← Chronos for CodexCONTENT HISTORY

Update to Chronos for Codex

Snapshot Sep 30, 2026 · 23:14 UTC · version 0.9.2

Collection source: not recorded for this historical snapshot.

WHAT CHANGED · RULE-BASED ANALYSIS

First saved snapshot

No earlier snapshot is available to establish a change.

Compare saved observations

Download comparison JSON
Full technical diff · 0 changed fields
Full snapshot data
{
  "name": "chronos-governor",
  "description": "Set up one dedicated Chronos Governor for passive supervision and Heartbeats, or coordinate bounded read tasks for low-complexity repository exploration, review, and verification with Codex native workers while limiting concurrency, context, attempts, health impact, and token use. Shared-folder write delegation is disabled.",
  "included_files": [
    {
      "relative_path": "agents/openai.yaml",
      "size_in_bytes": 256
    },
    {
      "relative_path": "scripts/governor.ps1",
      "size_in_bytes": 86399
    }
  ],
  "skill_md_contents": "---\nname: chronos-governor\ndescription: Set up one dedicated Chronos Governor for passive supervision and Heartbeats, or coordinate bounded read tasks for low-complexity repository exploration, review, and verification with Codex native workers while limiting concurrency, context, attempts, health impact, and token use. Shared-folder write delegation is disabled.\n---\n\n# Chronos Governor\n\nDelegate small read-only side tasks while the coordinator retains all edits,\narchitecture, safety decisions, verification, and acceptance. Use Codex native\nworkers only. Do not create a daemon, operating-system scheduler, external\nservice, or unbounded autonomous loop.\n\n## Automatic Supervision Bootstrap\n\nWhen the user asks to enable Chronos supervision, enable Heartbeats, or set up\nChronos fully, perform this setup once. The request authorizes one dedicated\nGovernor task and one host-owned recurrence for supervision and due Heartbeat\nevaluation; it does not authorize an operating-system scheduler, service,\nworker loop, or unbounded model use. Tell the user before creation that the\ndefault cadence is at most one Governor turn per hour while work is active and\none every six hours while idle. Worker tasks receive no recurring turns.\n\n**Hard gate:** Do not create or enable any Governor recurrence until native\ninitialization succeeds, supervision and Heartbeat status are readable, and one\ncomplete host-inventory cycle accounts for the selected Governor exactly once\nand returns `recurrenceEligible=true`. The raw inventory uses schema v1 when the\nhost includes its caller, or schema v2 with\n`callerVisibility=excluded_by_host` when the host task list omits the current\nGovernor; v2 normalization adds only that registry-verified cycle caller and\nmakes no second host-status call. Any other result requires zero active\ncurrent-key recurrences, verified from fresh host state. Never use a recurrence\nto retry, recover, or finish a failed setup.\n\nRead `hostEquivalenceKey` from supervision status. It is\n`chronos-supervision-v1:<opaque-installation-id>` and scopes the dedicated task,\nits compact assignment, and the matching automation to one local Chronos\ninstallation. Use the complete returned value; the prefix or exact automation\nname alone is not an equivalence key. Never copy a key from another machine.\n\nNative status also reports privacy-safe `codexHomeSource` and\n`codexHomeIdentity` fields. A nonempty `CODEX_HOME` is authoritative; different\ncanonical Codex homes are different installations. Stop before host mutation\nwhen the override is invalid, unavailable, or cannot be resolved consistently.\nThis includes a reparse point in any path component. Do not treat unscoped\nlegacy state as belonging to an explicit or environment-provided Codex home.\n\n1. Run `chronos.cmd -Action install-status`, compact supervision status, and\n   Heartbeat status. A confirmed enabled-source conflict or unreadable native\n   state fails closed before host mutation. Cached copies alone are not proof\n   of a conflict. Do not run the broad Inspector or packaged validation suites\n   during normal first-use setup; use Inspector only when compact status reports\n   a health problem or the user separately asks for diagnostics.\n2. Reconcile host state before trusting local state or running initialization.\n   Collect one all-same-name observation set containing every host\n   automation named exactly `Chronos Governor pulse`, its immutable automation\n   ID, creation time when available, target task, and equivalence key. Also run\n   `chronos.cmd -Action supervise -SupervisionAction status`. Observation does\n   not grant mutation authority.