Introduction¶
The core design philosophy of DeepSeek Harness (DSH) is “everything is a plugin.” In enterprise adoption, the first three questions are usually: who can invoke high-risk tools, how is an incident traced back after it happens, and where is the cost being spent. dsh-gov is a plugin designed for this purpose, providing policy-based tool gating, structured audit logs, and Agent-level token quota controls.
What This Is¶
This is an Agent governance suite for DeepSeek Harness, designed to provide policy gating, structured auditing, and cost management. It is maintained by user 863683348, with state persisted under the $DSH_HOME/gov/ directory.
Core Features¶
- Policy gating: Rules can be configured by tool name, Agent, or workspace, with actions including allow, deny, or ask. It supports wildcards and priority. The default policy is allow, and ties follow fail-closed logic (deny > ask > allow).
- Structured audit logs: Generates append-only JSONL files, recording tool name, Agent, workspace, decision, reason, and outcome (tool arguments are not recorded).
- Token quota management: Based on the host’s
tokenMeter, it accumulates token usage by Agent ID. It supports quotas by day/week/month/total, and injects warnings into the model context when limits are exceeded. - Tool interception and observation: Performs policy checks before tool execution and records the result after the tool call.
Installation and Enablement¶
Install it through the official plugin catalog:
dsh plugin --profile <profile> add dsh-gov
After installation, the plugin takes over DSH’s tool invocation workflow and automatically creates policy, quota, and audit data under $DSH_HOME/gov/.
Typical Usage¶
The plugin provides a gov tool with the following common commands:
- View governance overview:
gov status
- Add a policy (example: require approval for tools that start with PowerShell):
gov policy_add tool="pwsh*" policyAction=ask reason="shell commands require approval" priority=10
- Set a quota (example: set a daily limit of 100,000 tokens for Agent alice):
gov quota_set id=alice quotaLimit=100000 period=day
- Query audit logs (example: query the most recent deny records):
gov audit_query decision=deny limit=20
Use Cases and Cautions¶
This plugin is suitable for teams that require strict permission control, compliance auditing, or cost management. Note that the plugin runs with the permissions of the current DSH process, invokes tools, and accesses the file system. Be sure to inspect the source code and license before installation.
Conclusion¶
dsh-gov provides foundational capabilities for policy gating, audit tracing, and quota management, helping enterprises use DeepSeek Harness more securely. For more details, refer to the community directory or the GitHub repository.