Review mode
Review mode adds a human checkpoint before a proposal becomes an actual change. Evolver can produce candidate strategies and experience, while the active agent application or runtime edits files, runs commands, and calls external services. These are separate approval boundaries.
Require review when
- Running in a repository, production environment, or identity home for the first time.
- The plan touches dependencies, configuration, credentials, networks, releases, deletion, or persistent processes.
- The asset came from another node or was validated in a different environment.
- Expected impact exceeds the file or line budget set for the task.
Review a proposal
- Compare the proposal with the task and list the allowed read, write, and command scope.
- Inspect candidate provenance, trust state, and trigger signals.
- Review commands, working directory, timeout, network use, and secret sources.
- Define success evidence, stop conditions, and recovery.
- Approve only the current scope and review again when the proposal changes.
Review an asset
bash
evolver review --approve <asset_id> "verified for this scope"
evolver review --reject <asset_id> "scope or evidence is insufficient"
Review approval does not authorize automatic publishing or unrestricted execution. Publishing, trust promotion, and task execution keep their own controls.
After rejection
Preserve the asset ID, rejection reason, and evidence. Do not widen repository permissions merely to make the proposal pass. Validate an environment mismatch in isolation; revoke or replace a strategy that is itself out of bounds.
Related pages
EvoX Docs · Security · Execution boundaries