\n3. Derive a separate current-key mutation set. Include only automations whose\n   compact assignment contains the complete current `hostEquivalenceKey` and\n   confirms the dedicated role. Never mutate a same-name automation carrying a\n   different key or an unverified key. Build the host candidate set from live\n   targets in the current-key mutation set. Sort valid\n   automation candidates by creation time ascending, then immutable automation\n   ID and target task ID using ordinal comparison; a missing creation time sorts\n   after a present time. Every installer must select the first candidate. If no\n   valid automation exists, apply the same creation-time and immutable-ID order\n   to role-verified claimed Governor tasks. A name alone or a local claim alone\n   is not proof of role compatibility. If several candidates exist and stable\n   host IDs are unavailable, stop without creating another candidate or recovery\n   turn.\n4. If no valid Governor exists and the host exposes `create_thread`, create one\n   fresh task titled `Chronos Governor`. Do not fork the current task or copy its\n   history. Request `gpt-5.6-terra` with Medium reasoning only when the host\n   advertises that exact task-model choice. Field validation requires reliable\n   tool use and recovery judgment in the coordinator role. Never silently\n   substitute another model. After any creation, re-list all live, role-verified\n   current-key Governor tasks and apply the same stable creation-time and\n   immutable-ID ordering. Only the first deterministic setup contender may\n   proceed to recurrence mutation or initialization. Every other fresh-task\n   contender performs no local or host recurrence mutation, verifies that no\n   recurrence targets it, and stands down. If stable IDs are unavailable, no\n   contender proceeds.\n5. Before initializing the selected task, pause or delete every active\n   recurrence from the current-key mutation set, including\n   the deterministic winner from an earlier setup. Immediately before the first\n   mutation, repeat the all-same-name observation, current-key filtering, and\n   role-verified task listing in steps 2 and 3, then repeat the deterministic\n   setup-contender election. If a new recurrence or task changes the winner, or\n   the selected task is no longer first, skip `-SupervisionAction initialize`\n   entirely and enter the loser-verification branch below. Otherwise re-list host\n   state and prove\n   that zero current-key recurrences are active. Recompute the mutation set after\n   every host read or mutation and use at most three bounded mutation and\n   verification attempts. Leave foreign-key and unverified-key observations\n   unchanged. If zero cannot be proven, stop before initialization and create no\n   additional task, recurrence, or recovery turn.\n6. Have only the elected selected task run `-SupervisionAction initialize`. The\n   registry mutex fences only one machine and state root. If native initialization\n   returns `error=supervision_governor_conflict`, do not execute the generic\n   initialization-failure cleanup in step 7 and do not retry initialization.\n   Enter the same loser-verification branch below. Any other initialization error\n   proceeds to the fail-closed current-key cleanup in step 7. Use `-Force` only\n   after host task status proves the recorded owner is not live.\n\n   **Loser verification:** This branch has exactly two entries: pre-mutation\n   election loss in step 5, which skips initialization, or the literal native\n   `error=supervision_governor_conflict` in step 6. Re-read native status and host\n   state without recurrence mutation. Only when they identify one live,\n   role-verified winner with the complete current key may the loser stand down.\n   The loser creates no automation, mutates no recurrence belonging to the\n   verified winner, verifies that no recurrence targets the losing task and no\n   worker recurrence exists, and may be archived. The winning setup alone owns\n   recurrence convergence; after at most three bounded reads, final converged\n   state is exactly one current-key Governor recurrence. If the winner cannot be\n   verified within the bound, stop with no recurrence mutation and no recovery\n   turn. Never fall through from this branch to step 7.\n7. Before creating or enabling any recurrence, require the successful\n   initialization payload, re-read supervision and Heartbeat status, and run one\n   complete host-inventory `cycle` that accounts for the selected Governor\n   exactly once under the caller-visibility contract above. Continue only when\n   native state is writable, Heartbeat is readable,\n   the cycle returns `recurrenceEligible=true`, and its compact status includes\n   the selected Governor. Except for the two non-fallthrough loser-verification\n   entries above, if initialization, status, Heartbeat, or the complete\n   cycle fails, create no recurrence. Pause or delete every recurrence\n   in the current-key mutation set, including a pre-existing active recurrence,\n   then re-list host state and prove that zero current-key recurrences are\n   active. Leave foreign-key and unverified-key observations unchanged. Use at\n   most three bounded mutation and verification attempts. Retain only bounded\n   local recovery state. Do not schedule a recovery turn.\n8. Reconcile only current-key automations after the claim and complete inventory\n   cycle succeed. Update the\n   deterministic winner in place when possible, or create one when none exists.