Workspace isolation
Candidate content must belong to the current task workspace.
Governance / Runtime Control Plane
Before information enters context, a tool runs, or business data is written, NexusClaw determines who is acting, what they may read, the action risk, and whether a person must approve.
After execution or blocking, the same chain preserves trace, tool calls, approvals, risk, cost, and outcome evidence. Governance is part of runtime, not a side report.

01 / Permission-aware Context
Knowledge retrieval checks workspace, role, object-read permission, and content access level for every candidate. If any condition fails, the candidate is denied by default and cannot influence later tool use.
Candidate content must belong to the current task workspace.
Independent employees use their role; assistants inherit the real caller’s role.
Business objects and related records must be readable by that subject.
Private, organization-node, and global knowledge are evaluated individually.

02 / Guardrails & Risk Levels
Guardrails turn “should not” prompt advice into system policy. Rules can target objects, operations, sensitive fields, tools, and learning usage with deterministic priority.
Low-risk reads or verified actions run and remain traced.
Extra checks or result review without necessarily pausing the flow.
Explicit confirmation before a sensitive action runs.
Pause execution and route the decision to an accountable person.
Deny the action with no bypass path.
Policy ownership
Guardrail release and rollback have registered owners. An Agent cannot disable, rewrite, or bypass policy at runtime.
03 / Human Approval
The approval center gives the approver the object, execution ID, current step, submission time, and recent action. The person reviews context and approves or rejects before execution.
Know which business record the action affects.
See where execution paused and what it intends to do.
The real approver identity enters the audit chain.

04 / Trace, Cost & Audit
Execution detail preserves input, output, status, duration, model and token usage, tool-call chain, and ReAct step timeline. Audit connects risk, object, action, approval, PII, and learning-use state.
Trigger source, step timeline, and final output.
Which tools ran, with parameters and result state.
Model, tokens, duration, and spend by step.
Which policy matched, who decided, and final state.

Filter by execution ID, trace, object, risk, action, and time to see how reads, writes, creates, or blocks happened and whether evidence entered learning.

Customer Evaluation Checklist
Confirm it never enters context instead of being masked after generation.
Confirm L3 pauses for approval and L4 blocks without a bypass.
Inspect input, tools, model, cost, approval, and outcome as one chain.
Verify linkage to execution, business object, owner, and learning-use state.
Governance depends on explicit identity, roles, object access, guardrails, and approval configuration. It does not define your compliance policy for you or imply undeclared certifications; it enforces configured boundaries and preserves evidence.
We will test permission context, guardrail matching, human approval, execution or blocking, then replay the complete audit evidence from the outcome.