{"className":93},[],[95],{"type":31,"value":96},"on_command_exec",{"type":31,"value":83},{"type":26,"tag":44,"props":99,"children":101},{"className":100},[],[102],{"type":31,"value":103},"on_agent_start",{"type":31,"value":105},", continuous trust scoring)",{"type":26,"tag":71,"props":107,"children":108},{},[109],{"type":31,"value":110},"Violation scenarios grounded in the PocketOS incident timeline (credential discovery → external connection → destructive mutation)",{"type":26,"tag":71,"props":112,"children":113},{},[114],{"type":31,"value":115},"Updated policy model fields: trigger hooks, enforcement tiers, trust scores, agent classifications",{"type":26,"tag":71,"props":117,"children":118},{},[119],{"type":31,"value":120},"Target pages in bob-wire: policy listing, policy detail, violation detail, remediation tracking",{"type":26,"tag":71,"props":122,"children":123},{},[124],{"type":31,"value":125},"Remediation data reflecting the new enforcement modes (redaction, allowlist blocking, gate denial, trust-based escalation)",{"type":26,"tag":27,"props":127,"children":128},{},[129],{"type":26,"tag":61,"props":130,"children":131},{},[132],{"type":31,"value":133},"Out of scope:",{"type":26,"tag":67,"props":135,"children":136},{},[137,142,147,152],{"type":26,"tag":71,"props":138,"children":139},{},[140],{"type":31,"value":141},"New wireframe\u002Fmockup pages (use existing page structures)",{"type":26,"tag":71,"props":143,"children":144},{},[145],{"type":31,"value":146},"Changes to Wire* or Ux* component APIs",{"type":26,"tag":71,"props":148,"children":149},{},[150],{"type":31,"value":151},"Changes to the design site itself (this cycle lives in bob-wire's pages)",{"type":26,"tag":71,"props":153,"children":154},{},[155],{"type":31,"value":156},"The trust score visualization (that's a separate design problem)",{"key":158,"title":159,"empty":16,"ast":160},"key-changes","Key Changes",{"type":23,"children":161},[162],{"type":26,"tag":163,"props":164,"children":165},"ol",{},[166,211,221,231],{"type":26,"tag":71,"props":167,"children":168},{},[169,174,176,182,184,190,192,197,198,203,204,209],{"type":26,"tag":61,"props":170,"children":171},{},[172],{"type":31,"value":173},"Policy data model expansion",{"type":31,"value":175}," — new rule types beyond ",{"type":26,"tag":44,"props":177,"children":179},{"className":178},[],[180],{"type":31,"value":181},"allowed_regions",{"type":31,"value":183},"\u002F",{"type":26,"tag":44,"props":185,"children":187},{"className":186},[],[188],{"type":31,"value":189},"blocked_vendors",{"type":31,"value":191},": trigger hooks (",{"type":26,"tag":44,"props":193,"children":195},{"className":194},[],[196],{"type":31,"value":81},{"type":31,"value":83},{"type":26,"tag":44,"props":199,"children":201},{"className":200},[],[202],{"type":31,"value":89},{"type":31,"value":83},{"type":26,"tag":44,"props":205,"children":207},{"className":206},[],[208],{"type":31,"value":96},{"type":31,"value":210},"), match patterns (regex, path globs, destructive verbs), actions (redact, block, gate, escalate, suspend)",{"type":26,"tag":71,"props":212,"children":213},{},[214,219],{"type":26,"tag":61,"props":215,"children":216},{},[217],{"type":31,"value":218},"Trust score as a first-class field",{"type":31,"value":220}," — policies now carry a trust impact dimension, and the violation model includes trust score at time of violation",{"type":26,"tag":71,"props":222,"children":223},{},[224,229],{"type":26,"tag":61,"props":225,"children":226},{},[227],{"type":31,"value":228},"Agent classification",{"type":31,"value":230}," — POL-006 introduces a new entity type (agent permission level) that the listing page needs to surface",{"type":26,"tag":71,"props":232,"children":233},{},[234,239],{"type":26,"tag":61,"props":235,"children":236},{},[237],{"type":31,"value":238},"PocketOS incident as through-line",{"type":31,"value":240}," — violation and remediation data tells a coherent story: the same 9-second incident seen through each policy's lens",{"key":242,"title":243,"empty":16,"ast":244},"outcome","Outcome",{"type":23,"children":245},[246],{"type":26,"tag":27,"props":247,"children":248},{},[249],{"type":31,"value":250},"Bob-wire policy pages populated with AI agent security data that demonstrates Qpoint's runtime enforcement thesis — prevention at the source, not detection at the boundary. The synthetic data is grounded enough to use in demos and storytelling.",{"key":252,"title":253,"empty":16,"ast":254},"extra","Source Material",{"type":23,"children":255},[256],{"type":26,"tag":67,"props":257,"children":258},{},[259,269,280],{"type":26,"tag":71,"props":260,"children":261},{},[262,267],{"type":26,"tag":44,"props":263,"children":265},{"className":264},[],[266],{"type":31,"value":49},{"type":31,"value":268}," — 6 policies, definitions, PocketOS mappings, visual test cases",{"type":26,"tag":71,"props":270,"children":271},{},[272,278],{"type":26,"tag":44,"props":273,"children":275},{"className":274},[],[276],{"type":31,"value":277},"bob-wire\u002Fapp\u002Fpages\u002Fc1\u002Flearnings\u002Fpolicy-starter-pack.md",{"type":31,"value":279}," — existing 16-policy enterprise pack (infrastructure-era reference)",{"type":26,"tag":71,"props":281,"children":282},{},[283],{"type":31,"value":284},"Bob-wire policy pages: c0\u002Fpolicies-v2, c1\u002Fpolicy-compliance-v1, c6\u002Fdashboard-v1\u002Fsecurity, c10\u002Fsecurity-global-overview-v1",[],[],[],[],[],1789151084407]