| name | agentic |
| position | none |
| description | Write a SLICE's agentic lens as a grounding doc (agentic.md) — the is-it-an-agent gate, the load weights (cognitive / creative / logistical on a low→ultra scale), and the controls (guardrails, handoff). The MIDDLE of the FUNCTIONAL realize pipe (ux → agentic → marketing), run on a shaped slice. A deterministic slice comes out "not an agent", stated plainly. Reads the hub from the spine (functionality grounding + profile), never another lens. Writes only the slice's agentic lens, in place on the live model. |
| user-invocable | true |
agentic
Write a shaped slice's agentic lens as the grounding doc agentic.md: whether the slice is
(or contains) an agent at all, and if so how much human load it offloads on three axes and what
controls bound it. A deterministic read/compute slice comes out "not an agent", stated plainly.
/agentic reads the slice's hub — its functionalities' grounding docs plus the profile (both
from the spine) — and never another realize lens.
Pipeline position: none. /agentic is the MIDDLE of the functional realize pipe (ux → agentic →
marketing): it runs on the branch /ux already started, injects no start-change head and no close
sequence, stops when its work is done, and leaves the branch for /marketing. The close belongs to
/marketing. It writes the persistent product model (the slice's agentic lens) directly, in place
on the already-started branch — there is no draft copy and no apply/promote step; review is the
branch git diff and the pipeline's end PR. (#437, #500, ADR 026)
Write discipline (ADR 026, standards/rules/direct-model-write.md). The LLM authoring skill
(author-agentic-lens) writes ONLY the per-node lens doc agentic.md straight to the live model
(overwriting a prior lens on a re-run); the one shared-file concern — the slice's decisions/ — is
done by the deterministic keyed persist script (persist_agentic.py), in place, keyed to the target
slice so it cannot write outside the slice's decisions folder, reading the manifest for what to
apply. The model tree is asserted clean at entry (F14) and the play commits its own model delta at
close (C13), so the working-tree diff vs HEAD is exactly this run's delta. Containment is a
post-write scoped guard (scoped_write_guard.py), not a draft.
Compiled From
This play was compiled from the agentic ICE (reference/ice.md) by play-editor (#466 Batch C;
#467 Batch B — the checkpoint upgraded to a conditional learned gate, see gate-config.md; #500 —
migrated to direct-model-write per ADR 026 and standards/rules/direct-model-write.md). Intent
defines constraints (C1–C13) and failure conditions (F1–F14); the expectation defines success
scenarios (S1–S6), a Done means (D1–D3, baked to stop-condition.yaml), and one recovery entry per
failure condition. To modify this play, update reference/ice.md and recompile with play-editor.
Do NOT edit this file manually — it is a compiled artifact.
Role
You are the orchestrator. You own the workflow and step order. You delegate the domain work —
authoring the agentic lens grounding doc — to the product-os-keeper agent via a JSON contract over
files on disk, and you run the mechanical work (readiness/hub resolution, the shape linter, the
content-quality eval, grounding + coverage, KB grounding, the keyed in-place persist, and the
post-write scoped guard) through bundled scripts and an isolated judge. You never write the lens
yourself, and you never COMMIT the model delta before the single checkpoint (C11) resolves — a typed
approval, a recorded config skip, or a recorded policy auto-pass.
Forbidden: hand-writing the lens or a decision; writing anything other than this slice's
agentic.md and a decision (C2); reading or grounding on another realize lens (C7); manufacturing
an agent where the functionalities don't warrant it (C8); persisting a decision by any route other
than scripts/persist_agentic.py; committing the model delta before the checkpoint gate resolves;
running against a dirty product-os tree (C13/F14); closing COMPLETED without the stop-condition
verdict held (C12).
Agent boundaries:
| Agent | Domain | Skill it invokes | Phases |
|---|
product-os-keeper | Author the slice's agentic lens (gate + weights + controls) straight to the live model from the hub + KB framing grounding; emit any decision into the manifest | kb-search, author-agentic-lens | Draft |
product-os-keeper is the single domain agent this play uses (1 of the ≤5 budget). The
content-quality judge always runs as an isolated, clean-context sub-agent (optionally on a configured
different model) — never the orchestrator's own context.
Pre-flight
| Check | Constraint | Action on Failure |
|---|
Resolve config + product_base (.garura/core/config.yaml) | — | Hard halt |
Resolve grounding-eval.judge (optional model override) | C4 | Default: sub-agent on the session model |
Slice ready + hub resolves (check_ready_slice.py) | C1 | Hard halt (REC1) |
Clean model tree — git status --porcelain -- <product_base>product-os is empty | C13/F14 | Hard halt (REC14) |
Resolve the pre-flight facts mechanically with the bundled resolver:
python3 scripts/preflight.py --play agentic --config .garura/core/config.yaml
Then resolve the slice and its hub from the spine — the readiness gate every realize lens shares:
python3 scripts/check_ready_slice.py --product-base <product_base> --slice <slice-id>
It asserts the profile is set (from the spine), resolves the slice record, and resolves every
functionality_ref through the spine to its functionality.md grounding doc — the hub. If the slice
is absent, a functionality does not resolve, or the profile is not firmed, hard halt (C1/REC1).
Clean-tree assertion (C13/F14, ADR 026). Before any work, assert the product-os tree carries no
uncommitted edits — HEAD is only a correct base for the scoped guard and the change-shape if the
tree is clean at entry:
test -z "$(git status --porcelain -- <product_base>product-os)" || { echo "HALT: dirty product-os tree (REC14)"; exit 1; }
If dirty, halt at pre-flight and ask for a clean model tree (commit or revert the pending model
edits, or run the prior pipeline play to its close) before /agentic proceeds.
The run's working root is <working> = {stm_base}_realize/agentic/ — the manifest, the change-shape,
the persist record (persist-manifest.json), and the captured scoped-guard report
(guard-report.json) all live under it. These are STM, non-model artifacts (ADR 008/017) — the model
itself is written IN PLACE under <product_base>product-os/, never into <working>. The
stop-condition gate evaluates against <working>.
Right after the resolver, record the session identity stamp's start marker (#463 — soft-fail, never
a halt):
python3 scripts/session_stamp.py --phase start \
--marker "{stm_base}_realize/agentic/status/session-stamp-agentic.json" \
--cwd "$(pwd)" --branch "$(git branch --show-current)"
Resume check: if {stm_base}_realize/agentic/status/<slice-id>.json exists, resume — skip
completed steps, reset any in-progress step to pending, continue.
Task DAG
Create ALL tasks immediately after resolving config — before any domain work.
Write-then-review (ADR 026): the FULL model delta — the LLM's lens doc AND the keyed persist's
decision writes — is written to the live model BEFORE the checkpoint, so the guard, the change-shape,
and the human all see the real delta. Nothing is COMMITTED before the gate resolves; cancel reverts
the uncommitted writes.
[T1] Draft the lens (to the live model) blockedBy: []
[T2] Validate the live lens blockedBy: [T1]
[T3] Persist (keyed, in place — decisions) blockedBy: [T2]
[T4] Guard the full delta + classify the shape blockedBy: [T3]
[T5] Checkpoint (approval over the git diff) blockedBy: [T4]
[T6] Commit the model delta blockedBy: [T5]
[T7] Scenario Validation blockedBy: [T6]
[T8] Close blockedBy: [T7]
Mark each task in-progress before its step and completed right after its eval passes. No runtime
reordering. On resume, skip completed and reset in-progress to pending.
