# CASAN Loop Budget Governor policy (Plan-17 Track 1). # # This file is a GOVERNED, security-sensitive artifact. Loosening any ceiling # (raising a max_*, or adding a more permissive delegation_level / project rule) # must go through control-plane-settings.py (approval JWT + SoD proposer!=approver # + versioned + rollback) — see Plan-17 17.3 / Plan-14 / Plan-16 SEC-07. # # Deny-by-default: any run whose (profile, delegation_level, project) does not # match a rule here falls back to the strictest built-in ceiling in loop_common.py # (STRICT_CEILING), NOT to "unlimited". A missing field inside a matched rule also # falls back to the strict value for that field. # # on_exceed: halt | escalate (halt = stop the loop; escalate = route to the # HITL approvals inbox, Plan-13 §3.4). version: 1 # Organization hard cap (Plan-17 17.19): a governed meta-loop change can never # loosen a budget above these values, even with a valid approval. Defense-in-depth # — the governor also clamps any governed override to this cap at read time, and # loop-metaloop.py refuses to apply a loosen proposal that exceeds it. org_ceiling: max_steps: 200 max_tokens: 1000000 max_wall_clock_sec: 7200 max_cost_usd: 25.0 max_corrections_per_step: 6 profiles: # Production is secure-by-default: tight ceilings, escalate on breach so a human # decides whether to grant more budget (never silently continue). prod: defaults: max_steps: 20 max_tokens: 100000 max_wall_clock_sec: 600 max_cost_usd: 1.0 max_corrections_per_step: 2 on_exceed: halt delegation_levels: L0: max_steps: 5 max_tokens: 20000 max_wall_clock_sec: 120 max_cost_usd: 0.10 max_corrections_per_step: 1 L1: max_steps: 10 max_tokens: 40000 max_cost_usd: 0.25 L2: max_steps: 20 max_tokens: 100000 max_cost_usd: 1.0 L3: max_steps: 40 max_tokens: 200000 max_wall_clock_sec: 1200 max_cost_usd: 3.0 max_corrections_per_step: 3 L4: max_steps: 80 max_tokens: 400000 max_wall_clock_sec: 2400 max_cost_usd: 8.0 max_corrections_per_step: 4 L5: max_steps: 160 max_tokens: 800000 max_wall_clock_sec: 4800 max_cost_usd: 20.0 max_corrections_per_step: 5 projects: okr: max_steps: 30 # Convergence detection (Plan-17 T2): stop a loop that repeats actions or # stops making forward progress. on_stall=escalate routes to the HITL inbox. convergence: oscillation_repeat: 3 thrash_window: 4 no_progress_window: 3 on_stall: escalate # Dev may run longer while iterating, but is still bounded and still audited. dev: defaults: max_steps: 50 max_tokens: 250000 max_wall_clock_sec: 1800 max_cost_usd: 5.0 max_corrections_per_step: 3 on_exceed: halt convergence: oscillation_repeat: 4 thrash_window: 6 no_progress_window: 5 on_stall: escalate