\n   Attach it to the selected task, pause or delete every non-winner, then re-list\n   host state. Recompute the same winner after every mutation. Use at most three\n   reconciliation attempts in one setup turn. Success requires this exact\n   postcondition: one live dedicated Governor, one active automation carrying\n   the complete current equivalence key, and zero active duplicates. On the third\n   failure, stop all further retries in that setup attempt. If any create, update,\n   duplicate cleanup, or exact postcondition verification fails, pause or delete\n   every recurrence in the recomputed current-key mutation set, re-list host\n   state, and prove zero current-key recurrences are active within three bounded\n   attempts. Schedule no recovery turn. Never mutate a foreign or unverified key,\n   turn routine convergence failure into a user chore, or rely on a create or\n   allow result alone as proof.\n9. Before `discover` on Governor cycles zero and one, repeat the host candidate\n   scan and exact postcondition check. This catches a concurrently created\n   recurrence that was not visible during setup. A non-winning Governor must\n   pause or delete its own recurrence, verify that the deterministic winner\n   remains active, and stand down. If the losing task itself owns the local\n   claim, use the normal two-phase release only after its recurrence is proven\n   absent; otherwise do not mutate the local claim. Never clear another task's\n   claim. After cycle one, do not rescan all host\n   automations during normal cycles unless claim loss, rotation, or recovery\n   requires reconciliation.\n10. Use the cadence returned by supervision: 60 minutes with active monitored\n   work and 360 minutes while idle. The setup is an explicit opt-in to those\n   recurring model turns. A Governor is bounded to 336 cycles or 14 days. At the\n   bound, perform a verified fresh-task handoff when host tools support it;\n   otherwise pause the recurrence and retain the reason in Governor-local state.\n11. If task creation is unavailable, use the current task only when the user's\n   setup request is explicit. State that it is the fallback and do not duplicate\n   the current conversation through `fork_thread`.\n\nThis order is also the recovery protocol. It converges after a crash between\ntask creation, claim, or automation creation; after a stale local claim; and\nafter local registry loss. Unclaimed extra tasks do not get a recurrence.\nDuplicate recurrences are paused or removed before setup is reported complete.\nThe scoped host equivalence key and stable ordering are the same-installation\nownership fence; the local mutex is not. Different machines have different\nopaque keys and therefore retain separate Governors for their separate local\nregistries.\n\nThe dedicated task should receive this compact, self-contained assignment:\n\n```text\nChronos equivalence key: <complete hostEquivalenceKey from status>. Act as the\nsingle Chronos Governor. Maintain one verified Governor recurrence and zero\nworker recurrences.\n\nStart each pulse by resuming native intervention state. Follow only the returned\npermitted next action. Then use one complete host task inventory as liveness\nauthority. Write only opaque IDs, safe status categories, optional opaque\ngenerations, capture time, and completeness to one bounded TEMP file. Run one\nnative supervision cycle, then remove the file.\n\nEvaluate Heartbeats only from a current schema-v2 normalized collector snapshot\nwith stable sourceEpoch, increasing sourceSequence, and explicit coverage for all\neight public families. A Heartbeat status read without input is prior-state\ninspection, not evaluation. If evidence is unavailable, keep that family partial\nor unsupported. Never describe unevaluated families as healthy or absent.\n\nRun Inspector only when health is unknown and this pulse will extend long-running\nwork, when the user reports degradation, or before and after long-running parallel\nwork. Feed only its compact output to the collector, with the authorized-evidence\nflag. Do not run Inspector on every routine pulse or infer its fields from task\nliveness.\n\nFor a new, materially worse, or eligible resolution transition, use only native\nplan, claim, send, and record. Contact one exact verified live target with the\nreturned fixed template. Normal cycles do not wake tasks. Never read transcripts,\nedit repositories, create a worker recurrence, or ask the user to relay routine\nremediation.\n\nApply a returned Governor-local cadence action only to this recurrence and verify\nit. Use 60 minutes for active work or 360 minutes while idle. Never create a\nsecond recurrence.\n```\n\nDo not report full setup complete until all observable postconditions hold:\nthe expected installed source is active, native status is healthy or explicitly\ndegraded, exactly one live dedicated Governor owns exactly one active matching\nrecurrence, Heartbeat status is readable from that Governor, its `evaluation` is\nreported as `observed`, `partial`, or `unsupported`, and no worker task has a\nrecurrence. `unsupported` is a valid coverage result, not a healthy result.