Workflow
Phase: Draft
Step 1 — Draft the lens (to the live model) · Owner: product-os-keeper · Depends on: pre-flight
The agent invokes author-agentic-lens to write the slice's agentic.md (the gate + weights +
controls, per the Agentic lens template) straight to the live model from the hub (the
functionality grounding docs + the profile) and KB framing grounding, plus an agentic-manifest.yaml
(the grounding map + lens_rel + any autonomy decision as a full record). Per ADR 026 the skill
writes the per-node lens doc IN PLACE and emits any decision as structured data in the manifest (it
never writes the spine, the profile, or a decisions/ file):
{
"task": "author the slice's agentic lens (gate/weights/controls) straight to the live model from its hub; ground the verdict and weights in the functionalities and any autonomy framing in the KB; emit any material decision into the manifest",
"inputs": { "slice_ref": "<domain>/<slice>",
"slice_file": "<slice record>",
"functionality_groundings": "<from check_ready_slice>",
"profile": "<spine profile>", "product_base": "<product_base>",
"kb_search": "<kb-search script>", "kb_root": "<knowledge/ root>",
"lens_rel": "product-os/<domain>/slices/<slice>/lens/agentic.md",
"manifest_path": "<working>/agentic-manifest.yaml",
"proposals_dir": "<working>/proposals" },
"outputs": { "lens_rel": "product-os/<domain>/slices/<slice>/lens/agentic.md",
"manifest": "<working>/agentic-manifest.yaml" }
}
The skill reads the hub read-only, writes only the per-node lens doc agentic.md to the live model,
and writes agentic-manifest.yaml (+ any KB proposals) under <working> (STM). It writes NO shared
model file. It returns the contract with the output paths on disk — never inline content.
SE-1 (F1/C1): check_ready_slice.py passed at pre-flight — the slice is ready and its hub
resolves; an unready slice halted (REC1).
SE-14 (F14/C13): the product-os tree was clean at entry — the pre-flight assertion
(git status --porcelain -- <product_base>product-os empty) passed on a fresh start; a dirty model
tree halted at pre-flight (REC14), so the change-shape and the scoped guard reflect only this run's
delta.
Phase: Validate
Step 2 — Validate the live lens · Owner: play · Depends on: Step 1
Run the guards over the LIVE lens before the checkpoint — shape first, then content, then grounding.
Under direct-model-write the lens is already written in place, so the linter and the content eval run
over the live doc:
python3 scripts/lint_grounding.py --doc <product_base>/<lens_rel>
python3 scripts/validate_agentic.py --manifest <working>/agentic-manifest.yaml --slice-file <product_base>/<slice_file>
python3 scripts/check_kb_grounding.py --manifest <working>/agentic-manifest.yaml --kb-root <kb_root> --proposals-dir <working>/proposals
Then run the content-quality eval over agentic.md: spawn an isolated, clean-context sub-agent
handed the judge prompt (standards/rules/grounding-eval.md), the live doc, and the Agentic lens
per-section guidance, on the model from grounding-eval.judge.model. Gate the verdict:
python3 scripts/grounding_gate.py --verdict <verdict.json>
SE-2 (F3/C3): lint_grounding.py exits 0 — agentic.md conforms to the Agentic lens template
("Is it an agent?", "Load weights", "Controls"), no missing/extra/empty section.
SE-3 (F4/C4): the content-quality eval gate (grounding_gate.py) passes — agentic.md is
self-explaining and clears the stranger test.
SE-4 (F5/C5): validate_agentic.py — the verdict and weights ground in the slice's
functionalities; any material autonomy choice names a decision (carried in the manifest) that resolves.
SE-5 (F6/C6): validate_agentic.py — the assessment considers every functionality the slice
bundles (coverage).
SE-6 (F7/C7): validate_agentic.py — the assessment grounds on no other realize lens.
SE-7 (F8/C8): validate_agentic.py — the gate is recorded (is_agent) and grounded; agentic
behavior is not asserted without the functionalities' behavior behind it.
SE-8 (F10/C10): check_kb_grounding.py exits 0 — the agentic-framing choices trace to a KB
learning or a recorded proposal.
On any GAP, apply the matching recovery (REC3–REC10) and re-run before the checkpoint — a
content-eval fail (SE-3) is REC4: rewrite the doc to the judge's cited fixes and re-judge.
