feat(governance): in-runtime policy evaluator + native exports#124
Open
aditik0303 wants to merge 4 commits into
Open
feat(governance): in-runtime policy evaluator + native exports#124aditik0303 wants to merge 4 commits into
aditik0303 wants to merge 4 commits into
Conversation
There was a problem hiding this comment.
Pull request overview
This PR introduces a native (in-process) governance policy evaluator implementation and adds a comprehensive test suite validating enforcement modes, operator behavior, and key governance detectors (including incident taxonomy and commitment language detection). It also exposes the native evaluator and models via uipath.runtime.governance.native for downstream consumption.
Changes:
- Add
GovernanceEvaluatorimplementation with operator support, audit emission, and guardrail-compensation dispatching. - Add new tests covering evaluator enforcement/audit behavior, operator semantics, and commitment-language/incident detection.
- Export native evaluator and policy-model symbols from
uipath.runtime.governance.native.
Reviewed changes
Copilot reviewed 6 out of 6 changed files in this pull request and generated 5 comments.
Show a summary per file
| File | Description |
|---|---|
| tests/test_text_extraction.py | Adds tests for governable-text extraction used by the governance wrapper. |
| tests/test_evaluator.py | Adds tests for evaluator enforcement modes and audit/exception behavior. |
| tests/test_evaluator_operators.py | Adds tests for operator semantics, field resolution, and evaluate_* dispatcher context building. |
| tests/test_commitment_concern.py | Adds tests for updated commitment-language detection behavior. |
| src/uipath/runtime/governance/native/evaluator.py | Adds the native governance evaluator implementation and detector/operator logic. |
| src/uipath/runtime/governance/native/init.py | Exposes the evaluator + native policy model + loader APIs via package exports. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
8812695 to
2da1f67
Compare
a019ade to
6af3c9f
Compare
2da1f67 to
5b119ac
Compare
6af3c9f to
f7cc79e
Compare
5b119ac to
2154aba
Compare
f7cc79e to
94cea5b
Compare
2154aba to
1f7bdad
Compare
ce18588 to
e186f5f
Compare
0e9ad5b to
470533e
Compare
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
… in rule + cross-rule aggregation; align vader threshold default to -0.3 (matches docstring/comment/else + YAML default); importorskip wrapper in text-extraction test Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
… import - evaluator.py: inline `# type: ignore[import-untyped]` on the vaderSentiment import (replaces the removed [[tool.mypy.overrides]] entry; vaderSentiment ships no stubs). - test_evaluator / test_evaluator_operators: import reset helper from tests._helpers. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
…orts Closes radu's recurring boundary objection for the evaluator slice and makes the post-rebase stack actually import. The evaluator was the last place where everything PR #121-#123 instance-scoped collapsed back to process globals. Architectural - GovernanceEvaluator gains constructor injection: GovernanceEvaluator(policy_index, *, enforcement_mode=AUDIT, audit_manager=None, compensator=None) - Drop get_audit_manager() / get_enforcement_mode() / submit_compensation free-function lookups. The evaluator now consults zero process-globals on the hot path. - mode property is read-only (drop the setter); no two-writer race between the loader and evaluator. - audit_manager=None and compensator=None short-circuit cleanly so tests + minimal wirings work without injecting every dep. - Drop unused is_enforce_mode() public method (dead code; no caller in src/ or tests/). Post-rebase plumbing - _dispatch_compensation uses self._compensator.submit(...) instead of the deleted free function; reads r.validator (Pydantic attribute) instead of the old r["validator"] TypedDict access. - _emit_audit passes policy_id (PR #122 trace-contract field, was rule_id) and enforcement_mode=mode enum (PR #122 required arg). - Import EnforcementMode from uipath.core.governance (governance.config deleted in PR #121); import AuditManager from _audit.base (audit/ is _audit/ post-PR-#122). native/__init__.py - Drop the four module-level loader-function re-exports (get_policy_index / load_policy_index / prefetch_policy_index / reset_policy_index) — all deleted in PR #121's PolicyLoader refactor. - Export PolicyLoader instead. Tests - test_evaluator: full rewrite. Drop deleted-import paths (tests._helpers.reset_enforcement_mode, governance.config). Replace the global-manager fixture with a per-test AuditManager that uses register_default_sinks=False + a capturing sink. Every GovernanceEvaluator() call routes through a _build_evaluator helper with explicit mode + manager. New test_no_audit_manager_short_circuits replaces the previous test that mocked the global to raise. - test_evaluator_operators: drop the autouse mode-isolating fixture (no globals to isolate); DISABLED-mode test passes enforcement_mode=EnforcementMode.DISABLED via constructor. - test_guardrail_compensation: rebase-conflict resolution dropped the stale incoming-side imports (Action/LifecycleHook, backend_client, unguarded GovernanceEvaluator) since none of them are referenced in the rest of the file. 357 passed, 1 skipped (pre-existing wrapper skip). Ruff clean. Mypy clean (11 source files). Bandit shows only the pre-existing B101 in _yaml_to_index.py (out of scope). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
e186f5f to
5812bbf
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Stacked PR 5/7 — part of splitting
feat/governance-coreinto reviewable slices. Base:feat/governance-guardrail-compensation. One logical slice (branch is cumulative so CI is green). Merge in order #1 → #7 and delete each branch on merge so the next PR auto-retargets ontofeat/agentic-governance.feat/governance-corekept untouched as backup.