Parent epic: #5
Summary
Implement Context Builder authorization and source-access policy for Context Builder v1.
Ownership and dependencies
Scope and deliverables
- Require an explicit caller/owner, purpose, source scope, target prompt/version, classification ceiling and time-bounded preparation decision before loading source bytes.
- Implement a policy-verifier interface and deterministic test verifier; trusted policy evidence must be verified rather than inferred from a caller-supplied allow string.
- Keep preparation approval distinct from the later exact package-instance use authorization required by Prompt SDK.
- Prevent confused-deputy access, source-scope expansion, expired/revoked decisions, path traversal and authorization-cache reuse across callers/purposes.
Acceptance criteria
Implementation guardrails
Follow Constitution v1.0.0 at a9cc8a503aa30e17820edc62ac95f7cbe10e0564 and repository boundaries. Add focused tests with implementation; the later suite task consolidates rather than postpones testing. Public issues, fixtures and docs use synthetic/already-public material only. Approved private inputs stay behind explicit secure artifact boundaries. No direct Lore checkout, silent declassification, self-approval or canon promotion.
Parent epic: #5
Summary
Implement Context Builder authorization and source-access policy for Context Builder v1.
Ownership and dependencies
Scope and deliverables
Acceptance criteria
Implementation guardrails
Follow Constitution v1.0.0 at
a9cc8a503aa30e17820edc62ac95f7cbe10e0564and repository boundaries. Add focused tests with implementation; the later suite task consolidates rather than postpones testing. Public issues, fixtures and docs use synthetic/already-public material only. Approved private inputs stay behind explicit secure artifact boundaries. No direct Lore checkout, silent declassification, self-approval or canon promotion.