tappass/dsh-governance
The authority layer for agentic AI, as a DeepSeek Harness plugin
TapPass governance is an authority layer for agentic AI implemented as a DeepSeek Harness plugin: it intercepts every tool call at the harness's tools/pre-execute seam, sends it to the TapPass policy decision point (POST /v1/govern), and allows, denies or escalates it for human approval. The distinction vs safety classifiers: those ask whether model output is harmful; TapPass asks whether this agent is allowed to do this under your rules right now — business rules rather than model safety ('refunds over 500 need a human', 'no customer PII leaves the EU region', 'this agent may read the CRM, never write it'). Rules are enforced on every tool call, on every harness, under every model. The plugin ships in observe mode (watch and record, block nothing) so you see real agent behavior before enforcing a single deny. Configuration: baseURL, apiKeyEnv (default TAPPASS_API_KEY), mode (observe → enforce), onError (deny fail-closed / allow fail-open), timeoutMs (4000), agentId, orgId. Verdict outcomes map to dsh PreToolDecision: allow → the tool runs, block → denied, escalate → human approval.
Install
dsh plugin --profile default add @tappass/dsh-governancenpm @tappass/dsh-governance 0.2.1 verified 2026-09-03 (repository field → github.com/tappass/dsh-governance; README EN primary). Install: dsh plugin --profile default add @tappass/dsh-governance, export a TapPass developer key (TAPPASS_API_KEY="tp_dev_..."), verify the composed layer with dsh --profile default --dump-config, then start. The plugin ships in observe mode — it watches and records every tool call and blocks nothing until you enable enforcement. This is an external governance service (app.tappass.ai); a developer key is required and TapPass records the audit trail against it.
Compatibility
DSH harness profiles (tools/pre-execute seam); external TapPass policy decision point (default https://app.tappass.ai/v1/govern); EU hosted; works across harnesses and models (Claude Code, Codex, LiteLLM share the same rules).
Details
- Repo: tappass/dsh-governance
- Category: Agent Capabilities
- Stars: 1
- Version: npm @tappass/dsh-governance 0.2.1
- Last push: 2026-08-18
- First seen: 2026-08-13
Recent updates
tools/pre-execute governance seam; external TapPass PDP; observe-first mode; allow/deny/escalate verdicts; EU AI Act ready; harness- and model-agnostic rules.
FAQ
- How is this different from a model safety classifier?
- Safety classifiers ask 'is this output harmful?' — a property of the model. TapPass asks 'is this agent allowed to do this under our rules right now?' — a property of your business, enforced on every tool call.
- Does it block anything on day one?
- No — it ships in observe mode and only records. You switch mode to enforce when you are ready; onError defaults to deny (fail closed) when the PDP is unreachable.
- Is an API key required?
- Yes — a TapPass developer key (tp_dev_...) bound to one agent and one org, provided via the TAPPASS_API_KEY environment variable; TapPass records the audit trail against it.
Alternatives
PAKIKNOWLEDGE/dsh-auto-classifier · 940842546/dsh-permissions · ai-eks/dsh-auth-tunnel