Principles
- Grant permission per action
- Irreversible actions get their own approval
- Done must be verifiable
How to do it
Write the goal
Describe done as a result the user can see.
Draw the scope
Say what can be read, what can be written and what's off-limits.
Set permissions
State whether installing, committing, publishing, sending and deleting are allowed.
Set stop conditions
Pause on conflicts, secrets or scope creep.
Before you call it done
- The goal is observable
- Path scope is explicit
- Risky actions need approval
- There's a way to recover from mistakes