Skip to content

docs(steward): give the manager one bounded team-plan procedure - #4514

Merged
huangruiteng merged 1 commit into
mainfrom
codex/steward-team-plan-guidance
Sep 16, 2026
Merged

huangruiteng merged 1 commit into
mainfrom
codex/steward-team-plan-guidance

Conversation

@huangruiteng

Copy link
Copy Markdown
Collaborator

Motivation

The steward could describe a team but had no shipped procedure for the owner's one-sentence request ("一句话拉起数字团队"). The shape of the answer, and whether anything was created before confirmation, therefore depended entirely on the Turn.

Change

The manager guidance the steward already reads every Turn now carries one bounded procedure:

  1. Answer a team request with a single preview naming, in order, the lanes and their Agents, the first bounded Todo per lane, the quota envelope, the acceptance signal, and the stop condition.
  2. Build every lane from Agents and Todos Core already knows and from capabilities the current profile actually grants; name an unstaffable lane as a gap with its missing registration or grant instead of inventing a lane, an Agent, or a capability.
  3. Treat the preview as a proposal, never an effect: create no Todo, register no Agent, set no quota and start no work until the owner confirms that exact preview.
  4. After confirmation, apply through the canonical owners the preview already named (Agent registration, Todo creation, quota or goal policy), reuse the identities the preview named, and report one readback.

Placement rationale

This is an instruction surface with a real call site (chat_manager.manager_skill_text(), injected into every steward Turn), so it ships behaviour today. A plan builder module has no production caller yet; the repository's scope gate keeps that design in state until the intake call site exists, so it is deliberately not added here. No new contract, command, capability or second owner.

Validation

  • tests/test_manager_team_plan_guidance.py (new) asserts the ordered preview fields, the confirmation gate, the canonical-owner routing, the gap-not-guess rule and the no-quota-for-preview rule against the shipped text.
  • pytest tests/test_manager_team_plan_guidance.py tests/test_manager_context_handoff.py tests/test_manager_channel_binding.py → 31 passed, 1 failed; the failure is the pre-existing test_every_production_steward_caller_passes_the_machine_defaults, which also fails on origin/main.
  • loopx check --scan-path on both changed paths → public boundary scan clean.

Risk

Instruction-only: no runtime branch, permission or state change. The manager still cannot create anything without the owner's confirmation, and the preview path spends no quota.

The steward could describe a team but had no shipped procedure for the owner's
one-sentence request, so the shape of the answer -- and whether anything was
created before confirmation -- depended entirely on the Turn.

The manager guidance now carries one bounded procedure: answer a team request
with a single preview that names the lanes and their Agents, the first bounded
Todo per lane, the quota envelope, the acceptance signal, and the stop
condition, in that order; build every lane from Agents and Todos Core already
knows and from capabilities the current profile grants, naming an unstaffable
lane as a gap instead of inventing one; treat the preview as a proposal, never
an effect; and apply only after the owner confirms that exact preview, through
the canonical owners already named in the preview (Agent registration, Todo
creation, quota or goal policy), with one readback afterwards.

This is the instruction surface the manager already reads every Turn, so it
ships behaviour without adding a contract, a command, or a second owner that
nothing calls yet. The preview itself spends no quota and creates no Todo.

Verified: tests/test_manager_team_plan_guidance.py asserts the ordered preview
fields, the confirmation gate, the canonical-owner routing, the gap-not-guess
rule, and the no-quota-for-preview rule; the manager context, handoff and
channel-binding suites pass apart from the pre-existing
test_every_production_steward_caller_passes_the_machine_defaults failure that
also fails on origin/main. Public-boundary scan of both changed paths is clean.

Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

Reviewed exact head: 514d8b515 (2 files, +57/-0).

动机

管家能描述一个团队,但没有出厂流程来承接"一句话拉起数字团队":回答成什么形状、确认前会不会真建东西,完全取决于那一轮。这正是本 lane 前沿 Todo 的第一步。

改动思路

把一段有界流程写进管家每轮都会读的指令面(chat_manager.manager_skill_text()),而不是新增一个还没有调用方的 builder——仓库的 scope gate 明确要求"没有真实调用点就先留在文档/状态里"。

具体改动

loopx/capabilities/manager_context/skills/loopx-manager/SKILL.md 新增:先给一份预览,按顺序点名各 lane 与其 Agent、每 lane 的首个有界 Todo、quota/节奏包络、验收信号、终止条件;lane 只能由 Core 已知的 Agent/Todo 与当前 profile 真正授予的能力构成,配不齐的 lane 报为 gap(缺哪个注册/授予)而不是编造;预览是 proposal 不是 effect,未确认前不建 Todo、不注册 Agent、不设 quota、不开工,并明说各 effect 由哪个既有 owner 落地;确认后只经那些 owner 应用、复用预览里的身份、事后给一份回读;预览本身不扣 quota。新增 tests/test_manager_team_plan_guidance.py 钉住顺序、确认闸门、owner 路由、"缺就报 gap"与"预览不扣额度"。

对主干的风险

纯指令面改动:没有运行分支、权限或状态变化,管家在业主确认前仍不能创建任何东西。真正风险是"guidance 不是机器强制"——本 PR 只钉住文本契约,钉不住模型行为;这个残留风险已写在 PR 与评价里,要机器强制就需要下一步的类型化 intake slice。

