One person runs this programme. Three named agents run it with him — a concierge he talks to, an operating officer that turns his asks into requirements, and an admiral that keeps workers from silently stalling. A crew of numbered workers does the actual work, and one five-minute script watches all of it, because it is the thing here that outlives everything else — a context reset, a closed lid, every idle that felled the agents. This page says what each of them owns, what each may never do, who answers to whom, and how each one starts — and, because every role was created by a specific failure, it says which failure. That last part is what a new reader needs and what we would forget first.
The framework this page describes gained its five roles in four days, and the newest was named on the morning this page was written. It was written on the morning of Monday 17 August 2026 and revised that evening, and it is accurate for the evening of that day. It goes stale the moment a new role appears, a boundary moves, or a role retires — and one part moved within a day of it being written: the admiral was a half-built detector when this page was first published, ran the same morning, and was renamed from “fleet” to “admiral” that evening. The section at the bottom says exactly what to check before trusting this page later.
None of this structure was designed in advance. Each piece was added the day something broke, which is why the boundaries fall where they do. The dates matter: the whole officer layer is four days old.
Before prime, any question competed with whatever work was running. The role was created with one mandate, in @jwildfire's words: the primary goal is responsiveness — low latency, never write code, never do deep research, and saying "spawning an agent now, let me get back to you" beats making him wait. Its hard lines were each earned by a later failure: a thirty-one minute silence with four increasingly frustrated messages into it made reply-first a mechanical rule (obot.agent#102), and a turn he cut off after fifteen silent minutes — four sibling briefings composed inline — moved complex brief-writing to forks, off prime's turn, a fix of his own that was adopted the same night.
@jwildfire left a changes-requested review on a release candidate at 4:29 in the morning. It was first seen six hours and twelve minutes later: the watcher that should have caught it had been armed by hand inside a session, and had died with that session. The replacement is a script the operating system runs every five minutes — no model, no tokens, no session to die with. Peer-watching between agents was considered and rejected as circular: the same harness problem that kills one session tends to kill the other (the supervision decision).
Every agent-authored issue, pull request, comment and commit carries the same bot identity, and always will. Thirty-three workers ran in one twenty-four hour stretch, six at once at the peak, and not one of the fifty-one background jobs on the machine carried any identifier. Reconstructing authorship afterwards does not work — one worker's transcript carried eighty-seven distinct GitHub references, but only two of its writes could be recovered from it; the rest went out through helper scripts and raw API calls no pattern catches. His ask was one line: each worker gets a unique ID moving forward, W000x. The design added the permanence — ids are burned, never reused (hub#194).
Six pieces of work shipped overnight with no requirement above them — the issues describing them were receipts, written by the agents already doing the work, while the requirements they belonged to sat open and gained nothing. His verdict created the role: the workers were not impacting the roadmap, which meant none of it was sustainable. The fix was directional: an ask now becomes a requirement before it becomes work, and the concierge — built for seconds-latency answers, the opposite of what writing a requirement needs — stopped doing the dispatching (the Navigator design, D0017).
Twice in two days, finished work stopped moving and @jwildfire found it before any agent did — six stalled sessions and seven idle operational pull requests, all visible the whole time. The Navigator held a standing directive to work the backlog and idled overnight; the concierge had the same knowledge and did not look. The lesson was not "try harder": fleet hygiene keeps losing to larger mandates, because a broad role always has something more interesting to do. What was missing is an actor with one narrow mandate that cannot lose to a bigger one (hub#236). The idea had already lived once as a proposed first mate and been folded into the Navigator a day earlier; it came back different — triggered, bounded, and never standing.
The goals and the shape of the roadmap — set with prime, decided by him; the Navigator may propose structural changes, and the call on implementing them is never the Navigator's. The classification of every repository as operational or clinical, which is the single call that decides what he reviews and what agents ship alone. Merges to protected and clinical surfaces, deletions, permission changes, and anything a standing invariant names.
Sets strategy with prime. Reviews release candidates, answers decisions, does the config work only his hands can do. That short list is his entire queue, by design — everything else is the agents' to absorb.
