Repository navigation
Proposal: a Delegation Charter for agent approval policies #16575
Replies: 3 comments
|
For operators who want to measure this on their own deployment first, we've published a read-only check that runs against a LibreChat database with one mongosh command and returns aggregate counts only, no message content: https://github.com/almma-ai/agent-governance-check It reports how many agents have no instructions, hold tools without stated scope, reach outside the tenant or execute code without stated prohibitions, or were revised after being shared. If you run it, sharing the aggregate numbers here would help show how widespread the gap is. |
|
Update ahead of tomorrow’s town hall. We answered our own two questions by reading v0.8.8-rc4:
We published a diagnostic that any operator can install as an Agent Plugin: https://github.com/almma-ai/librechat-charter-diagnostic. It tests every agent against the charter, and the deployment against three conformance levels. It is read-only, admin-only, and MIT-licensed. Its hooks only observe, and every file states what it touches so a coding agent can verify it before you run it. Three things it surfaced in v0.8.8 that may be worth a look:
A first mock, in LibreChat’s own builder style: a never-do list where each item is either Enforced (tied to a tool and a condition, blocked outside the model) or Instructed (guidance to the model only). This is the core change we’d propose: the plugin can already enforce, but only the builder can capture it. See you tomorrow.
|
|
Opened #16923 for the bash fail-open case mentioned above. |

Uh oh!
There was an error while loading. Please reload this page.
The v0.8.8 approval work and Danny's note about approval policies that consider tool inputs and outputs prompted this.
Approvals answer whether a tool call may run. In production, the harder questions are what the agent must never do, when it must stop, and who is accountable.
We've published an open specification, the Delegation Charter (CC BY 4.0): https://github.com/almma-ai/delegation-charter
Every agent gets eight fields:
Why it matters for LibreChat: in an audit of 3,478 agents on a LibreChat-based deployment, 97% had no named human contact and 93% had no escalation path. The builder doesn't ask for these, so they rarely get written.
What we'd propose:
Two questions for maintainers:
a) Will the approval policy and plugin hooks be stable enough for third parties to build on?
b) Could a plugin add a panel to the agent builder, or would that need core changes?
Design mocks will follow next week. Happy to discuss at the October 9 town hall.
All reactions