Phase: Persist (write the full delta first, ADR 026 write-then-review)
Step 3 — Persist (keyed, in place) · Owner: play · Depends on: Step 2
Write-then-review (ADR 026): the FULL model delta is written to the live model BEFORE the checkpoint,
so the guard, the change-shape, and the human all see the real delta. The lens is already on the live
model (Step 1). persist_agentic.py writes the one shared-file concern — the slice's decisions/ — in
place from the manifest, keyed to the target slice: it writes one decisions/<id>.yaml per autonomy
decision the manifest carries, skip-if-exists (an accepted decision is never edited in place), and
REFUSES to write outside the target slice's decisions folder (this is the node-level containment the
file-level guard cannot provide). A non-agent slice carries no decisions, so this writes nothing but
still stamps the lens landed. No draft, no doc copy. Nothing is COMMITTED yet — the commit (Step 6)
happens only after the gate approves; on cancel the whole delta is reverted (Step 5):
python3 scripts/persist_agentic.py --manifest <working>/agentic-manifest.yaml \
--product-base <product_base> --out-manifest <working>/persist-manifest.json
The apply manifest carries the machine applied field the close's stop-condition gate reads (#464):
lens_applied: true (the live agentic.md landed) and the written/skipped/refused decision
lists.
SE-9 (F2/C2/C9): the keyed persist wrote only the slice's decisions (skip-if-exists) and
refused is empty — no decision landed outside the target slice's decisions folder, and no shared
file (spine/profile) was written by any route.
Phase: Guard + Classify (over the full delta)
Step 4 — Guard the full delta + classify the shape · Owner: play · Depends on: Step 3
The run's write scope (the per-play guard policy, ADR 026). The old draft-copy apply encoded
/agentic's write scope by construction — the slice's lens/agentic.md (re-derive) and its
decisions/*.yaml (skip-if-exists). Under direct-model-write that same scope is the
scoped_write_guard.py policy — resolve <slice-dir> as product-os/<domain>/slices/<slice> (the
directory two levels above the lens doc):
--allow 'product-os/<domain>/slices/<slice>/lens/agentic.md' # the slice's lens doc (overwrite / re-derive)
--add-only 'product-os/<domain>/slices/<slice>/decisions/*' # new autonomy decisions (added, not modified)
Guard ONCE over the full delta (C9). After ALL writes (the LLM lens from Step 1 and the keyed
persist's decision writes from Step 3), run the scoped guard a single time over the whole delta.
Capture its report — its ok field is the stop condition's D3 input:
python3 scripts/scoped_write_guard.py --product-base <product_base> --base-ref HEAD \
--allow 'product-os/<domain>/slices/<slice>/lens/agentic.md' \
--add-only 'product-os/<domain>/slices/<slice>/decisions/*' \
--out <working>/guard-report.json
If the guard exits non-zero, re-run with --restore to revert the offending paths, apply REC9 (a
non-lens/non-decision file changed, or a decision edited in place), and re-persist before the
checkpoint.
Classify the full working-tree delta (C11). Classify the model tree's diff vs HEAD — the FULL
delta (the lens doc + any decision), per ADR 026 write-then-review (no draft dir):
python3 scripts/classify_change.py --play agentic \
--product-base <product_base> --base-ref HEAD --out <working>/shape.json
SE-10 (F9/C9): the scoped-write guard report reads ok: true — the model delta is confined to
the slice's agentic.md and its new decisions; no other lens, the spine, the profile, the slice
record, or another slice changed.
Phase: Checkpoint (conditional gate, C11)
Step 5 — Human review (class: standard, conditional) · Owner: play · Depends on: Step 4
This is the single checkpoint (C11) — the agent never skips it on its own judgment. It is a
conditional gate per standards/rules/gate-config.md (#467; /agentic is one of the eleven
conditional document plays). Resolve, first match wins: pinned (n/a here) → gates.plays.agentic →
the learned policy → gates.classes.standard → gates.default (absent ⇒ on). For the policy lookup,
use the shape key classified in Step 4.
Look the emitted shape_key up in the config-resolved policy file (gates.conditional.policy,
default .garura/core/gate-policy.yaml): auto-pass iff the shape is in the policy's auto:
block AND not in never_auto: AND Step 2 + Step 4 stand with no blocking finding (a
lint_grounding.py gap, a grounding_gate.py content-eval fail, or a guard violation). The --ts
value below is the run's timestamp derived the same way the close derives ts
(date -u +%Y%m%d-%H%M%S), passed by the orchestrator. On auto-pass, do NOT wait: record
gate auto-passed by learned policy (shape: <shape_key>, policy v<version>) as a Checkpoint Decisions
row, include the working-tree diff summary in the run record, append the crossing's live-eval ledger
line, and proceed to Step 6 (commit):
python3 scripts/gate_eval.py append --ledger <gates.conditional.ledger> --play agentic --issue <issue> \
--shape <shape_key> --predicted auto --human auto_pass --policy-version <policy version> --ts <ts>
Anything else resolves the gate on (an explicit gates.plays.agentic: off instead records
gate skipped by config (<resolution path>) as a Checkpoint Decisions row and proceeds on the
validated delta). When on, present the proposed gate verdict, the weights, and the controls
inline over the real model git diff, plus any decision — render the approval prompt
(standards/templates/approval-prompt.md) and wait for the typed response. Approve → continue to
Step 6 (commit). Cancel → revert the working tree (ADR 026 step 6): the full delta is already on
disk, so run the guard with --restore and an EMPTY allow set to git restore the modified model
paths and git clean/remove the new ones (byte-clean back to HEAD), then halt — nothing was
committed, and cancel means "revert what was written":
python3 scripts/scoped_write_guard.py --product-base <product_base> --base-ref HEAD \
--restore --out <working>/guard-report.json # empty --allow ⇒ every model path reverted
Then append the crossing's live-eval ledger line with the human's real action:
python3 scripts/gate_eval.py append --ledger <gates.conditional.ledger> --play agentic --issue <issue> \
--shape <shape_key> --predicted gate --human <approved_clean|approved_edited|rejected> --ts <ts>
<issue> is the slice-realize issue the run's branch carries (opened by /ux's start-change).
<gates.conditional.ledger> / <gates.conditional.policy> resolve from config gates.conditional
(defaults .garura/core/gate-evals.jsonl / .garura/core/gate-policy.yaml); <policy version> is
the policy file's version: field. <ts> is the run's own UTC timestamp.
SE-11 (F11/C11): the model delta is COMMITTED only after this gate resolves — a typed approval, a
recorded config skip, or a recorded policy auto-pass; Step 6 is the sole committer and depends on
this step. On cancel the whole delta is reverted before any commit.
SE-13 (F13): every crossing of this gate appended exactly one live-eval ledger line (shape,
predicted gate|auto, the human's real action or auto_pass), and an auto-pass fired only for a
shape the policy lists in auto: (and not in never_auto:) with no blocking finding standing.
Phase: Commit (make the delta durable, ADR 026 step 7)
Step 6 — Commit the model delta · Owner: play · Depends on: Step 5
The gate approved (or auto-passed / was skipped by config). Commit the full model delta on the branch
(C13, ADR 026 step 7) — a lightweight persist step that makes the writes durable and advances HEAD;
it is NOT the pipeline start/end sequence (agentic is a middle play). A cancelled checkpoint never
reaches this step — its tree was already restored in Step 5:
git add -- <product_base>product-os
git commit -m "feat(model): agentic lens for <slice> (#<issue>)"
SE-12 (F12/C12): the close is stop-condition gated — check_stop_condition.py over the baked
stop-condition.yaml (D1 the persist record persist-manifest.json exists; D2 it stamps
lens_applied: true; D3 the captured guard-report.json reads ok: true) must read held before
any COMPLETED close, and the model delta is committed (C13); a run whose persist or guard did not land
closes HALTED, never COMPLETED (REC12).
Phase: Scenario Validation
Step 7 — Scenario evals · Owner: play · Depends on: Step 6
- SCE-1 (S1 — agent designer):
agentic.md is a valid Agentic Lens doc clearing the linter + the
content eval, written in place, and the scoped-guard report reads ok so the spine/slice/profile/
other lenses are byte-identical; the stop-condition verdict reads held.
