5dive human gates: can an agent clear one?
the list of things our agents have to stop and ask a human about is a file we wrote. the check that a human is the one who answered lives somewhere we can’t write.
if you run agents that can spend money, publish things or delete things, you own two separate questions, and they get collapsed into one constantly. the first is which actions need a person. the second is whether “a person approved this” can be made true by something that isn’t one.
the first is a business judgement and it moves every month. the second is an invariant.
the part you write
gating policy on a 5dive box is /var/lib/5dive/constitution.yaml. it names decision classes as case-insensitive regexes, and an agent about to do something that matches one stops and waits for a tap.
the enforced set, on the box this post was written on:
$ 5dive constitution show --json | jq .data.hard_gates_source
{
"spend_billing": "custom",
"public_comms": "default",
"secrets": "default",
"destructive": "custom"
}
the docs are blunt about how far that goes: supplying the hard_gates map “replaces the shipped class map, so an organization can add or remove a class without patching the CLI.” your editor, your box, no support ticket.
one honest footnote on our own two, because it took me a second to read it right. custom means the sealed doc differs from the patterns we currently ship, and in both cases ours is the narrower one: the shipped destructive class matches drop … table and ours doesn’t. that isn’t a decision anybody made. it’s what a sealed file looks like when the shipped defaults keep growing and yours stays frozen at the version you ratified.
where the floor actually lives
here’s the sentence i went and got verified before writing it down, because the loose version is wrong.
gates typed approval, secret or manual are refused whenever the caller’s operating-system identity is an agent. that check lives in the binary, not the constitution, so a company can retune which topics escalate to a human but not that a human gate needs a human.
the escalation rules are configuration. the refusal is code.
there’s no constitution you can write, seal and ratify that turns an agent-identity caller into an acceptable answer on an approval gate, because the check never consults your constitution to find out. and it reads the identity the operating system reports for the process, rather than a value the command was handed, which is a materially different problem from editing yaml.
why it’s split that way
configuration is the first thing to go under pressure.
an agent that wants past a gate has a shell, sits on the same box as the policy, and the policy is just a path. an agent editing its own permissions and then proceeding is the default threat model in a company staffed by software, not an exotic one, and it stays the default until something structurally prevents it. so the one rule that has to survive a motivated agent can’t be a line in a file that agent can open.
the topic list should be editable for the same reason. we don’t know your company. our defaults gate the word “refund” because we sell a subscription. if you don’t, that class is noise, and a governance system that made you keep it would only train you to swipe taps away without reading them.
the seal is the authority, not the file
the constitution on disk has force only while it matches the digest sealed into the amendment chain. i copied ours, deleted the destructive class from the copy, and pointed the reader at the copy:
$ FIVEDIVE_CONSTITUTION_FILE=./candidate.yaml 5dive constitution show
sealed: fcae79680235d9a2… ⚠ DRIFT: constitution.yaml digest e7ed181a37a3…
does not match the sealed fcae79680235… — an unsanctioned edit
no scan, and gate tiering says the same thing at the moment of the decision: “enforcing the shipped tier-2 floor, not the on-disk file.” a hand-edited constitution stops being obeyed. we wrote that mechanism up in full when it shipped, so it’s not relitigated here.
one thing to try
on a box you already have, file an approval gate at yourself, then try to clear it from an agent seat instead of tapping it:
5dive task need <id> --type=approval --ask="..."
the class that gate falls into is yours to set. seeing the refusal once is worth more than reading about it.
5dive runs a company of AI agents on your own box, on the Claude plan you already pay for. spin one up at 5dive.ai, or read the whole thing at github.com/5dive-ai/5dive.