PTENES
Skip to content
TRACK 4

🛡️ Govern and learn

An unconstrained agent needs written rules. Define what it can do on its own and what it must ask you first, let it propose new rules only with your approval, turn on the guard that asks before causing damage, and finish with the final project: your bridge and your team.

4
Modules
24
Topics
~2h20
Duration
Project
Level
0 of 240%
POLICY N0 · N1 · N2 N3 · N4 prepares and asks agentproposes youapproves Lessons deleting and spending: never on its own

Learning path map

Detailed content

4.1~35 min

🚦 Autonomy policy

POLITICA.md: five levels of autonomy, a limit for each type of action, and how Claude Code and Codex apply the same rules.

0 of 60%
What it is:

N0 only talks, N1 prepares and the human executes, N2 executes after asking, N3 executes and notifies, N4 executes without notifying.

Why learn:

It’s the scale that determines how much the agent can do without you. The kit’s default is “prepare and ask.”

Key concepts:

Autonomy, N0–N4, prepare and ask, impact of the action.

What it is:

The POLITICA.md table: reading goes up to N4, modifying files up to N3, system commands and sending up to N2, and spending and deleting only at N1.

Why learn:

The greater the impact of the action, the more you participate. The table determines this before the agent starts.

Key concepts:

Limit, action type, send, spend credits, delete with a backup.

What it is:

The rule in POLITICA.md: a "always allow" permission never exceeds the action limit.

Why learn:

One hasty click must not turn "send" or "delete" into an automatic action.

Key concepts:

Always allow, ceiling, accumulated permission.

What it is:

The kit's .claude/settings.json blocks rm -rf, git push --force, git push -f, and git reset --hard.

Why learn:

In CHANGELOG 0.1.0, even in the mode that allows everything, touch ran and rm -rf was denied.

Key concepts:

Permissions, deny, acceptEdits, written block.

What it is:

In Codex, the policy becomes a sandbox: read-only to read, workspace-write to make changes, and no auto-approval for everything else.

Why learn:

The codex-exec.sh bridge rejects danger-full-access: the same rule applies to both agents.

Key concepts:

Sandbox, read-only, workspace-write, refusal due to POLICY.

What it is:

Only official tools through the subscription, never pass credentials from one tool to another, reverse engineering only in a lab.

Why learn:

These are the three lines that protect your account and your data when connecting one tool to another.

Key concepts:

Subscription, credential, LIMITES.md, production.

View Full
4.2~35 min

📚 The agent proposes, you approve

The kit's learning cycle: the Aprendizado table, the AGENTS.md Lessons, FALHAS.md, and LIMITES.md, one line at a time.

0 of 60%
What it is:

The AGENTS.md rule: the agent doesn’t change the rules; to propose a change, it adds a row to the Aprendizado table.

Why learn:

An agent that rewrites its own rules may give itself more freedom than you allowed.

Key concepts:

Proposes, approves, incorporates; separation of roles.

What it is:

Date, what happened with evidence, one-line proposal, and status: proposed, approved, or rejected.

Why learn:

You can approve a proposal with evidence in seconds; without evidence, you can't decide.

Key concepts:

Evidence, one-line proposal, status.

What it is:

What you approve becomes a rule in the Lessons section of AGENTS.md, which Claude and Codex read.

Why learn:

The lesson applies in future sessions for both agents, without you having to repeat it.

Key concepts:

Lessons, AGENTS.md, CLAUDE.md, approved rule.

What it is:

Date, what broke, the smallest fix, and whether it was a prompt or infrastructure issue. Real example from the kit: the doctor read only Codex’s stdout.

Why learn:

After a few lines, the pattern emerges, and you stop rebuilding what only needed a safeguard.

Key concepts:

Smallest fix, prompt × infrastructure, one line.

What it is:

Date, what was attempted, what blocked it, the workaround, and the status. Bugs go in FALHAS.md; environment limits go here.

