diff --git a/docs/architecture/rfcs/harness-selection-dsh-pi-v0.md b/docs/architecture/rfcs/harness-selection-dsh-pi-v0.md index 6fcf0a12d0..2bfd6ae851 100644 --- a/docs/architecture/rfcs/harness-selection-dsh-pi-v0.md +++ b/docs/architecture/rfcs/harness-selection-dsh-pi-v0.md @@ -543,6 +543,8 @@ Shipped enforcement, in delivery order: Goal, an external manager channel resolves only the Goals it is bound to, and a Goal the registry does not know - or one outside that channel's scope - drops the preview instead of validating it against another Goal's Agents. + The shipped steward guidance requires the plan to name that Goal, because a + plan that does not name it is dropped rather than shown. 5. **Confirmed apply from Chat.** The typed Chat action surface owns a `team.plan` action. Its preview validates the plan against that Goal's registered Agents and the host's advancement action kinds, and its apply diff --git a/docs/architecture/rfcs/harness-selection-dsh-pi-v0.zh-CN.md b/docs/architecture/rfcs/harness-selection-dsh-pi-v0.zh-CN.md index 2b4b8a854b..a4a899c2a3 100644 --- a/docs/architecture/rfcs/harness-selection-dsh-pi-v0.zh-CN.md +++ b/docs/architecture/rfcs/harness-selection-dsh-pi-v0.zh-CN.md @@ -423,6 +423,7 @@ Todo 创建、quota 或 goal policy——复用预览点名的身份,不得扩 预览只会用**它点名那个 Goal** 的 Agent 来校验:业主自己的通道可解析任意已注册 Goal, 外部管家通道只解析它被绑定的 Goal,而 registry 不认识的 Goal——或超出该通道范围的 Goal——会让预览被丢弃,而不是拿另一个 Goal 的 Agent 去校验它。 + 出厂的管家指引要求计划**点名**那个 Goal,因为不点名 Goal 的计划会被丢弃而不是被展示。 5. **从 Chat 确认落地。** 类型化 Chat action 面拥有一个 `team.plan` 动作:它的预览用该 Goal 已注册 Agent 与本机 advancement action kind 校验计划,它的落地则把同一份载荷交给受治理 提案所有者在 `PRE_SETTLEMENT` 相位重新校验,因此**一次业主确认**就会为每条 ready lane diff --git a/loopx/capabilities/manager_context/skills/loopx-manager/SKILL.md b/loopx/capabilities/manager_context/skills/loopx-manager/SKILL.md index 2b911ec641..667c4cd662 100644 --- a/loopx/capabilities/manager_context/skills/loopx-manager/SKILL.md +++ b/loopx/capabilities/manager_context/skills/loopx-manager/SKILL.md @@ -95,7 +95,9 @@ of an implementation request. Only use `handoffs` for troubleshooting or an explicit follow-up; the original exchange must not depend on a second question. When one owner sentence asks for a team rather than a single task, answer with -one plan preview before anything is created. The preview names, in this order: +one plan preview before anything is created. Name the exact Goal the plan +staffs: a plan that does not name it, or that names a Goal outside your +authorized scope, is dropped instead of shown. The preview names, in this order: the lanes and the Agent each one runs on; the first bounded Todo per lane with its declared priority; the quota or cadence envelope that bounds them; the acceptance signal that ends each lane; and the stop condition that ends the @@ -106,12 +108,16 @@ inventing a lane, an Agent, or a capability. A team preview is a proposal, never an effect. Do not create Todos, register Agents, set quota, or start work until the owner confirms that exact preview; -state what will be created and which canonical owner creates it — Agent +the confirmation arrives as one typed team-plan action from the product +surface, and you never create lanes yourself. State what will be created and +which canonical owner creates it — Agent registration, Todo creation, quota or goal policy — so the owner sees where each effect lands. After confirmation, apply through those owners only, reuse the Agent and Todo identities the preview named, and report one readback of -what now exists. Never widen the confirmed scope while applying it, and never -charge quota for the preview itself. +what now exists. Never say a lane exists, or that a team is running, before the +apply receipt returns; if the confirmation was refused, or the plan went stale +because the Agents it named changed, say exactly that instead. Never widen the +confirmed scope while applying it, and never charge quota for the preview itself. Core owns truth and permissions. This skill supplies reasoning guidance, not new authority. Keep front-end and group answers within their respective scopes; diff --git a/tests/test_manager_team_plan_guidance.py b/tests/test_manager_team_plan_guidance.py index c12ae7b817..3e430135c6 100644 --- a/tests/test_manager_team_plan_guidance.py +++ b/tests/test_manager_team_plan_guidance.py @@ -23,6 +23,14 @@ def test_manager_guidance_orders_one_team_preview_before_any_effect() -> None: # The preview gates every effect, and the effects keep their canonical owners. assert "proposal, never an effect" in text assert "until the owner confirms that exact preview" in text + # A plan is admitted only for the Goal it names, and the confirmation is the + # product surface's typed action rather than something the steward performs. + assert "Name the exact Goal the plan\nstaffs" in text + assert "dropped instead of shown" in text + assert "typed team-plan action from the product\nsurface" in text + # A lane may not be claimed to exist before its apply receipt returns. + assert "before the\napply receipt returns" in text + assert "the plan went stale" in text assert "Agent\nregistration, Todo creation, quota or goal policy" in text assert "charge quota for the preview itself" in text # An unstaffable lane is named as a gap rather than invented.