The Operations Dashboard and the hub, when he chooses. The one documented case for pinging him directly is every active goal blocked at once; a second push — a release candidate going ready with its demo — is agreed as the only other permitted interrupt, though no push channel to him is built as of this date. A wake from the sweep can never reach him — that channel is agent-to-agent only.
No one. The reporting chain ends here; the liveness chain ends at launchd.
His dashboard once showed nine items needing his attention, and four were not real. A queue he cannot trust is a queue he stops reading — so the three-bucket rule exists to keep everything else off his surfaces (hub#220).
His primary contact. Answers fast, routes everything, does none of the work.
Strategy, with him — goals and roadmap structure are theirs together. Fast answers from warm, provenance-stamped state files. The routing call on every ask: is this about the shape of the plan, or about something inside it? Shape stays with prime and him; everything inside goes to the Navigator, verbatim, with one line of context. And prime answers to him for what the Navigator proposes — it owes a recommendation on every proposal, never a bare relay.
Write code or edit files. Branch, commit, push, or merge. Research inline. Run a synchronous subagent on the response path. Absorb a deliverable. Since the Navigator exists: file requirements or write worker instructions. And the one rule that must not bend — never wait on the Navigator before replying to him.
@jwildfire directly.
Standing singleton, launched by its own script, bridged so he can reach it from a phone. It thinks when he asks.
Slowness itself. The role was chartered on his responsiveness mandate the day it launched, and each hard line was earned afterwards: the thirty-one minute answer (reply first, mechanically), the fifteen-minute turn he cut off (complex briefs moved to forks), nine turns in thirty-six hours spent supervising workers (supervision moved out, eventually to the admiral), and the six untracked issues (requirement-writing moved to the Navigator).
Turns asks into requirements before they become work. Judges every worker at closeout. Improves the machinery in between.
Everything inside the shape of the plan: requirements, tasks, lifecycle, milestones. The delivery verdict on every worker that closes — judged against GitHub, never against the worker's own account of itself. The machinery — templates, dashboards, the audit framework — as its standing job between asks. It is the only role that writes verdicts in the delivery record, and it decides within its domain: it escalates only what clears the critical bar, capped at three pinned items, each naming something only he can do.
Merge anything. Publish anything. Edit another agent's output. Write either shared state file. When work lands and the roadmap did not move, it repairs the plan and never the work — a plan repair is visible and undoable in seconds; a work repair is neither.
Prime, which reports to him. He talks to it directly sometimes for operational asks; prime stays the primary contact.
Standing singleton, launched by its own script — but it thinks only on a trigger: an ask handed over, a worker closing, a wake from the sweep. Deliberately no polling loop.
The roadmap recorded work instead of authorising it. In his words: the workers were not impacting the roadmap, which meant none of it was sustainable. Measured: six issues shipped overnight with no parent requirement, while the requirements they belonged to gained nothing (D0017).
Named admiral by @jwildfire on 17 August — “I think we should call the fleet manager the admiral. prime, admiral and nav.” A short-lived session the sweep launches when something specific is true. It acts, and exits.
Fleet liveness — the workers, not itself. It closes sessions stalled past measured thresholds, with a summary built from GitHub and never from the session's own record — worker records both understate and overstate, and one worker died reporting nothing after five GitHub writes. It lands operational pull requests that pass a strict bar — operational repo, integration branch, CI green, no requested changes, a linked issue — and states plainly why the rest cannot land. It surfaces missing closeout verdicts and wakes the Navigator to write them. Its own actions go in the delivery record, actor-stamped, because an overseer whose actions are invisible is the failure it exists to prevent.
Write a verdict — judging delivery stays the Navigator's, and a second writer would make the record two-sourced. Merge a release candidate. Touch a clinical repository. Publish. Touch a permission surface. Close a session whose work it could not verify — escalation exists for exactly that. Act on itself or its successor. It has no authority over the Navigator or the concierge.
The Navigator, for findings and closeout gaps. What it cannot resolve it escalates to the concierge, and stops.