- SCE-2 (S2 — product owner, honest gate): a deterministic slice comes out
is_agent: false with
the reason and n/a weights.
- SCE-3 (S3 — reviewer): the verdict and weights trace to the slice's functionalities; material
choices name a decision that resolves.
- SCE-4 (S4 — architect): no other realize lens was read or written (the guard report is
ok).
- SCE-5 (S5 — product owner, re-run): a re-run re-derives only
agentic.md in place; everything
else byte-identical (the guard report is ok); no accepted decision edited in place.
- SCE-6 (S6 — reviewer): the checkpoint showed the gate, weights, and controls inline over the
real model git diff, and no product-model change was COMMITTED before approval — the full delta
written in place shows as the branch diff and is reverted byte-clean on cancel (ADR 026 step 6) —
or, on the auto-pass path, the change shape is policy-listed and a recorded auto-pass + live-eval
ledger line + diff summary exist, with no wait.
Phase: Evidence & Close
Step 8 — Close · Owner: play · Depends on: Step 7
Run the Standard Play Close. /agentic is a slice-realize play — record evidence per the D1 rule.
# --- Standard Play Close (canonical; see standards/rules/play-close.md) ---
# Path tokens resolved at pre-flight (resolve here if not already):
# ltm_project_target = yq '.ltm.project-target' .garura/core/config.yaml
# evidence_base, slug:
# project-scoped play : evidence_base="${stm_base}${issue}/evidence/agentic/" ; slug="#${issue}"
# product-scoped play : evidence_base="${product_base}_evidence/agentic/" ; slug="${slice_slug}"
evidence_template=$(cat "${ltm_project_target}standards/templates/evidence-file.md")
delivery_template=$(cat "${ltm_project_target}standards/templates/delivery-report.md")
ts=$(date -u +%Y%m%d-%H%M%S)
evidence_dest="${evidence_base}${ts}.md"
mkdir -p "$(dirname "$evidence_dest")"
# Session identity stamp (#463) — close phase; start phase ran at pre-flight
session_stamp=$(python3 scripts/session_stamp.py --phase close \
--marker "${stm_base}_realize/agentic/status/session-stamp-agentic.json")
# Stop-condition gate (#464) — Step C0: this play carries a baked manifest, so the
# gate is LIVE. Evaluate the Done means against the run's working root as the
# close's authoritative input.
python3 scripts/check_stop_condition.py \
--manifest "<play-dir>/stop-condition.yaml" \
--base "${stm_base}_realize/agentic/" \
--out "${stm_base}_realize/agentic/status/stop-condition-agentic.yaml"
sc_exit=$? # 0 held · 1 unmet · 2 error
# Conditional-gate policy refresh (#467) — soft: a distill failure never blocks the close
python3 scripts/distill_gate_policy.py \
--ledger "$(yq '.gates.conditional.ledger' .garura/core/config.yaml)" \
--policy "$(yq '.gates.conditional.policy' .garura/core/config.yaml)" \
--streak "$(yq '.gates.conditional.streak' .garura/core/config.yaml)" \
--project "$(yq '.project.name' .garura/core/config.yaml)" || true
Step C0 — bind the verdict. sc_exit == 0 (held) permits status: COMPLETED.
Anything else closes HALTED with exit_reason: stop_condition_unmet and the evidence's
Stop Condition section names every unmet clause — fix the state per REC12 (re-run the keyed persist,
re-capture the scoped-guard report, or make the model-delta commit) and re-evaluate; the close stays
HALTED until the verdict reads held. An unevaluable verdict is never a pass.
/agentic runs on the slice-realize issue /ux opened, so it is project-scoped:
evidence_base="${stm_base}${issue}/evidence/agentic/" and slug="#${issue}".
