Security
Dobby Security
jhf-dobby is the Fabric-governed adaptive-learning module for Helpifyr. It
produces recommendation and learning posture, but it must not become an
unreviewed authority for external actions, tenant-crossing synthesis, policy
changes, or source-code mutation.
Security Boundaries
- Dobby must fail closed to
warmup,observe_only, orproposal_onlywhen Fabric truth, approval integrity, policy integrity, or tenant separation is missing. - No-learn zones are hard boundaries and must not be bypassed by replay, promotion, or recommendation flows.
- Learning output is advisory unless an admitted owner workflow explicitly promotes it.
- Dobby must not mutate external repositories, workflow files, source files, or production systems directly.
- Sensitive evidence should be linked by owner reference, not copied into public docs, Gitea comments, logs, or generated recommendation text.
- Runtime diagnostics must be bounded and must not leak secrets, tokens, credentials, tenant data, or private trace payloads.
Public Documentation Safety
Public manufacturer docs may describe Dobby's advisory role, tenant separation, no-learn posture, and verification paths. They must not expose private learning records, raw traces, tenant-specific samples, or operator-only evidence.
Verify Path
python scripts/validate_docs_inventory.pypython scripts/validate_docs_platform_v1_6.pypython scripts/validate_module_docs.py
License
AGPLv3. See LICENSE.
Project: https://helpifyr.com