治理预设
wesgine 的 Compliance 预设一键装配——从安全级别到治理模式。
三个预设
| 预设 | GovernMode | NetworkPolicy | Redactor | 适用场景 |
|---|---|---|---|---|
StandardPreset() | open | allow | 无 | 编程/助手/通用 |
RegulatedPreset() | locked | internal_only | 按场景 | 金融/PII/医疗 |
ReadonlyPreset() | locked | deny | 无 | 展示/demo |
ComplianceClass
语义标签,通过预设自动映射:
| 类别 | 预设 |
|---|---|
standard | StandardPreset |
pii-strict | RegulatedPreset |
financial | RegulatedPreset |
healthcare | RegulatedPreset |
GovernMode
| 模式 | Yellow Zone 行为 | 典型用途 |
|---|---|---|
open(默认) | Allow + Audit | 编程助手 |
locked | Deny | 金融合规 |
Compliance 与 DenyPaths 解耦
Compliance 只决定 RedactorRules + GuardrailsRequired。
DenyPaths 由 preset 注入(如 PresetFinancial 注入 /credentials)与显式 CellSpec.DenyPaths 管理。
UpdateSpec(Compliance:) 热切只 swap RedactorRules,不增删 DenyPaths。
各产品映射
| 产品 | 默认预设 |
|---|---|
| wescode | standard |
| wesclaw 桌面 | standard |
| wesclaw SaaS | regulated (locked + internal_only) |
| wescraft 个人 | standard |
| wescraft 团队 | 按部门(financial / pii-strict) |
| teleclaw | 按部门映射 |