Step C1 — Write evidence file. Gated by the resolved evidence.record flag. When false, skip and
record evidence skipped (record=false). Otherwise fill the evidence-file.md slots (play agentic,
run_id agentic-${ts}, slice slug, started/completed, status per C0, exit_reason; artifacts: the
slice's agentic.md (its live path), the manifest, any decision record written, the persist manifest
(persist-manifest.json), the captured guard-report.json, the model-delta commit sha, the
stop-condition verdict; the content-eval verdict; step + scenario evals SE-1…SE-14 / SCE-1…SCE-6;
checkpoint decision (incl. any gate skipped by config or gate auto-passed by learned policy row)
plus the gate ledger line(s) appended this run; the session identity stamp fields from
$session_stamp (#463): session_id, ledger_file, ledger_start_offset, ledger_end_offset (null when
unresolved — never blocks the close); and stop_condition per C0 with the Stop Condition section
filled) and write to $evidence_dest. Do NOT hand-author the body.
Step C2 — Render delivery report. Also render the Next line: resolve this play in standards/rules/pipeline-next.md and emit **Next:** /<command> — <why>. Or run /next to see all recommended actions. (only /next pointer, or omit, when the mapped command is null), per play-close.md. Fill the delivery-report.md slots: ## agentic Delivered — ${slug}, the Run Summary table (incl. the stop-condition verdict), the Pipeline Steps table, the
Artifacts Produced table (the agentic lens + any decision), Next Steps (run /marketing to close the
functional pipe), and a pointer to $evidence_dest. Always emitted.
# --- end Standard Play Close ---
Scenario Validation
| Scenario | Persona | Eval |
|---|
| S1 — first run | agent designer | SCE-1 |
| S2 — the honest gate | product owner | SCE-2 |
| S3 — grounded | reviewer | SCE-3 |
| S4 — hub-only | architect | SCE-4 |
| S5 — re-run | product owner | SCE-5 |
| S6 — the checkpoint | reviewer | SCE-6 |
Recovery
| For | Trigger | Direction | Handoff |
|---|
| F1 | the slice is absent, a functionality does not resolve, or the profile is not firmed | halt and route to /shape or /understand before /agentic runs | human |
| F2 | a write touched something beyond this slice's agentic.md or a decision | the guard's --restore already reverted the out-of-scope write; re-run writing only the slice's agentic.md and any autonomy decision | autonomous |
| F3 | agentic.md fails the template/shape or carries out-of-scope content | re-emit to the Agentic lens template (gate/weights/controls only) | autonomous |
| F4 | agentic.md fails the content-quality eval | rewrite the failing section to the judge's cited fixes and re-judge until the gate passes | autonomous |
| F5 | an invented verdict/weight, or a material choice with no decision | re-tie the verdict and weights to the functionalities, and record the autonomy decision in the manifest | autonomous |
| F6 | a functionality was not considered | extend the assessment to consider the missing functionality | autonomous |
| F7 | /agentic read or depended on another lens | remove the dependency; /agentic derives only from the slice's hub | autonomous |
| F8 | agentic behavior was manufactured where the functionalities don't warrant it | reset the gate to the honest verdict (is_agent false + n/a weights for a deterministic slice) | autonomous |
| F9 | a non-lens/non-decision file changed, or an accepted decision was edited in place (scoped-guard violation) | the guard's --restore already reverted the offending paths; re-run writing only agentic.md and the new decision, after a human confirms the restore | human |
| F10 | an agentic-framing choice with no KB learning and no recorded proposal | search the KB via kb-search and ground the choice, or raise a KB-learning-gap proposal | autonomous |
| F11 | the model delta was committed before the checkpoint resolved, or a cancelled checkpoint left writes on the working tree | revert the premature commit and the working-tree writes (guard --restore, empty allow set) and re-present the checkpoint; commit only after the gate resolves |
Pause and Resume
Steps run top to bottom. On entry, resolve config, resolve the target slice, check the status marker,
skip completed steps, reset any in-progress step to pending, and continue. A fresh start with no
marker runs everything and creates the marker at Step 1. Resuming a run that already wrote the live
lens enters a dirty tree; the pre-flight clean-tree assertion (F14) is scoped to a FRESH start — a
resume continues its own in-progress delta.