\nReturn a compact setup summary with those fields. Do not make\nthe user infer success from `governorClaimed` or another internal state name.\nInitialization, status, Heartbeat, or inventory failure is a hard zero-recurrence\npostcondition. It applies to matching recurrences that predate the setup attempt\nas well as any created during it; it is not a reason to schedule a retrying\nGovernor.\n\nPlugin monitoring hooks register `SessionStart`, `SessionEnd`,\n`SubagentStart`, `SubagentStop`, and one `Stop` signal after each completed main\nturn. Non-terminal handlers request asynchronous execution where the host\nsupports it; `SessionEnd` is synchronous. When Codex dispatches them, they run\nheadless, return no model context, and create no model turn. Hook trust is\noptional acceleration and must never block setup. If hooks are disabled,\nuntrusted, or not dispatched, continue with one complete compact host task-list inventory and reconcile\nit through `-SupervisionAction cycle`; do not ask the user to register\nor relay tasks. Brief registry contention uses a bounded protected fallback event;\n`status` and `discover` reconcile and remove it under the registry lock. Never\nbypass hook trust.\n\nEvery Governor pulse starts by calling `-HeartbeatInterventionAction list` with\nthis Governor ID. Resume or retain each record only through its returned\n`permittedNextAction`. Do this before fresh detector evaluation. Reclaim only an\nexpired claimed send; native state changes it to `delivery_unknown`, never a\nblind retry.\n\nThen apply the bounded cycle-zero/one host convergence check when required and\ncall the host task list exactly once. The inventory must be\ncomplete for the cycle to advance. Write only opaque task\nIDs, safe status categories, optional opaque generations, capture time, and a\ncompleteness flag to a bounded JSON file under `%TEMP%`; schema v1 requires the\nGovernor in `tasks`. When the host list excludes its current caller, schema v2\nmust declare `callerVisibility=excluded_by_host` and omit the Governor from\n`tasks`; Chronos then adds that registry-verified cycle caller intrinsically.\nNever infer caller exclusion, supplement it from a second host call, or write titles,\npaths, or transcript content. Run `-SupervisionAction cycle` with that file,\nremove the file, and treat the returned inventory as liveness authority. Verify\nthat `hostInventoryCycle` advanced once, `hostInventoryRawObserved` matches the\none raw list, and `hostTaskStatuses` contains one hash-only normalized entry for\nevery listed task plus exactly one intrinsic Governor only in caller-excluded\nschema v2. The host inventory proves discovery and liveness only. It does not\nprove Heartbeat progress, approval health, quota state, rule health, SQLite\nchurn, tests, Git state, or machine health.\n\nCreate a separate bounded Heartbeat collector file under `%TEMP%`. Use schema\nv2, one Governor-local opaque `sourceEpoch`, an increasing `sourceSequence`, and\nan explicit `observed`, `partial`, or `unsupported` label for each of the eight\npublic families. Include only current compatible evidence. Every accepted\nschema-v2 snapshot advances the source watermark even when a family is not due\nor its coverage is partial or unsupported. Never substitute a zero for an\nunavailable or malformed field. Run `chronos.cmd -Action heartbeat -HeartbeatInputPath <collector-file>`,\nthen remove the file. A plain\n`chronos.cmd -Action heartbeat` call reads prior state only. It does not count as\nthe current pulse's evaluation. Require compact status to report\n`evaluation=observed`, `partial`, or `unsupported` and retain all unsupported\nfamily labels.\n\nInspector is a bounded diagnostic source, not the hourly workload. Run it only\nwhen health is unknown and the pulse will extend long-running work, when the\nuser reports degradation, or before and after long-running parallel work. Save\nonly the compact `CHRONOS` output to a bounded TEMP file. Add it to the same\nschema-v2 collector call with `-HeartbeatInspectorOutputPath` and\n`-HeartbeatInspectorAuthorized`, then remove it. The adapter requires compatible\nrun provenance. Without that authorized output, Inspector-derived approval,\nreview, quota, rollout, SQLite, rule, and resource evidence stays unavailable;\ntask liveness cannot supply it.\n\nUse compact `wait_threads` snapshots from the rotating `checkBatch`, which\ncontains at most eight entries. If host inventory is unavailable, fail closed\nfor task-directed sends, retain pending state, and retry next cycle without a\nuser handoff. If an ended registry entry is confirmed live by the host, use\n`-SupervisionAction confirm-active -SupervisionSubjectId <id>`; a delayed start\nhook cannot revive terminal state by itself. Do not repeatedly read full tasks\nor transcripts. A normal cycle must end without messaging monitored tasks;\n`taskWakePolicy=intervention_claim_required` is the native postcondition. If\n`rotationRequired=true`, reconcile a fresh Governor or pause the recurrence\nbefore the current cycle ends. See the public\n[supervision contract](https://github.com/FaxanFM/chronos/blob/main/docs/SUPERVISION.md).\n\nBefore building a Governor `usage` record, run `chronos.cmd -Action heartbeat`\nonce and copy its five named counters exactly: `completedCycles`,\n`stateChanges`, `acknowledgedEvents`, `failedCycles`, and `duplicateRuns`.\nCombine them only with the current compact Inspector usage fields for this\nGovernor. Never synthesize a missing counter as zero. If any counter or usage\nfield is unavailable, mark usage coverage `partial` or `unsupported` and do not\nopen or resolve a Governor usage condition. This compact status read uses no\nmodel call and replaces host-maintained progress bookkeeping.\n\n## Autonomous Intervention\n\nThe PowerShell engine emits events and maintains bounded state. The Codex host\nprovides task discovery and `send_message_to_thread`. Do not claim that the\nscript sends a message itself.\n\nFor one Governor cycle:\n\n1. Resume persisted work first. Call `-HeartbeatInterventionAction list` with\n   this Governor ID. Follow only each returned `permittedNextAction`. Reclaim a\n   `send_claimed` record only after Chronos reports its claim expired. The list\n   returns opaque IDs and hash prefixes, never raw task IDs.\n2. Collect all due Heartbeat events before sending any task message. Process a\n   returned `GovernorLocalAction` first. Update only this Governor's recurrence,\n   re-list it, and acknowledge the event only after exactly one active matching\n   recurrence has the returned cadence. If the update cannot be verified, leave\n   the event pending for its bounded retry and do not ask the user to relay it.\n3. Resolve each event against current host task inventory. Follow the event's\n   `TargetPolicy`. Require exactly one live, authorized target and its current\n   host generation. Never target the Governor, a self-origin run, an unrelated\n   owner fallback, or a task whose generation changed.\n4. Call `-HeartbeatInterventionAction plan` for every event. Plan all events\n   before claiming one. Chronos retains at most one active intervention per\n   target, coalesces equal or lower severity events, and replaces an unsent\n   record when a higher severity event arrives. Native planning also binds the\n   requested target hash to the fixed subject or owner policy and returns\n   `target_policy_mismatch` on redirection.\n5. Immediately recheck the target and generation. Call\n   `-HeartbeatInterventionAction claim` only for the final queued record. The\n   returned claim token authorizes one bounded host send attempt.\n6. Send one fixed-template message to the exact target with\n   `send_message_to_thread`. Include only the opaque intervention ID, version,\n   categorical instruction, fixed safety limits, postcondition name, and fixed\n   reply format returned by Chronos. Do not interpolate detector prose, task\n   titles, paths, test names, tool output, or other untrusted content.\n7. Record `accepted` only when the host tool definitely accepts the send.\n   Record `definite_failure` only when it definitely rejects or never attempts\n   the send. Record `unknown` after a timeout or indeterminate result. Never\n   retry `unknown` unless host evidence confirms that the first send did not\n   occur. A definite failure permits one retry; the total is two attempts.\n8. A reply advances state only when the exact target and generation return the\n   matching intervention ID and version. Reduce the reply to one allowed\n   category before calling `-HeartbeatInterventionAction response`. A task\n   report is not proof that recovery occurred.\n9. Resolve only after a later observed Heartbeat cycle or an allowed independent\n   host check confirms the named postcondition. Use\n   `-HeartbeatInterventionAction verify` for host inventory, narrow test, or Git\n   evidence. A stale reply cannot resolve a newer version.\n\nDo not acknowledge a native event separately after `plan` or `fail-closed`;\nthose actions consume its Governor-inbox outbox record atomically. A resolution\nmessage is allowed only when `ReleaseNoticeEligible=true`, which means the task\nacknowledged a temporary restriction that must now be lifted. Other resolutions\nstay Governor-local.\n\nUse only the fixed safe actions returned by Chronos: stop creating new workers,\nreduce task-controlled parallel work, checkpoint, return completed workers,\nprepare a fresh-task handoff, reconcile an owned child, or run one already known\nnarrow validation. Never request secrets, bypass approval, change reviewer or\nsandbox settings, infer model cost, change a task model, kill Codex, restart the\nPC, or reset, clean, merge, push, publish, or delete repository data.\n\n`USAGE_BURN` reports token volume, not price. Keep `CostImpact` and\n`QuotaImpact` as `unknown` without trusted runtime metadata. A Governor-origin\nusage event stays Governor-local. It may target another task only when a second\nevent proves stall, review amplification, or machine degradation for the same\nsubject within the same observation window. It can never target the Governor.