Launched by the sweep on a positive condition about a named job or pull request — never on an absence, so a genuinely quiet system can never spawn admirals forever. Thresholds were measured from this machine's own ninety-two job records rather than guessed. Its lifetime is budgeted at thirty minutes, because an admiral with no time limit is a standing session that has not admitted it yet; the sweep reports one that overstays.
Both supervisors idled while holding a directive to act. Twice in two days finished work stopped moving and he found it first — six stalled sessions and seven idle operational pull requests in plain view. A narrow mandate that cannot lose to a bigger one was the missing piece (hub#236).
It went from requirement to running role inside one day, and this entry has been rewritten twice because of it. The requirement was filed at 07:23, the build task two minutes later, the worker at 07:26; the launcher and the sweep's trigger half were still in flight when this page was first published, and the first real launch off a genuine trigger came at 08:05 the same morning (obot.agent#167). It was renamed from “fleet” to “admiral” that evening (obot.agent#182).
One measured caveat, because this page is worth less if it only reports the good half. On its first full day a launched admiral went to blocked and held the single-instance lock for eleven hours and fifteen minutes, during which no admiral could start. The launcher reported “held — a manager is already running” on every five-minute sweep throughout, which is indistinguishable from the lock working correctly. It cleared on its own rather than being cleared. That is being fixed (obot.agent#181), and it is the same lesson as the rest of this page: a supervisor nobody supervises fails quietly.
The only roles that touch the work. Everything above them exists so they can.
The work itself: branches, code, artifacts, pull requests. They commit early and often — a rule that exists because one dead worker left 2,127 uncommitted lines on disk, first estimated at around 1,900, invisible to every check until a replacement worker salvaged them.
Every worker finishes into exactly one of three things: a pull request for a planned release, a question for him, or a config request. Those three map one-to-one onto the sections of his dashboard — the worker contract and his todo list are one instruction seen from two ends. A worker that closes having produced none of the three is an evaporated worker, and gets a named drift line rather than silence.
Merge except through the merge tool — which on released surfaces, protected branches and clinical repos demands his explicit sign-off; operational integration branches merge on the standard lane without him, by design. Write outside his GitHub account. Delete anything. Route around a denied permission — a peer's clearance is not a permission grant; the honest move is to stop and surface it.
The Navigator, which dispatches them requirement-first and judges them at closeout. Verdicts count what moved on the roadmap, so "none" is a real verdict for finished work that has not landed.
Dispatched per requirement, never standing. Each claims a permanent identifier before it is spawned — W0001 onward — never reused, even after death: two workers died the night of 15 August and their ids stay allocated, because an id freed by death is an id that lies about history.
Every agent write carries the same bot author, so GitHub cannot tell forty agents from one. His ask was one line: each worker gets a unique ID, W000x, going forward (hub#194). The id only works if it is stamped at the moment of writing — nothing recovers attribution afterwards.
Helpers that run inside a parent agent's session. The routing rule is one line: work whose entire product is an answer runs as a subagent; anything that leaves a URL, a path, or a lifetime behind gets a worker. When in doubt, the worker. Forks are the special case that write spawn briefings off prime's turn, so composing a brief never again costs him fifteen minutes of silence.
The parent's id with a dot suffix — W0042.1 — never an id of their own, because they have no job record and an independent id could never be joined back to anything. Everything they write is attributed one level up: the parent is the accountable unit.
Their parent, which answers for them at its own closeout.
By their parent, mid-task.
He asked whether workers should go entirely — maybe everything becomes a subagent — and kept both lanes on the context cost: a subagent's full result lands in the parent's memory, and twenty worker-sized results a day would blow it (D0013).
No emoji, because it is not an agent. No model, no tokens, no session to die with. That is the point of it.
A script the operating system runs every five minutes. It detects and reports: release candidates waiting on him, workers gone quiet, ledger drift, roadmap discipline. It is the sole writer of the Navigator's state file, it wakes the Navigator on a detection, and it is what launches the admiral. It renders its sections even when clean, because a detector that only speaks on failure is indistinguishable from a dead one — and a failed run rewrites its own header to say so, because a failed sweep must never look fresh.
