The custodian's estate-wide sweep (2026-09-21), extending flex-auth's boundaries
review FLEX-WP-0030, found this repository declaring `layer: surface` against a
§3 vocabulary that does not enumerate it. flex-auth's validator admits only
{Staff, Engine, Tooling}, so this fails on the value rather than on casing or on
B1's precedence question. It was never raised here directly and it is not the
nine-repository defect: both our files say `surface`, in the same casing.
`surface` denotes the presentation-and-binding tier — the runtime a human
touches, where a decision rendered elsewhere is shown to a named person, that
person binds their identity to the act, and the evidence that the presentation
happened is produced. It was chosen by elimination on 2026-09-09 (f6376dd),
because GH-DEC-2026-012 R1 ruled us out of Engine and left the layer ours to
declare, and each remaining value is false of us: not Staff (deterministic by
construction, and holding state audit-core depends on at runtime, which §3.4
forbids Staff), not Tooling (we persist nothing another layer reads), not
Taxonomy (we are nothing but a runtime position). Faced with a false value that
satisfies a validator or the true word and a finding, the true word was written.
Position: `surface` names a real tier §3 does not enumerate. The sharpest form
is that a standing ruling plus a closed vocabulary leaves this repository no
conforming declaration available — the §9.1 defect applied to conformance that
§11 names against itself. But the ruling is gate-house's and we do not claim it
must go our way: if the vocabulary is ruled closed and a value named, both files
change the same day without argument. We ask only that such a ruling show how
§3's determinism cut reaches that value given GH-DEC-2026-012 R1, because the
next repository in this position will reason from it — and the tier a human
touches having no owner is exactly what produced approval-engine's unowned
inbox, key-cape's blocked client_id, and this repository.
Two observations offered: flex-auth's validator admits three values where §3
enumerates four, so railiance-master's `Taxonomy` fails the validator rather
than the standard and is separable without any ruling, leaving `surface` as the
only surveyed value outside §3 itself; and §3's row label is `Engines` while
declarations use `Engine`, which should be written out as declaration values if
the set is ruled closed.
The declared value is UNCHANGED on purpose. Changing it ahead of the ruling
would pre-empt gate-house and throw away the evidence of what was concluded.
layer.yaml, INTENT.md and AGENTS.md now say so in place, so the value is not
read as unexamined and no later agent silently "fixes" it. AGENTS.md's layer
section was also stale — it still said layer.yaml was unwritten.
28 layer conformance tests pass.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
301 lines
12 KiB
Markdown
301 lines
12 KiB
Markdown
# informed-decision — Agent Instructions
|
|
|
|
## Repo Identity
|
|
|
|
**Purpose:** Presentation and binding surface for decisions — the Decision Memo, and the browser-facing approver UI that approval-engine does not contain.
|
|
|
|
**Domain:** infotech
|
|
**Repo slug:** informed-decision
|
|
**Topic ID:** `a6c6e745-bf54-4465-9340-1534a2be493e`
|
|
**Workplan prefix:** `INFD-WP-`
|
|
**Category:** product (not `prj-` project flavor — see `.repo-classification.yaml`)
|
|
|
|
Read in this order: `INTENT.md` (stable purpose) → `GOAL.md` (current stage) →
|
|
`SCOPE.md` (what actually exists) → `workplans/`.
|
|
|
|
`history/20260909-initial-exploration/` is the founding provenance record and is
|
|
**never edited**. Governed copies of the schema, canonicalizer and vectors live
|
|
in `schemas/` and the package once `INFD-WP-0001-T06` promotes them.
|
|
|
|
---
|
|
|
|
## State Hub Integration
|
|
|
|
The Custodian State Hub tracks work across all domains. Codex uses HTTP REST and
|
|
the `statehub` CLI by default. MCP is opt-in because the current Codex MCP bridge
|
|
adds severe call latency; the full administrative MCP surface remains available
|
|
to clients that need it.
|
|
|
|
| Context | URL |
|
|
|---------|-----|
|
|
| Local workstation | `http://127.0.0.1:8000` |
|
|
| Remote via tunnel | `http://127.0.0.1:18000` |
|
|
| Optional local edge relay | http://127.0.0.1:18080 |
|
|
|
|
When an operator has enabled the edge relay, set API_BASE to the relay URL.
|
|
Queueable writes return an explicit queued receipt if the central hub is
|
|
unreachable. Treat that as pending local evidence, then ask the operator to run
|
|
statehub outbox status/replay after connectivity returns.
|
|
|
|
Codex workspace-write sandboxes need network access enabled to reach the host's
|
|
loopback listener. Bootstrap this once with `make -C ~/state-hub configure-codex`
|
|
and restart Codex. The canonical REST health endpoint is `/state/health`, not
|
|
`/health`. If a sandboxed loopback probe fails, retry it with escalated execution
|
|
before declaring State Hub unavailable; a managed Codex permission profile may
|
|
still enforce isolated networking. Experimental MCP can be enabled explicitly
|
|
with `make -C ~/state-hub configure-codex WITH_MCP=1`.
|
|
|
|
### Orient at session start
|
|
|
|
```bash
|
|
# Offline brief — works without hub connection
|
|
cat .custodian-brief.md
|
|
|
|
# Active workplans for this domain
|
|
curl -s "http://127.0.0.1:8000/workplans/?topic_id=cee7bedf-2b48-46ef-8601-006474f2ad7a&status=active" \
|
|
| python3 -m json.tool
|
|
|
|
# Check inbox
|
|
curl -s "http://127.0.0.1:8000/messages/?to_agent=informed-decision&unread_only=true" \
|
|
| python3 -m json.tool
|
|
```
|
|
|
|
Mark a message read:
|
|
```bash
|
|
curl -s -X PATCH "http://127.0.0.1:8000/messages/<id>/read" \
|
|
-H "Content-Type: application/json" -d '{}'
|
|
```
|
|
|
|
### Log progress (required at session close)
|
|
|
|
```bash
|
|
curl -s -X POST http://127.0.0.1:8000/progress/ \
|
|
-H "Content-Type: application/json" \
|
|
-d '{
|
|
"summary": "what was done",
|
|
"event_type": "note",
|
|
"author": "codex",
|
|
"workplan_id": "<uuid>",
|
|
"task_id": "<uuid>"
|
|
}'
|
|
```
|
|
|
|
Omit `workplan_id` / `task_id` when not applicable.
|
|
|
|
### Update task status
|
|
|
|
```bash
|
|
curl -s -X PATCH "http://127.0.0.1:8000/tasks/<task_id>" \
|
|
-H "Content-Type: application/json" \
|
|
-d '{"status": "progress"}'
|
|
# values: wait | todo | progress | done | cancel
|
|
```
|
|
|
|
### Flag a task for human review
|
|
|
|
```bash
|
|
curl -s -X PATCH "http://127.0.0.1:8000/tasks/<task_id>" \
|
|
-H "Content-Type: application/json" \
|
|
-d '{"needs_human": true, "intervention_note": "reason"}'
|
|
```
|
|
|
|
---
|
|
|
|
## Session Protocol
|
|
|
|
**Start:**
|
|
1. `cat .custodian-brief.md` — domain goal and open workplans (offline-safe)
|
|
2. Check inbox: `GET /messages/?to_agent=informed-decision&unread_only=true`; mark read
|
|
3. Scan workplans: `ls workplans/` — note `status: ready`, `active`, or `blocked` files and open tasks
|
|
4. Check human-needed tasks: `GET /tasks/?needs_human=true`
|
|
|
|
**During work:**
|
|
- Update task statuses in workplan files as tasks progress
|
|
- Record significant decisions via `POST /decisions/`
|
|
|
|
**Close:**
|
|
1. Update workplan file task statuses to reflect progress
|
|
2. If finishing a workplan: hand off **residuals** as live work records first
|
|
(intake with `origin: residual` + `origin_ref: <WP-id>`, or a next workplan /
|
|
decision / engagement). Do not park leftovers only in prose or `SCOPE.md`.
|
|
Canon: `the-custodian/canon/standards/work-record-types_v0.1.md` § Residuals.
|
|
3. Log: `POST /progress/` with a summary of what changed (name handoff ids)
|
|
4. After workplan file changes, run:
|
|
```bash
|
|
statehub fix-consistency
|
|
```
|
|
Coding agents should run this directly; ask the operator only if the CLI or
|
|
State Hub API is unavailable. This syncs task status from files into the hub DB.
|
|
If C-06/C-11 reports that this host is not the identifier registrar, do not
|
|
retry, export `STATEHUB_REGISTRAR`, or register records by hand. Commit and
|
|
push the file-backed work first, then run the repo-manager fallback once:
|
|
```bash
|
|
uv run --project ~/repo-manager rmgr registrar-reconcile \
|
|
--path . --confirm-primary --push
|
|
```
|
|
If unavailable, send one deduplicated registrar request to `repo-manager`
|
|
naming the repo and canonical ids; UUID absence does not block local work.
|
|
|
|
---
|
|
|
|
## Credential and access routing
|
|
|
|
**Audience:** Codex, Claude Code, Grok, and custodian agents that call **llm-connect**
|
|
for inference. Run this check **before** requesting secrets, API keys, SSH access,
|
|
login tokens, or database passwords — in any repo, not only `ops-warden`.
|
|
|
|
The companion (`net-kingdom/SECURITY-COMPANION.md`) says what the rules are;
|
|
`ops-warden` stewards the paths through them. **Do not** message `ops-warden`
|
|
on State Hub expecting a secret value; the reply is a pointer, not a key.
|
|
|
|
### Lookup (do this first)
|
|
|
|
```bash
|
|
warden route find "<describe your need>" --json
|
|
warden route show <catalog-id> --json
|
|
```
|
|
|
|
Requires the `warden` CLI from `~/ops-warden`.
|
|
|
|
| Agent runtime | How to orient |
|
|
| --- | --- |
|
|
| **Codex / Grok** (shell, HTTP State Hub) | `warden route`; inbox `to_agent=informed-decision` is for coordination, not secret vending |
|
|
| **Claude Code** (MCP when available) | domain summary for workplans; **still** use `warden route` for credential ownership |
|
|
| **llm-connect** | Never put secret retrieval in prompts |
|
|
|
|
### Quick routing table
|
|
|
|
| I need… | Owner | ops-warden executes? |
|
|
| --- | --- | --- |
|
|
| SSH cert (`adm`/`agt`/`atm`) | ops-warden | **Yes** — `warden sign` |
|
|
| API key, DB password, provider token | OpenBao | No — route only |
|
|
| Login / OIDC / MFA | key-cape | No — route only |
|
|
| Authorization decision | access-engine (`flex-auth`) | No — route only |
|
|
| Approval current-state | **this engine** (not yet implemented) | No |
|
|
| SSH tunnel | ops-bridge | No — route only |
|
|
|
|
### Anti-patterns
|
|
|
|
- Asking State Hub or `ops-warden` to vend a secret
|
|
- Pasting secrets into Git, State Hub, workplans, logs, or chat
|
|
- Treating a callable tool as permission (companion §7)
|
|
|
|
**Canon:** `~/ops-warden/wiki/CredentialRouting.md`
|
|
|
|
<!-- REPO-AGENTS-EXTENSIONS -->
|
|
<!-- Append repo-specific agent instructions below this marker.
|
|
The state-hub template sync preserves content after this line. -->
|
|
## This repository's layer
|
|
|
|
**PEP-shaped**, statute §6.4 / companion §5 — ruled by `GH-DEC-2026-012`
|
|
(2026-09-09, answering `INFD-IN-0001`) and declared in `layer.yaml` and
|
|
`INTENT.md` frontmatter. Still no §4 catalog row: this repository declared ahead
|
|
of being catalogued.
|
|
|
|
The **layer value** (`surface`) is open, not the shape. §3 of the model does not
|
|
enumerate it; `INFD-IN-0006` asks `gate-house` whether the vocabulary is closed.
|
|
Do not change `layer:` in either file on your own initiative — that would
|
|
pre-empt the ruling. See `docs/gate-house-decision-request-layer-vocabulary.md`.
|
|
|
|
Hard rules, regardless of how the ruling lands:
|
|
|
|
- **Never decide.** No endpoint in this repository answers "may this actor do
|
|
X". That is `access-engine`, always and only (statute §6). This surface
|
|
renders a question and records a human's answer; a disposition is evidence of
|
|
an act, not an authorization verdict.
|
|
- **Never own approval state.** `approval-engine` is the sole mutator. Do not
|
|
cache validity, do not infer consumption from a decision record, and do not
|
|
request scope `approval:consume` — the engine refuses it for human principals
|
|
and consumption belongs to the PEP that causes the side effect
|
|
(`GH-DEC-2026-003`).
|
|
- **Never invent identity.** Every principal is authenticated by `key-cape`.
|
|
No local credential, no self-issued assurance level.
|
|
- **Never let awareness enter the signature.** `view_hash` covers only what the
|
|
person committed to. Proposed roles, other-tenant orientation and last-session
|
|
summaries are hashed separately and are unsigned unless explicitly promoted
|
|
into `awareness_promoted`.
|
|
- **Never let an agent bind.** An agent may assemble a memo; only a human
|
|
completes a disposition.
|
|
- **Never fork the schema.** A field added for approvals must be expressible for
|
|
an L0 login banner, or it does not go in the shared object.
|
|
- **Fail closed.** Degrading into showing a memo that cannot be bound is
|
|
acceptable. Degrading into binding without evidence is not.
|
|
- Remote hub: this host reaches State Hub on `http://127.0.0.1:8000` (primary
|
|
on railiance01). Do not use `127.0.0.1:18000` — that reverse tunnel is being
|
|
retired (`CUST-WP-0067`).
|
|
|
|
---
|
|
|
|
## Workplan Convention (ADR-001)
|
|
|
|
Work items originate as files in this repo — not in the hub. The hub is a
|
|
read/cache/index layer that rebuilds from files.
|
|
|
|
**File location:** `workplans/INFD-WP-NNNN-<slug>.md`
|
|
|
|
**Archived location:** finished workplans may move to
|
|
`workplans/archived/YYMMDD-INFD-WP-NNNN-<slug>.md`. The `YYMMDD` prefix is
|
|
the completion/archive date; the frontmatter `id` does not change.
|
|
|
|
**Ad Hoc Tasks:** small opportunistic fixes discovered during a session use
|
|
`workplans/ADHOC-YYYY-MM-DD.md`, workplan id
|
|
`INFD-WP-ADHOC-YYYY-MM-DD`, and task ids
|
|
`INFD-WP-ADHOC-YYYY-MM-DD-T01`, etc. `APPROVAL-WP` includes its final `-WP`
|
|
token. Unqualified historic `ADHOC-*` ids are grandfathered and must not be
|
|
copied into new records. Use this only for low-risk work completed directly;
|
|
create a normal workplan for anything needing analysis, design, approval,
|
|
dependencies, or multiple phases.
|
|
|
|
**Frontmatter:**
|
|
|
|
```yaml
|
|
---
|
|
id: INFD-WP-NNNN
|
|
type: workplan
|
|
title: "..."
|
|
domain: infotech
|
|
repo: approval-engine
|
|
status: proposed | ready | active | blocked | backlog | finished | archived
|
|
owner: codex
|
|
topic_slug: ...
|
|
created: "YYYY-MM-DD"
|
|
updated: "YYYY-MM-DD"
|
|
state_hub_workstream_id: "<uuid>" # fix-consistency — do not edit (legacy field name; workplan UUID)
|
|
---
|
|
```
|
|
|
|
Use `proposed` for a new draft, `ready` after review against current repo
|
|
state, and `finished` after implementation. `stalled` and `needs_review` are
|
|
derived health labels, not frontmatter statuses.
|
|
|
|
**Terminology:** workplan is the fleet term; `workstream` appears only in legacy
|
|
API/MCP/frontmatter bridges until `STATE-WP-0069` retires them — see
|
|
`the-custodian/canon/standards/workplan-terminology-fleet_v0.1.md`.
|
|
|
|
**Task block format** (one per `##` section):
|
|
|
|
```
|
|
## Task Title
|
|
|
|
` ` `task
|
|
id: INFD-WP-NNNN-T01
|
|
status: wait | todo | progress | done | cancel
|
|
priority: high | medium | low
|
|
state_hub_task_id: "<uuid>" # written by fix-consistency — do not edit
|
|
` ` `
|
|
|
|
Task description text.
|
|
```
|
|
|
|
Status progression: `todo` → `progress` → `done`; use `wait` for waiting/blocked work and `cancel` for stopped work.
|
|
|
|
**Residuals when finishing:** actionable leftovers become live work records
|
|
before `status: finished` — usually an intake (`origin: residual`,
|
|
`origin_ref: INFD-WP-NNNN`) or a spawned workplan. Residual is a *role*,
|
|
not a kind. Fleet list lives on State Hub, not in `SCOPE.md`.
|
|
|
|
To create a new workplan:
|
|
1. Write the file following the format above
|
|
2. Run `statehub fix-consistency` locally.
|
|
3. On a non-registrar C-06/C-11 skip, use the repo-manager fallback documented
|
|
above exactly once; never set registrar authority directly.
|