Customer guide
Session clearance
Clearance is what this session may still do. It is not the named-agent census and it is not risk.
- Deploy (default for new sessions): full set
- Build: no net, no external side effect, no export
- Read: read-only / observe
If a tool is above the session clearance, evaluate returns
DENY with reason SESSION_CLEARED.
HIGH-risk shrink
Workspace mode on /app/kya/policy:
- Operator (default): HIGH risk lights Watch. Powers stay until someone shrinks.
- Auto: HIGH risk drops Deploy to Build. Never auto-restores.
- Require approve: the knob exists. Today HIGH risk still waits for an operator click (same as Operator). Restore to a higher clearance is also an operator action.
Shrink never kills the agent. Console: Sessions table and session detail. Dashboard Watch counts high-risk or already-shrunk sessions.
Docs hub · Install · How KYA works · Source