\n`throttle_recurrence_to_idle_cadence` means set only the Governor recurrence to\n360 minutes and verify the one-recurrence postcondition. On\n`restore_supervision_recommended_cadence`, reconcile the 60-minute active or\n360-minute idle cadence and verify it before closing the local action.\n\nWhen ownership is ambiguous, the target is not live, transport is unavailable,\nor user authority is required, call `-HeartbeatInterventionAction fail-closed`.\nDo not broadcast, choose an arbitrary target, or manufacture a user action.\n\nTo disable supervision, first call `release` without confirmation and follow\nits host cleanup instruction. Pause or delete every verified current-key\nrecurrence, leave foreign and unverified keys unchanged, verify that no\ncurrent-key recurrence remains active, then call `release` again with\n`-SupervisionConfirmRecurrenceStopped`. Never clear the claim first.\n\n## Boundary\n\nGovernor is an advisory coordination aid, not a sandbox or security boundary.\nIts temporary state is worker-reachable, prompt restrictions are not runtime\npermissions, and its Git-visible fingerprint cannot prove that no filesystem\neffect occurred. Rely on the active Codex sandbox for actual permissions.\n\nDefaults:\n\n- At most two active read-task workers.\n- Shared-folder write workers disabled.\n- At most three attempts per task and one correction.\n- Delegation depth one by coordinator policy.\n- Worker-created agents prohibited by prompt contract, not runtime enforcement.\n- Full parent history disabled with `fork_turns=\"none\"` on Multi-Agent V2.\n- Final coordinator verification required.\n- Automatic merge, reset, cleanup, commit, and deletion disabled.\n- Worker-task recurrence and per-turn monitoring disabled.\n\n## Keep With The Coordinator\n\nDo not delegate edits, architecture, authentication, authorization, payments,\nsecrets, security boundaries, migrations, CI, dependencies, lockfiles, central\nrouting, deployment, publishing, merge, release, destructive operations, or\nambiguous work. Delegate only a concrete read-only side task that can proceed\nwhile the coordinator continues useful non-overlapping work.\n\n## Runtime Routing\n\nBefore calling Governor `status` or `plan`, inspect the active `spawn_agent`\ntool contract. Delegation requires Multi-Agent V2 with\n`fork_turns=\"none\"`. If that field or value is not advertised, do not reserve a\nplan, create a lease, or spawn a worker; complete and verify the work with the\ncoordinator. This clean fallback is a successful bounded outcome.\n\nWhen V2 is available, read the active tool's advertised models and supported\nreasoning efforts for this task. Encode that current inventory in runtime order:\n\n```text\nmodel-a=low,medium,high;model-b=low,medium\n```\n\nInclude `|cost=N` only when the runtime itself advertises a numeric rank for\nevery compatible model. Pass the result as `-RuntimeModels`. Never infer cost\nfrom a model name or reuse inventory from another task or installation.\n\nUse low effort for exploration, documentation review, formatting review, and\nfocused verification. Use medium only for nontrivial code review or test\nanalysis. If inventory is missing, malformed, or incompatible, keep the work\nwith the coordinator.\n\n## Workflow\n\n### 1. Inspect Once When Needed\n\nUse the Chronos inspector once when health is unknown and degradation matters.\nInterpret `machineHealth` separately from `resourceDiagnosticLevel`,\n`overallDiagnosticLevel`, and quota/rule findings. At machine `CRITICAL`, do not\ncreate a worker. Never terminate work because of a Chronos result.\n\n### 2. Preflight V2 Before Planning\n\nConfirm that the active `spawn_agent` schema accepts `fork_turns=\"none\"`. If it\ndoes not, stop the delegation workflow before any Governor `status` or `plan`,\ncomplete the read task locally, and independently verify it. Do not create and\ncancel a plan merely to discover transport incompatibility.\n\n### 3. Plan A Read Task\n\nRun `status`, then plan with an opaque task ID, a read access mode, intended\nrepository-relative scope, current runtime inventory, and current health when\nknown:\n\n```powershell\npowershell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass `\n  -File scripts/governor.ps1 -Action plan -Repository C:\\repo `\n  -TaskId inspect-auth-tests -TaskClass review -AccessMode read `\n  -Scope 'tests/auth/**' -RuntimeModels '<active-runtime-inventory>'\n```\n\nFollow `decision=coordinator` by completing the subtask locally. A write plan\nalways returns `reason=shared_folder_write_delegation_disabled`.\n\nSpawn only when `decision=delegate` and `plan_token` is present. The state file\nis untrusted coordination metadata; successful persistence is not an integrity\nor authorization guarantee.