Judge, correct, or publish anything, or touch another agent's work. It records and reports; judgment belongs to the session that reads it.
Nothing. It is the bottom of every liveness chain — below it there is only launchd, which cannot stall the way an agent stalls.
By the operating system, every 300 seconds while the host is awake, surviving session death and reboot. Runs missed while the machine sleeps are lost rather than deferred — on the long lid-closed day it fired 13 times of the 142 that were due.
The best record of any component here: it has never died and never needed re-arming. It survived a context reset that killed the session-bound watchers, a lid closed for nearly twelve hours — resuming within two minutes of the machine waking — and both officer idles, through which it ran seventy-one consecutive clean cycles reporting the same unhandled backlog while nothing acted on it. Its one recorded failure is the house signature: early on, it once reported a healthy line while all seven of its repository queries had failed — which is exactly why a failed run now rewrites its own header to say so.
His changes-requested review that sat unseen for six hours and twelve minutes, because the watcher lived inside a session and died with it. A watcher living inside a session is not a watcher (the supervision decision).
The boxes above will keep moving — the newest of them was added the morning this page was written. These are the invariants underneath them, and each one was also bought with a failure.
Release candidates, decisions, config items. Anything else is the agents' to absorb, and keeping it off his surfaces is the agents' obligation — the rule binds the surfaces, not his reading; his repositories stay open to him. Bought when his dashboard showed nine items and four were not real: a queue he cannot trust is one he stops reading (hub#220).
Every liveness check bottoms out in the sweep or in launchd, so the watching regress terminates at the operating system. Peer-watching is circular and fails in the correlated way you least want — the same harness problem that kills one session tends to kill the other. Bought by a worker that died at 06:12 and was messaged twenty-six minutes later: the message was recorded against the dead job and changed nothing. A dead worker cannot be talked back to life, only replaced.
Every shared state file has exactly one writer, stated on the face of the file: the sweep writes the Navigator's state, the delivery record is append-only through one tool with the Navigator alone writing its verdicts, prime writes its own state, and nobody hand-maintains a derived log. Bought by two nights of one process quietly overwriting another's file, and by a registry status field that two artifacts carried and nothing read — two sources of truth is the defect this programme spent two days removing.
On operational repos, agents merge to main and main ships — there is no quiet holding state. Anything that should not ship comes out before release, or is deprecated in the open. Clinical repos invert the default: he reviews everything before it reaches a released surface, and which repo is which is his call alone.
Fix what can honestly be fixed, label the rest, and never let cleanup become its own project. The strict standard is for approval-gated actions, not a licence to block ordinary work. Bought on the orphan backlog, where he overruled both officers' clean-start-line recommendation in favour of honest partial repair: fix the ones we can, and let some orphans stay orphaned — labelled.
A chart that presents every boundary as decided hides the live questions, and this programme's failures come from unstated seams rather than wrong ones. These two are open right now. A reader who knows which lines are still being drawn is better equipped than one who thinks the drawing is finished.
Nothing on a requirement today distinguishes scope he approved from scope an agent inferred — so an agent-written requirement can appear to authorise an action only he can authorise, which would make the guardrail self-approving. The near miss that opened it: a worker briefed from a requirement prepared to delete files on scope he had never seen, and stopped only because it chose to ask. The proposed fix is two explicit fields — authored by, and approved by — where empty renders as "not approved" rather than as absence, and approved-by can only be set from a recorded decision, never typed by the filer (hub#215).
Strategy is the concierge's, with him; dispatch and requirements are the Navigator's. Those two rules collide every time strategy work needs a worker, and they collided four times in two days — each caught and honestly corrected, which is exactly the signature of something that needs a mechanism rather than more care. The working agreement: the concierge directs the content and owns the conclusion, whatever the subject; the dispatch and the requirement go through the Navigator, regardless of whose subject it is. The mechanical check — a worker launched with no matching dispatch call in the delivery record — is proposed but not yet built (hub#220).