Why learn:

Quota, permission, or network blocks don’t disappear on their own: once recorded, they become a list to resolve.

Key concepts:

Environment limitation, workaround, open or accepted status.

What it is:

Once a week, the agent reads FALHAS.md and LIMITES.md and proposes entries for the Learning table; you approve or reject them.

Why learn:

It’s the “learn” step of the cycle becoming a habit, without taking the decision away from you.

Key concepts:

Weekly review, failure patterns, approve or reject.

View Full
4.3~35 min

🧱 Guard and panel

Recipe R7: official hooks that ask before stepping on another session’s work or deleting too much, and the team dashboard in the background.

0 of 60%
What it is:

Mod is the nickname for official plugins. The guard uses PreToolUse and PostToolUse hooks: the rule lives in the script, the interface in the mod.

Why learn:

The videos showed collision and blast-radius guards; the kit does the same using only official features.

Key concepts:

Hook, plugin, mod, PreToolUse, PostToolUse, worktree.

What it is:

Before editing a file another session has touched, or that changed externally in the last 30 min, the guard asks: continue, worktree, or cancel.

Why learn:

In one of our projects, one session emptied a file another was editing.

Key concepts:

Collision, toques.json, 30-minute window, Codex limit.

What it is:

Before rm or git clean, the guard counts the files that would be deleted, shows their size, and asks for confirmation.

Why learn:

The R7 proof runs the script on its own and shows "permissionDecision":"ask" without deleting anything.

Key concepts:

Blast radius, disk read-only, backup.

What it is:

claude --plugin-dir for one session, or the hooks block copied into the other project's settings.

Why learn:

The protection applies wherever your agents work, not just in the kit’s folder.

Key concepts:

--plugin-dir, hooks block, kit path.

What it is:

An optional mod that shows claude --bg sessions with Refresh and Stop buttons.

Why learn:

Monitor and stop the team without leaving Claude Code; just your click for a session.

Key concepts:

Panel, plugin validate, plugin test, 1 pass.

What it is:

Mods run with Claude Code permissions. Before installing a third-party one, ask the agent to read and explain it without running it.

Why learn:

The same power that protects can cause damage: reading the code is the only guarantee.

Key concepts:

plugin.json, hooks.json, network, credentials.

View Full
4.4~35 min

🧪 Lab and final project

The right place for reverse engineering, and the project that wraps up the course: a system of your own without an API becomes a bridge, a team works on it, and the verifier proves it.

0 of 60%
What it is:

Before any reverse engineering, test each level with one command, from API to local bridge.

Why learn:

Often the route exists; it just wasn’t documented.

Key concepts:

Ladder, evidence by level, rung 7.

What it is:

Test machine, one line in LIMITES.md, "fragile" label with date, and never in production.

Why learn:

The lab answers “where does it communicate?”; the answer leads back to an official route.

Key concepts:

Test machine, LIMITES.md, fragile, production.

What it is:

Only official tools through the subscription, and never pass credentials or a token from one tool to another.

Why learn:

Whoever has the token acts as you; the right bridge doesn't carry a password.

Key concepts:

Credential, token, terms of use, human login.

What it is:

A system of your own without an API, one line in CAPACIDADES.md, and the highest-level path that works.

Why learn:

Without an entry in the map, the agent won’t use the system; it’s the first step in the final project.

Key concepts:

Final project, CAPACIDADES.md, via, pending.

What it is:

The bridge through recipe R3 (file) or R5 (site), with the three-role team working on it under N2 policy.

Why learn:

It’s the whole course applied to your work: connect, route, and execute with rules.

Key concepts:

Bridge, selftest, Connected, planner, executor, reviewer, N2.

What it is:

One goal with command → expected criteria, the output from verificar.mjs with all OK, and one approved row in the Aprendizado table.

Why learn:

Done means proof, not a guess; and the cycle only closes when learning becomes a rule.

Key concepts:

Goal, verificar.mjs, delivery checklist, Lessons.

View Full
← Previous track: Route and execute Back to top →