$ca-override — logged bypass
The sanctioned escape hatch. Bypass is permitted only with an audit log entry. Overrides are always
logged, always visible, never silent. Single identity, single confirm.
Flow
Validate $ARGUMENTS — the reason names the gate being bypassed and a justification. Reject a
vague reason ("just skip it") and ask for a specific one.
Detect the operator identity from git config user.email only. If it is unset, ask the user once
to state their identity for the log. (No platform ladder, no second confirmation.)
Append one line to <project-root>/.codearbiter/overrides.log:
[ISO-8601 timestamp] | BY: <email> | GATE: <gate bypassed> | REASON: <reason>
The log is append-only — never edited or deleted, committed as a permanent audit artifact.
Proceed with the overridden action. Note in the response that the override is logged.
Security ceiling — heavier path for security-critical stops
A routine gate (lint, a style rule, a non-security review finding) takes the single-confirm path above.
But a security-critical stop is NOT bypassable by a single confirm. The following require the
heavier path below, never the one-line flow:
- a security CRITICAL finding;
- the crypto/secret commit gate (hook H-09b / H-10b — staged crypto/TLS or secret without a gate pass);
- an irreversible operation (data loss, a destructive migration, anything unrollbackable).
Heavier path (all required, in order):
Surface the specific finding verbatim — name the exact primitive/secret/operation and the
concrete risk. A generic "security override" is rejected.
Explicit per-finding acknowledgement — the user must acknowledge that specific finding in
their own words (a bare "yes"/"go ahead"/"I trust you" is declined — this mirrors decision-variance).
Detect identity from git config user.email; if unset, ask once.
Heavier log entry — append a line tagged SECURITY-OVERRIDE that records the specific finding,
not just the gate name:
[ISO-8601] | BY: <email> | SECURITY-OVERRIDE | FINDING: <specific finding> | REASON: <reason>
Only then record the bypass. For the crypto/secret commit gate, that means resolving the
interpreter once by presence — PY=python3; { command -v python3 >/dev/null 2>&1 && python3 --version >/dev/null 2>&1; } || PY=python
— never python3 X || python X, which reruns X on any nonzero exit (#577), and running
"$PY" "${PLUGIN_ROOT}/hooks/security-pass.py",
which writes <project-root>/.codearbiter/.markers/security-gate-passed bound to the
sensitive lines it approves, so hook H-09b/H-10b allows the commit — recorded only after
steps 1–3, never to skip the gate proper.
Under $ca-sprint, a security-critical override is a hard-gate STOP: it surfaces to the user and is
never auto-decided, even in autonomous mode (SPRINT.md hard gates).
Hard gate
MUST write the log line before proceeding — it is not optional. MUST capture an operator identity —
"codeArbiter" or "automated" are not valid. MUST include a justification. The override is scoped to
the immediate action only; it creates no standing exception. MUST NOT edit or delete an existing
overrides.log entry. MUST route a security-critical / crypto-secret / irreversible stop through the
Security ceiling path — never the single-confirm flow — and MUST NOT auto-decide such an override
under $ca-sprint.
When NOT to use
- Routine work that passes all gates — never needed.
- Reconciling two conflicting sources →
$ca-conflict.
1---2name: ca-override-23description: Sanctioned, logged bypass of a gate or hard rule — one audit line, then proceed.4---56# $ca-override — logged bypass78The sanctioned escape hatch. Bypass is permitted only with an audit log entry. Overrides are always9logged, always visible, never silent. Single identity, single confirm.1011## Flow12131. Validate `$ARGUMENTS` — the reason names the gate being bypassed and a justification. Reject a14 vague reason ("just skip it") and ask for a specific one.152. Detect the operator identity from `git config user.email` only. If it is unset, ask the user once16 to state their identity for the log. (No platform ladder, no second confirmation.)173. Append one line to `<project-root>/.codearbiter/overrides.log`:1819 ```20 [ISO-8601 timestamp] | BY: <email> | GATE: <gate bypassed> | REASON: <reason>21 ```2223 The log is append-only — never edited or deleted, committed as a permanent audit artifact.244. Proceed with the overridden action. Note in the response that the override is logged.2526## Security ceiling — heavier path for security-critical stops2728A routine gate (lint, a style rule, a non-security review finding) takes the single-confirm path above.29But a **security-critical stop is NOT bypassable by a single confirm.** The following require the30heavier path below, never the one-line flow:3132- a security **CRITICAL** finding;33- the crypto/secret commit gate (hook **H-09b / H-10b** — staged crypto/TLS or secret without a gate pass);34- an **irreversible** operation (data loss, a destructive migration, anything unrollbackable).3536Heavier path (all required, in order):371. **Surface the specific finding verbatim** — name the exact primitive/secret/operation and the38 concrete risk. A generic "security override" is rejected.392. **Explicit per-finding acknowledgement** — the user must acknowledge *that specific finding* in40 their own words (a bare "yes"/"go ahead"/"I trust you" is declined — this mirrors `decision-variance`).41 Detect identity from `git config user.email`; if unset, ask once.423. **Heavier log entry** — append a line tagged `SECURITY-OVERRIDE` that records the specific finding,43 not just the gate name:4445 ```46 [ISO-8601] | BY: <email> | SECURITY-OVERRIDE | FINDING: <specific finding> | REASON: <reason>47 ```484. **Only then** record the bypass. For the crypto/secret commit gate, that means resolving the49 interpreter once by presence — `PY=python3; { command -v python3 >/dev/null 2>&1 && python3 --version >/dev/null 2>&1; } || PY=python`50 — never `python3 X || python X`, which reruns X on any nonzero exit (#577), and running51 `"$PY" "${PLUGIN_ROOT}/hooks/security-pass.py"`,52 which writes `<project-root>/.codearbiter/.markers/security-gate-passed` bound to the53 sensitive lines it approves, so hook H-09b/H-10b allows the commit — recorded **only** after54 steps 1–3, never to skip the gate proper.5556Under `$ca-sprint`, a security-critical override is a hard-gate STOP: it surfaces to the user and is57**never** auto-decided, even in autonomous mode (`SPRINT.md` hard gates).5859## Hard gate6061MUST write the log line before proceeding — it is not optional. MUST capture an operator identity —62"codeArbiter" or "automated" are not valid. MUST include a justification. The override is scoped to63the immediate action only; it creates no standing exception. MUST NOT edit or delete an existing64`overrides.log` entry. MUST route a security-critical / crypto-secret / irreversible stop through the65**Security ceiling** path — never the single-confirm flow — and MUST NOT auto-decide such an override66under `$ca-sprint`.6768## When NOT to use6970- Routine work that passes all gates — never needed.71- Reconciling two conflicting sources → `$ca-conflict`.