fix: align auditor channel perms, extend desk gate to tests, drop stale usage-event doc

- permissions: the Auditor is a silent, read-only observer with no say/dm in
  its verb surface, so can_write_channel now returns False for it — matching
  the role's real capabilities instead of granting an unreachable channel
  write (test updated to assert read-only).
- Makefile: make lint and make gate now type-check mypy roboco/ tests/, matching
  make quality / make quality-fast, so the developer-desk gate also catches test
  type errors before submit (tests/ is already mypy-clean).
- docs: CLAUDE.md no longer lists USAGE_UPDATE — only USAGE_SNAPSHOT is published
  to /ws/system.
This commit is contained in:
Renn F
2026-06-15 08:13:53 +02:00
parent ba74eb4fd2
commit 77771c280c
4 changed files with 10 additions and 9 deletions
+3 -2
View File
@@ -215,9 +215,10 @@ class PermissionService(SingletonService):
if agent.role == AgentRole.CEO:
return True
# Auditor can write but usually doesn't (to maintain cover)
# Auditor is a silent, read-only observer (no say/dm in its verb surface);
# deny channel writes so this layer matches the role's actual capabilities.
if agent.role == AgentRole.AUDITOR:
return True
return False
# Main PM has access to all channels
if agent.role == AgentRole.MAIN_PM: