You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The concierge has an empty card, so goal and done_when are written with the body. The desk in repo mode takes a request in words, edits one file, runs terraform plan and check-no-new-access, renders the access delta and opens a PR with a PR-only token. The merge is the approval and the sandbox holds no cloud credential. The worked request is "site-publisher needs read on waterpark-artifacts". An unmapped requester is refused with the enrollment path, a boundary change with the platform path. The lesson demonstrates properties V, VIII and IX, closes prescription P13, and enacts estate.md scenario 6, the request.
Build
the AWS desk page and its panes, with spec.ts and protocol.ts carrying aws-state, aws-plan and aws-result (phase 3, repo mode in phase 4)
scripts/render-delta and scripts/proofs, because delta and proofs are never model output (decision 14)
the checked-in Fountain manifest applied with fountain apply, holding the Environment (terraform, awscli, jq, networking_type: limited), the agent, a repo-mode vault with only a fine-grained GITHUB_TOKEN, the teammate
decision 17 enrollment, an identity field on a human principal's leaf file plus a check that it is well formed, unique and never on a workload principal
SKILL.md golden paths covering both refusals and their escalation routes
Lesson body written to the page model and verified on a live Floci stack per the authoring checklist in project/page-model.md
Done when
done_when is empty. P13's check in prescriptions.md is the done when and reads "the same command an agent invokes produces the same PR with no agent involved, and a refusal names the escalation path." #17's last criterion lands here too, an agent answering from a bare checkout with the correct file path and PR flow.
design/agentic.md has a repo script, scripts/request, author the concierge's edit. aws-desk.md step 2 has the desk make the edit itself and lists no such script. Reconcile the two before the lesson is written. D1 also puts plan-tier read-only credentials in the sandbox, which contradicts decision 15.
Lesson
The concierge has an empty card, so
goalanddone_whenare written with the body. The desk in repo mode takes a request in words, edits one file, runsterraform planandcheck-no-new-access, renders the access delta and opens a PR with a PR-only token. The merge is the approval and the sandbox holds no cloud credential. The worked request is "site-publisher needs read on waterpark-artifacts". An unmapped requester is refused with the enrollment path, a boundary change with the platform path. The lesson demonstrates properties V, VIII and IX, closes prescription P13, and enacts estate.md scenario 6, the request.Build
spec.tsandprotocol.tscarryingaws-state,aws-planandaws-result(phase 3, repo mode in phase 4)scripts/render-deltaandscripts/proofs, becausedeltaandproofsare never model output (decision 14)fountain apply, holding the Environment (terraform,awscli,jq,networking_type: limited), the agent, a repo-mode vault with only a fine-grainedGITHUB_TOKEN, the teammateDone when
done_whenis empty. P13's check in prescriptions.md is the done when and reads "the same command an agent invokes produces the same PR with no agent involved, and a refusal names the escalation path." #17's last criterion lands here too, an agent answering from a bare checkout with the correct file path and PR flow.Source material
Decisions 14, 15, 17, 18 and 30 govern.
Open
design/agentic.md has a repo script,
scripts/request, author the concierge's edit. aws-desk.md step 2 has the desk make the edit itself and lists no such script. Reconcile the two before the lesson is written. D1 also puts plan-tier read-only credentials in the sandbox, which contradicts decision 15.