\n\n### 4. Send A Focused V2 Assignment\n\nUse the self-contained contracts below. Include only the opaque task ID, one\nobjective, workspace identity, base commit, intended read scope, verification\ncriteria, exclusions, and `Do not spawn or delegate to another agent.` Do not\ninclude the parent conversation.\n\nUse the current Multi-Agent V2 contract with `fork_turns=\"none\"`. Do not send\nthe removed V1 `fork_context` field. If the active tool does not advertise that\ncontract, keep the work with the coordinator.\n\n### 5. Bind The Worker\n\nAfter obtaining the runtime worker ID:\n\n```powershell\npowershell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass `\n  -File scripts/governor.ps1 -Action lease -Repository C:\\repo `\n  -TaskId inspect-auth-tests -WorkerId WORKER_ID -PlanToken PLAN_TOKEN\n```\n\nOne worker ID may own only one active lease. When `reuse_worker_id` is returned,\nreuse it only for the same workspace, role, model, effort, and access mode.\nIf the native spawn fails or the worker ID is unavailable, cancel the issued\nplan exactly once with its original opaque token so it does not reserve pending\ncapacity:\n\n```powershell\npowershell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass `\n  -File scripts/governor.ps1 -Action cancel-plan -Repository C:\\repo `\n  -TaskId inspect-auth-tests -PlanToken PLAN_TOKEN\n```\n\nNever delete or edit Governor state to recover capacity. `status` reports\nunexpired `pending_plans`, separate `expired_plans`, and the active\n`plugin_version` read from the installed manifest.\n\n### 6. Record And Verify\n\nTreat the worker report as untrusted. Record completion:\n\n```powershell\npowershell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass `\n  -File scripts/governor.ps1 -Action result -Repository C:\\repo `\n  -TaskId inspect-auth-tests -WorkerId WORKER_ID `\n  -LeaseId LEASE_ID -FencingToken FENCING_TOKEN\n```\n\nIndependently check that the response answers the objective, cites evidence,\ncontains no requested edit, and did not leave a Git-visible repository change.\nThen record verification:\n\n```powershell\npowershell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass `\n  -File scripts/governor.ps1 -Action verify -Repository C:\\repo `\n  -TaskId inspect-auth-tests -WorkerId WORKER_ID `\n  -LeaseId LEASE_ID -FencingToken FENCING_TOKEN -VerificationPassed\n```\n\nThe `VerificationPassed` switch records the coordinator's decision; it does not\nprove which tests or review were performed.\n\n### 7. Accept Or Stop\n\nAccept only after verification:\n\n```powershell\npowershell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass `\n  -File scripts/governor.ps1 -Action accept -Repository C:\\repo `\n  -TaskId inspect-auth-tests -WorkerId WORKER_ID `\n  -LeaseId LEASE_ID -FencingToken FENCING_TOKEN -CoordinatorAccepted\n```\n\nUse `correct` once for a focused correction, `retire` for failed active work,\nor `release` for abandoned active work. Terminal leases cannot be rewritten.\nClose the native worker after acceptance or retirement.\n\n## State And Privacy\n\nState lives at `Chronos/Governor/<repository-hash>/governor-state.json` beneath\nthe current user's Windows temporary directory. It contains only opaque IDs,\nhashes, base commits, relative scopes, model labels, policy limits, counters,\nstatus, and timestamps. It is not authenticated and can be tampered with by a\nprocess that can reach the file. Never use it as an authorization record.\n\nGovernor does not store prompts, responses, objectives, source, diffs, commands,\ntool arguments, output, credentials, usernames, environment values, or absolute\npaths. It creates no telemetry and sends no state remotely.\n\n## Common Results\n\n- `shared_folder_write_delegation_disabled`: perform the edit as coordinator.\n- `model_inventory_unavailable`: refresh the active tool inventory.\n- `state_store_unwritable`: no worker was authorized; continue locally.\n- `state_store_unreadable` or `state_read_failed`: continue locally and report\n  the compact result; do not delete or edit state.\n- `state_invalid_json` or `state_schema_invalid`: preserve the state and report\n  the compact result; do not overwrite it to force recovery.\n- `state_lock_unavailable`: wait briefly or continue locally; do not delete it.\n- `worker_already_leased`: finish or release the worker's active lease.\n- `plan_token_mismatch`, `plan_expired`, or `plan_already_consumed`: plan again.\n- `cancel-plan` is terminal; a canceled token cannot later create a lease.\n- `invalid_worker_id`: use the exact runtime ID; `/root/name` is supported.\n- `workspace_fingerprint_limit_exceeded`: stop delegation and inspect locally.\n- `read_worker_modified_workspace`: preserve and inspect the changes; do not\n  attribute them automatically.\n- `invalid_lifecycle_transition`: preserve the terminal record.\n- `internal_error`: continue locally and report only the compact result. The\n  privacy-safe `failure_stage` and `exception_type` identify the failing code\n  boundary without including paths, exception text, or state content.\n\n## Honest Limits\n\n- Read-only is a requested access mode plus a Git-visible warning check, not a\n  verified filesystem property.