Introduction

The core idea of DeepSeek Harness is “everything is a plugin.” Existing safety classifiers usually focus on whether the output itself is harmful, which is a model-level property. The TapPass plugin focuses on a different question: under the current rules, is this agent allowed to perform this action? This is an organizational business attribute that model weights cannot answer.

The plugin intercepts each tool call at Harness’s tools/pre-execute hook, sends it to TapPass’s policy decision point, and allows, denies, or escalates it to human approval based on the returned result.

Plugin Positioning

This is a plugin designed for DeepSeek Harness, aimed at providing authoritative control at the business-rule level for agentic AI. It is maintained by tappass and is licensed under the MIT License.

The core problem it solves is: how to enforce internal organizational business logic in Harness—such as refund limits, PII data cross-border transfer restrictions, or CRM read-only policies—rather than relying solely on the model’s safety classifiers.

Core Features

  • Intercept tool calls: intervenes at the tools/pre-execute stage before tool execution.
  • Business-rule based: policies are written in business language (for example, “refunds over 500 require human approval”) rather than as prompts.
  • Observe and Enforce modes: runs in observe mode by default, recording all calls without blocking them; once verified, it can be switched to enforce mode.
  • Cross-model/framework interoperability: the same set of rules can be applied to Harness, Claude Code, Codex, or LiteLLM backends.
  • Audit logs: records the entire decision process, supports EU hosting, and meets EU AI Act requirements.

Installation and Enablement

Before installing, ensure that DeepSeek Harness is installed and that a default Profile is configured.

  1. Install the plugin:
    Run the following command to add the plugin to the default profile configuration:
    dsh plugin --profile default add @tappass/dsh-governance
  1. Configure the environment variable:
    Set the TapPass developer key, which is bound to a specific agent and org:
    export TAPPASS_API_KEY="tp_dev_..."
  1. Verify the configuration:
    Without starting Harness, check whether the configuration is loaded correctly:
    dsh --profile default --dump-config

Typical Usage

After the plugin is installed, its operating mode must be configured through a YAML patch. The default mode is observe (logging only); the policy takes effect when set to enforce.

Create or edit the configuration file (for example, $DSH_HOME/profiles/default/cordis.patch.yml):

- tappass-governance:
    config:
      mode: enforce

Decision Flow

The plugin maps the outcome returned by TapPass to a Harness decision:

TapPass outcome Harness decision Effect
allow next() The tool continues execution
block { kind: 'deny', reason } The model receives an error result and reason
needs_approval { kind: 'ask', reason } Routes to Harness’s human approval flow

In observe mode, all calls return next() by default, but intercepted block or needs_approval requests are still logged on the server side, allowing you to evaluate traffic before switching to enforce mode.

Use Cases and Notes

Use Cases

  • Fine-grained permission control is needed for agent tool calls (for example, read-only CRM access or preventing modifications to sensitive configuration).
  • Organizations that need to comply with EU data localization and AI Act requirements.
  • Teams that want to observe first, then enforce, and tighten policies gradually.

Notes

  1. Parameter rewriting is not supported: DeepSeek Harness sets tool parameters to read-only at the tools/pre-execute stage (for logging and display), so the TapPass modify intent cannot be applied directly. In enforce mode, the plugin denies such requests directly (Fail Closed) and returns the reason.
  2. Approval requires an open turn: The needs_approval intent maps to Harness’s ask decision and requires an approver to be configured. If no approver is configured, the request safely falls back to denial.
  3. Developer preview stage: DeepSeek Harness and its plugin API are currently in the developer preview stage and may change.
  4. EU hosting: The TapPass service is hosted in the EU, and the API endpoint is https://app.tappass.ai/v1/govern.

Conclusion

TapPass governance provides the ability to enforce organizational business rules at the AI agent execution layer. By switching between observe mode and enforce mode, it allows teams to retain agent autonomy while controlling risk. All decisions are recorded, ensuring audit transparency.

  • Plugin directory: https://www.skillhub.cn/plugins/tappass/dsh-governance
  • Source code repository: https://github.com/tappass/dsh-governance