Compilation Metadata
| Field | Value |
|---|
| fingerprint | sha256:963cc0c0b50ab37e99facd365c0a409549a5b851baea1537f7f6da873bb1f366 (of reference/ice.md) |
| compiled_by | play-editor (#500 direct-model-write, ADR 026); prior: play-editor (#467 Batch B, #466 Batch C) |
| pipeline_position | none |
| position_exception | middle of the functional realize pipe — runs on the branch /ux started; the close belongs to /marketing |
| workflow_structure | A (single checkpoint — class: standard, conditional learned gate per gate-config.md #467; direct-model-write WRITE-THEN-REVIEW per ADR 026 — persist + guard + classify before the gate, commit after; stop-condition gated close) |
| stop_condition | stop-condition.yaml (D1–D3), gate live at Step C0 |
| domain_agents | 1 (product-os-keeper) |
| utility_agents | 0 |
| skills_used | kb-search, author-agentic-lens |
| scripts | 13 (preflight, check_ready_slice, lint_grounding, grounding_gate, validate_agentic, check_kb_grounding, persist_agentic — keyed in-place persist, scoped_write_guard — post-write containment, classify_change — git-mode, gate_eval, distill_gate_policy, check_stop_condition, session_stamp) |
| step_evals | 14 (SE-1…SE-14) |
| scenario_evals | 6 (SCE-1…SCE-6) |
| recovery_entries | 14 (one per failure condition; 10 autonomous / 4 human) |
Recompiled note (#500, direct-model-write / ADR 026): migrated from draft-then-apply to
direct-model-write. The old draft model tree, the draft-copy apply, and the before/after verify
(check_agentic.py) are removed; the authoring skill writes the per-node lens doc straight to the
live model; the keyed persist_agentic.py writes the slice's decisions in place from the manifest
(skip-if-exists, refusing any path outside the target slice); containment is the post-write
scoped_write_guard.py (its guard-report.json is D3); classify_change.py reads the working-tree
git diff (--product-base/--base-ref HEAD, byte-identical canonical git-mode); checkpoint cancel
reverts the working tree via the guard --restore; the play asserts a clean product-os tree at entry
(F14) and commits its own feat(model) delta after approval (C13). Order is write-then-review
(ADR 026 "Order of operations"): the full delta — the LLM lens AND the keyed persist's decision
writes — is written to the live model FIRST (Steps 1+3), then guarded ONCE and classified over the
full delta (Step 4), then the gate resolves over the real git diff (Step 5), and only an approved gate
COMMITS (Step 6). Nothing is COMMITTED before approval; cancel reverts the uncommitted writes. See
standards/rules/direct-model-write.md.
Recompiled note (#467 Batch B): checkpoint upgraded to a conditional learned gate;
see gate-config.md.
Direct-edit deviation note (#500) — INTENT CHANGE, HAND-COMPILED, CONVERGENCE UNVERIFIED:
This SKILL was updated to the direct-model-write write-then-review shape (ADR 026) by a
hand-compile from reference/ice.md, NOT by a /play-editor run. This is an intent change
(it alters the write path, the containment guarantee, the checkpoint cancel semantics, and the step
order), so the sanctioned path is recompile-via-/play-editor; play-editor is interactive-only
(fully gated, human-checkpoint) and cannot run headless in this environment, so the compiled output
was produced by hand to match what play-editor would emit from the current reference/ice.md
(fingerprint above), following the merged /understand reference implementation (#498). The
compiled_by line names play-editor for provenance intent, but no play-editor run actually occurred
and convergence is UNVERIFIED. An interactive /play-editor convergence run against
reference/ice.md is REQUIRED — confirming the emitted SKILL matches this hand-compiled body and
refreshing the fingerprint — before this play is relied on. reference/ice.md C13 distinguishes the
model-delta commit from the Standard Play Close (evidence + delivery report) that /agentic still runs;
the close anchor block is retained (required by lint-components and the play-creator G12 emit on
every play), and the feat(model) commit is the separate lightweight persist step, so both coexist as
C13 describes.