\n- Delegation depth is policy, not a removed worker capability.\n- Effective model identity is unverified unless the runtime exposes trusted\n  evidence.\n- No authenticated broker or disposable worker repository is included in this\n  release. Those are prerequisites before write delegation can return.\n\n## Delegation Contracts\n\nThese contracts bound read-only work between the coordinator and a worker. The\ncoordinator remains responsible for decomposition, verification, acceptance,\ncorrection, retry, and integration.\n\n### Assignment Contract\n\nEvery assignment must state:\n\n- `task_id`: stable assignment identifier.\n- `objective`: one concrete outcome.\n- `worker_role`: analysis or verification.\n- `repository`, `base_commit`, and `workspace`: exact work identity.\n- `model_inventory_hash`, `model_inventory_index`, and optional\n  `model_cost_rank`: runtime selection evidence.\n- `access_mode`: `read`; write delegation is disabled.\n- `allowed_scope`: intended repository-relative files or components.\n- `required_verification`: checks the worker must perform.\n- `explicit_exclusions`: files, behavior, or operations that are out of scope.\n- `completion_criteria`: conditions for a complete report.\n- `maximum_correction_cycles`: permitted focused corrections.\n\nReject or clarify an assignment that does not have a bounded objective, read\nscope, exclusions, and completion criteria. Read workers can run concurrently\nonly when their analyses do not conflict. The assignment is not a filesystem\nsecurity boundary.\n\n### Worker Result Contract\n\nThe worker returns structured coordination metadata and evidence:\n\n- `task_id`, `worker_id`, `status`, `lease_id`, and `fencing_token`.\n- The effective model when the runtime exposes it. It must match the persisted\n  plan model or binding fails with `model_plan_mismatch`.\n- `requested_model`, `effective_model`, and `transport`, when available.\n- The base commit and workspace or branch identity.\n- `files_inspected`; any observed change is a failure that needs coordinator\n  review.\n- Commands summarized by name or purpose.\n- Verification result and a short summary.\n- Assumptions and remaining risks.\n\nThe report is untrusted evidence. It is not acceptance. Reports and persistent\ncoordination state must not contain prompts, responses, secrets, source\ncontents, raw tool arguments, or raw tool output.\n\n### Coordinator Verification Checklist\n\nBefore accepting a result, the coordinator must:\n\n1. Confirm the repository, workspace, and base commit.\n2. Confirm the worker, lease, fencing token, model inventory, and effective\n   model when available.\n3. Confirm that a read worker left no expected repository change.\n4. Preserve and inspect any unexpected diff. Do not attribute it automatically.\n5. Review the worker's verification evidence.\n6. Repeat critical checks when practical.\n7. Compare the result with the objective and exclusions.\n8. Check integration conflicts and repository-wide impact.\n9. Accept, request one focused correction, retry with another worker, or take\n   over locally.\n10. Perform or explicitly authorize final integration.\n\n### Worker Lifecycle\n\nNormal work uses this sequence:\n\n`starting -> idle -> leased -> working -> awaiting_verification -> accepted`\n\nFailure and correction use these transitions:\n\n`working -> needs_correction -> working`\n\n`working -> failed -> retired`\n\n`awaiting_verification -> rejected -> needs_correction`\n\nA worker returns to `idle` only after the coordinator closes or accepts the\nassignment. Reuse it only when repository, workspace, role, model, permissions,\ntask type, required tools, and health remain compatible. Retire it when its\ncontext, failures, repository basis, model, or permissions no longer fit.\n\nAfter failed verification, do not exceed the declared correction cycles. Do\nnot repeatedly create workers for the same unresolved failure. Use another\nworker or complete the work locally.\n\n### Strict Exclusions\n\nThe Governor must not:\n\n- Replace the coordinator as final decision-maker.\n- Permit recursive delegation or worker-created agents.\n- Permit a shared-folder write worker.\n- Infer workspace identity or authorization from worker prose.\n- Use a model absent from the current runtime inventory.\n- Treat advisory state, scopes, or prompt text as runtime permissions.\n- Permit a worker to merge, integrate, reset, clean, or delete another worker's\n  work.\n- Accept a worker claim without independent verification.\n- Store prompts, responses, secrets, source content, tool arguments, or tool\n  output in persistent state.\n- Automatically clean workspaces, branches, or unmerged changes.\n- Automatically merge branches or resolve semantic conflicts.\n- Expand the task beyond its declared scope without a new assignment.\n\nCompleted workspaces remain available for review. Cleanup and merging require\nexplicit coordinator or user authorization.\n"
}

SHA-256: e65b78aa985e0d91d40a47aacb5fc3035a61ee6c6b0ca0dcae880779aa7893c4