CLI reference
sqube-agent-guard --ledger ./sqube_ledger.sqlite3 <command>
Executions
executions --limit 20— list recent runsexecution <execution_id>— record + event timelineledger verify— verify tamper-evident event hash chains
Policy
simulate --action file.read --agent botexplain --action admin_deletepolicy validate policies/org_default.jsonpolicy simulate policies/org_default.json --action send_email
Approvals
Deferred mode (ExecutionGuard(approval_mode="deferred")):
approvals pending— durable approval requests (sq_apr_*)approvals grant <approval_id> [--by name]approvals deny <approval_id> [--reason text]
After grant, resume in Python via guard.resume_after_approval(ctx, fn, approval_id=...).
Sync mode (default) keeps the interactive CLI prompt inside the process.
Authorize (stateless)
Pipe JSON to evaluate policy without touching the ledger:
echo '{"agent_id":"bot","action":"send_email","resource":"a@b.com"}' | \
sqube-agent-guard authorize
Optional bundle:
echo '{"action":"admin_delete"}' | \
sqube-agent-guard authorize --policy-bundle policies/org_default.json