tappass/dsh-governance

The authority layer for agentic AI, as a DeepSeek Harness plugin

TapPass governance is an authority layer for agentic AI implemented as a DeepSeek Harness plugin: it intercepts every tool call at the harness's tools/pre-execute seam, sends it to the TapPass policy decision point (POST /v1/govern), and allows, denies or escalates it for human approval. The distinction vs safety classifiers: those ask whether model output is harmful; TapPass asks whether this agent is allowed to do this under your rules right now — business rules rather than model safety ('refunds over 500 need a human', 'no customer PII leaves the EU region', 'this agent may read the CRM, never write it'). Rules are enforced on every tool call, on every harness, under every model. The plugin ships in observe mode (watch and record, block nothing) so you see real agent behavior before enforcing a single deny. Configuration: baseURL, apiKeyEnv (default TAPPASS_API_KEY), mode (observe → enforce), onError (deny fail-closed / allow fail-open), timeoutMs (4000), agentId, orgId. Verdict outcomes map to dsh PreToolDecision: allow → the tool runs, block → denied, escalate → human approval.

Agent Capabilities ★ 1 updated 2026-08-18 ✅ runtime-tested
View on GitHub ↗

Install

dsh plugin --profile default add @tappass/dsh-governance

npm @tappass/dsh-governance 0.2.1 verified 2026-09-03 (repository field → github.com/tappass/dsh-governance; README EN primary). Install: dsh plugin --profile default add @tappass/dsh-governance, export a TapPass developer key (TAPPASS_API_KEY="tp_dev_..."), verify the composed layer with dsh --profile default --dump-config, then start. The plugin ships in observe mode — it watches and records every tool call and blocks nothing until you enable enforcement. This is an external governance service (app.tappass.ai); a developer key is required and TapPass records the audit trail against it.

Compatibility

DSH harness profiles (tools/pre-execute seam); external TapPass policy decision point (default https://app.tappass.ai/v1/govern); EU hosted; works across harnesses and models (Claude Code, Codex, LiteLLM share the same rules).

Details

Recent updates

tools/pre-execute governance seam; external TapPass PDP; observe-first mode; allow/deny/escalate verdicts; EU AI Act ready; harness- and model-agnostic rules.

FAQ

How is this different from a model safety classifier?
Safety classifiers ask 'is this output harmful?' — a property of the model. TapPass asks 'is this agent allowed to do this under our rules right now?' — a property of your business, enforced on every tool call.
Does it block anything on day one?
No — it ships in observe mode and only records. You switch mode to enforce when you are ready; onError defaults to deny (fail closed) when the PDP is unreachable.
Is an API key required?
Yes — a TapPass developer key (tp_dev_...) bound to one agent and one org, provided via the TAPPASS_API_KEY environment variable; TapPass records the audit trail against it.

Alternatives

PAKIKNOWLEDGE/dsh-auto-classifier · 940842546/dsh-permissions · ai-eks/dsh-auth-tunnel

More plugins in Agent Capabilities

Browse more in Agent Capabilities

Guides for Agent Capabilities plugins