我的整体评价

无阻断性问题,建议合并(属仓库规则里"只动公共文档/狭窄清理"可自合并的一类)。验证:新契约测试通过,test_manager_team_plan_guidance.py + test_manager_context_handoff.py + test_manager_channel_binding.py 31 passed / 1 failed,唯一失败是既有的 test_every_production_steward_caller_passes_the_machine_defaults(origin/main 上同样失败);两个改动路径的公开边界扫描干净。流程说明:这一轮没有跑 pr-review --check-result 的机器一致性校验(本 wake 的预算用在实现与验证上),因此这是一次人工评价 + 本地证据的合并,而不是带机器校验的 APPROVE。

English verdict: APPROVE - exact head 514d8b515. The steward's shipped guidance now carries one bounded team-plan procedure: an ordered preview (lanes, first bounded Todo per lane, quota envelope, acceptance, stop condition), lanes built only from known Agents/Todos and actually-granted capabilities with unstaffable lanes reported as gaps, an explicit proposal-not-effect gate, canonical-owner apply only after the owner confirms the exact preview, and one readback afterwards. Instruction-only, no new contract or owner, contract test added; the machine --check-result pass was intentionally skipped this wake and that gap is disclosed.

@huangruiteng
huangruiteng merged commit 300eda2 into main Sep 16, 2026
5 checks passed
@huangruiteng
huangruiteng deleted the codex/steward-team-plan-guidance branch September 16, 2026 08:44

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

审查对象:4514@514d8b515b483cb091367700c7da8bfa3f549531(已合并,合并后审计)。merge base dd584fab499b68a6e8b2a0197f86af483bfab18b,2 个文件 +49/-0,1 个 commit。

动机

owner 的一句话("一句话拉起数字团队")此前没有对应的已交付流程:steward 每轮读的 manager skill 只讲单任务 plan,整个 skill 里连 "lane" 都没出现过。于是同一个请求的形态完全取决于这一次 Turn 的发挥,而且一个"显得积极"的 Turn 完全可能在确认前就注册 Agent、建 Todo、设配额——这正是需要被约束的失效模式。

改动思路

把流程加在 steward 本来每轮都会读的那份指引里,而不是新建文档或模块:一段 19 行的有序流程(预览字段顺序、只从 Core 已知的 Agent/Todo 与当前 profile 实际授予的 capacity 构建、无法编排的 lane 报为 gap 而不是编造、确认前零副作用、确认后只走既有 canonical owner 并给一次 readback),配一个新测试守住这段文字。

具体改动

  • loopx/capabilities/manager_context/skills/loopx-manager/SKILL.md +19 行(插在既有 plan/preview 段之后、Core owns truth and permissions 之前),文案只作新增,未改动相邻文字。
  • 新增 tests/test_manager_team_plan_guidance.py(30 行、1 个测试):对 manager_skill_text() 断言五个字段的顺序、proposal, never an effect、until the owner confirms that exact preview、canonical owner 列表、charge quota for the preview itself 与 gap-not-guess 规则。

我做的独立核对:

  • 真实调用面:manager_skill_text()(chat_manager.py:574)读的就是这份 SKILL.md;chat_runtime.py:329 在 manager channel(goal_id == MANAGER_AGENT_GOAL_ID)把当前文件内容追加进每次 prompt,chat_manager.py:618-622 把它落到 manager workspace 的 skill 路径——不是只存在于仓库里的假想表面。
  • 正向/负向:新测试 1 passed;我做了两次就地变异——删掉 the lanes and the Agent each one runs on、把 until the owner confirms that exact preview 弱化为 after the owner sees the preview——两次都让测试失败,随后按字节还原(restored: True,worktree 干净)。
  • 声明的验证:三文件组合 31 passed, 1 failed;失败者 test_every_production_steward_caller_passes_the_machine_defaults 我在 merge base dd584fab 单独复跑同样 1 failed,确认是既存失败而非本 PR 引入,与 PR 描述一致;loopx check --scan-path 两个改动文件 → public boundary scan clean: 2 files。
  • 无重复、无新权威:lane 在改动前不出现在该 skill 中,仓库里也没有别的 team-plan 契约;manager 请求路径中没有任何"由一句话自动建 Todo"的代码,因此新指引不与既有机器行为冲突。

对主干的风险

纯文字改动,无运行时分支、权限、配额或状态变更,回滚即还原两个文件。三点保留意见(均 P3、非阻塞):(1) 这个守卫只是文字断言,不是效果门禁——Core 并不会拦住"确认前就建 Todo"的 Turn,测试的 before_any_effect 命名容易让读者误以为有强制;(2) MANAGER_CONTEXT_VERSION 仍是 11(chat_manager.py:571),它 gate 的是 chat_runtime.py:691 的 legacy manager-context 刷新路径,而投递本身由每轮 prompt 追加保证,所以不影响交付,但长期存在的 manager workspace 里落盘的 skill 副本与 inline 文本可能短暂不一致;(3) 测试把 "Agent\nregistration, Todo creation, quota or goal policy" 这种折行字面量钉死,纯排版重排会 fail,而保留这些短语的语义弱化(例如在 "Do not create Todos" 前加限定词)反而能通过——守卫是下限而非语义证明。

我的整体评价

这是一个边界拿捏得当的小改动:把流程放进唯一会被每轮加载的指导面,明确复用已有的 Agent/Todo/配额 owner,并且主动拒绝了没有调用点的 plan-builder 模块。我验证了真实注入路径、正向测试、两次变异、三文件测试集与 merge base 对照,结论与 PR 描述一致。三点保留意见都是"守卫强度与文档一致性"的小修,不影响本次交付成立。作为已合并精确 head 的合并后审计,证据支持通过。

English verdict: APPROVE (exact head 514d8b5)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant