{"slug": "naif-agent-mutation-firewall-allow-quarantine-and-unsupported-explained", "title": "NAIF Agent Mutation Firewall: ALLOW, QUARANTINE and UNSUPPORTED explained", "summary": "NAIF Gravity detailed its Agent Mutation Firewall (AMF), a review gate for AI-generated code changes that returns ALLOW, QUARANTINE or UNSUPPORTED verdicts based on a bounded admitted scope. The public Pilot Kit uses frozen AMF v0.4 with a default scope of up to eight modified Python files, one unannotated pure positional-argument function per file, and integers from -64 to 64 plus None, and produces unsigned receipts with SHA-256 integrity links rather than issuer authentication. The company says enterprise access is not yet generally available and is soliciting institutional enquiries for requirements and scope discussion.", "body_md": "An AI coding agent proposes a small refactor. The tests pass. Before approving it, a reviewer still needs to know which behavior was compared, which inputs were covered, and what happened when the change exceeded the evaluator's scope.\n\nThis is the review problem behind **NAIF Agent Mutation Firewall (AMF)**, the second component of NAIF Enterprise Assurance. RDR provides the analysis foundation; AMF provides the mutation review gate; the Pilot Kit packages the GitHub integration and evidence.\n\n**Enterprise Access — Coming Soon.** This article explains the documented approach for institutional enquiries; it does not announce general production availability.\n\n| Decision | Review meaning | \n|---|---|\n| ALLOW | No observed behavior change within the admitted scope and configured input domain. | \n| QUARANTINE | Review the change and any reported counterexample before proceeding. An intentional behavior-changing repair can also be quarantined under a preserve-behavior policy. | \n| UNSUPPORTED | The evaluator cannot assess the change within its supported scope. Route it to another review method. | \n\nAn unsupported result must never become ALLOW just because the agent produced plausible code or the surrounding workflow finished successfully.\n\nConsider this illustrative edit:\n\n``` python\n# Before\ndef classify(value):\n    if value >= 0:\n        return 1\n    return 0\n\n# Proposed change\ndef classify(value):\n    if value > 0:\n        return 1\n    return 0\n```\n\nFor an input of zero, the two versions take different branches. A preserve-behavior review should investigate that difference rather than treating it as a cosmetic refactor. Whether the new behavior is desirable is a separate product decision.\n\nThis example explains the review question; it is not a new execution result or benchmark claim.\n\nThe public Pilot Kit uses frozen AMF v0.4 and the engine hashes referenced by RDR V2.5.7. Its default admitted scope is narrow: up to eight modified Python files, one unannotated pure positional-argument function per file, and integers from -64 to 64 plus None.\n\nImports, attributes, loops, classes, arbitrary calls, strings, floats and general multi-language projects fall outside that scope. Both engine observations must agree before ALLOW in the documented adapter. Syntax-derived invariant candidates are not proven invariants.\n\nThis makes the result assessable: a reviewer can see the domain and exclusions instead of reading an unqualified “safe” label.\n\nThe documented artifacts include raw engine receipts, wrapper passports, hashes, logs, timings and a minimal-in-domain counterexample when one is found. The receipt must stay associated with the analyzed base and proposed revision.\n\nReceipts are unsigned. SHA-256 links support integrity checking; they do not authenticate the issuer. The gate does not certify arbitrary software, automatically merge a PR, or replace review of authentication, network behavior and unsupported code.\n\nA practical institutional evaluation starts by choosing a small supported change class and defining the behavior that must remain unchanged.\n\nInterested teams can email **[contact@naifgravity.com](mailto:contact@naifgravity.com)** with the subject **NAIF Agent Mutation Firewall — Institutional Enquiry**. Include your review use case, languages, current approval workflow and a synthetic or redacted example. Do not include credentials or customer data.\n\nEnquiries are for requirements and scope discussion. Availability will be announced separately.\n\nTechnical reference: [NAIF AMF Pilot Kit documentation](https://github.com/naief9961-tech/naif-amf-pilot-sandbox).\n\n[NAIF Gravity](https://naifgravity.com) · [Enterprise overview](https://dev.to/naifgravity/reviewing-ai-generated-code-changes-with-bounded-evidence-naif-enterprise-assurance-3k3c)\n\nDisclosure: Published by NAIF Gravity. AI drafted this explanation from the public pilot documentation; no new benchmark or production validation was performed for this article.", "url": "https://wpnews.pro/news/naif-agent-mutation-firewall-allow-quarantine-and-unsupported-explained", "canonical_source": "https://dev.to/naifgravity/naif-agent-mutation-firewall-allow-quarantine-and-unsupported-explained-39en", "published_at": "2026-10-07 05:41:49+00:00", "updated_at": "2026-10-07 05:47:44.777954+00:00", "lang": "en", "topics": ["ai-agents", "ai-safety", "developer-tools", "ai-tools"], "entities": ["NAIF Gravity", "NAIF Agent Mutation Firewall", "NAIF Enterprise Assurance", "RDR", "Pilot Kit", "GitHub"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/naif-agent-mutation-firewall-allow-quarantine-and-unsupported-explained", "markdown": "https://wpnews.pro/news/naif-agent-mutation-firewall-allow-quarantine-and-unsupported-explained.md", "text": "https://wpnews.pro/news/naif-agent-mutation-firewall-allow-quarantine-and-unsupported-explained.txt", "jsonld": "https://wpnews.pro/news/naif-agent-mutation-firewall-allow-quarantine-and-unsupported-explained.jsonld"}}