Three path states
EXPECTED
The Task explicitly authorizes this path. Matching work proceeds without human interruption.
REVIEW
The path may be relevant, but a human must decide before the exact mutation runs.
PROTECTED
The path is outside the Task boundary. The mutation is blocked before execution.
Password reset example
Objective: Add password reset rate limiting.
argos run \
--objective "Add password reset rate limiting." \
--expected "src/auth/password-reset/**" \
--review "src/shared/**" \
--protected "src/auth/session/**"The password-reset implementation is expected. Shared infrastructure requires judgment because the blast radius is wider. Session behavior is protected because it is outside this Task.
Scoping rules
- Use repository-relative paths that resolve to tracked files.
- Make expected scope only as broad as the Task requires.
- Use REVIEW for plausible work whose consequences need human judgment.
- Use PROTECTED for deterministic boundaries that the Task must not cross.
- Argos does not infer Task membership from text, timing, or nearby operations.