Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 10 additions & 2 deletions docs/architecture/rfcs/capable-manager-semantic-handoff-v0.md
Original file line number Diff line number Diff line change
Expand Up @@ -221,7 +221,9 @@ Do not put the entire handoff inside Goal Vision's bounded summary or expand eve

### 5.5 Responsibility discovery and receiver-owned planning

Discover all registered active Goals and their agents within authorized host scope. Stopped Goals are excluded by default but can be requested. Discoverability, read access, context delivery and execution permission are four separate facts. “Best effort” means the manager investigates role, current work, repository and availability; it does not mean broadcasting private context or guessing an identity.
**Broad discovery is the owner default.** The private steward discovers the owner's registered Goals and Agents across the local host and already-authorized connected sources, without requiring per-recipient enrollment just to find them. Search and pagination must reach the full permitted inventory; a small prompt or first-page limit is not a smaller discovery scope. Keep stopped Goals available through history/search, while excluding them from default work assignment. Offline, unbound, capacity-limited and unknown-presence Agents remain discoverable with their actual state.

Discoverability, evidence read access, context-delivery grants and execution readiness are separate facts. A narrow delivery allowlist must not become the owner discovery catalog or justify “no Agent exists.” A discovered relevant owner without a delivery grant is a specific delegation gap, with an existing configuration/recovery route; missing runtime evidence is an unknown-readiness gap. Reuse the broad authorized inventory for investigation, then check the requested effect separately. Shared/external audiences receive only their authorized metadata and evidence; owner-private coverage does not implicitly become group-visible coverage. Do not broadcast private context, discover arbitrary unconnected hosts or expand execution authority through discovery. These are target defaults; the current recipient catalog alone does not implement them.

The existing manager context-delivery catalog now excludes Goals marked stopped in its selected registry, and delivery rechecks that activation guard before creating or replaying an inbox request. A malformed activation state cannot grant a recipient. This is one admission boundary only: a lagging global mirror still needs source-authority reconciliation, and registration does not establish a live session, executable capacity, suitable model or a returned result. Explicit inspection of a stopped Goal remains separate from delivering it new work.

Expand Down Expand Up @@ -506,7 +508,13 @@ The shared [conversation work surface](intelligent-review-presentation-surfaces-

Routing uses §5.5 rather than a static Agent name list. For a product-design request addressed to the steward, first inspect authorized current Goal, registration, claimed work and fresh session reachability; then rank eligible receivers by responsibility and context, with model/profile fit and actual capacity as separate constraints. Explain the selected recipient or the exact gap. The receiver must acknowledge and assess the full corrected intent, then either work or defer with an owner and condition. The original conversation receives the assessment and final evidenced result through §5.6; the catalog, a stored inbox request and a spinner are three distinct incomplete states. This must pass with a real active worker plus stopped, registered-only, stale and model-mismatched decoys before advertising automatic delegation.

Delivery order is: (1) qualify the reusable report, activity and stop/steer surface in Chat, frontend and Lark; (2) add context-affine steward selection through the existing collaboration owner; (3) prove one original-conversation request through real receiver assessment, work and final return. These are independently reviewable slices; the steward product claim waits for the third. Characterize and retire duplicated answer-shape prose and message/Turn correlation rules where parity is proven.
Delivery now prioritizes one complete supported intent→receiver→work→result journey, with the shared report, activity and stop/steer behavior needed by that journey. Do not make routing wait for presentation polish across every channel. Frontend and Lark still need separate real acceptance before an equivalence claim. Characterize and retire duplicated answer-shape prose and message/Turn correlation rules where parity is proven.

The [golden-query pack](../../product/use-cases/steward/golden-queries.md) supplies short user requests and independent outcome/attention oracles. GQ01/GQ02 qualify creation and existing-Agent connection; GQ03/GQ04 qualify responsible dispatch; GQ05/GQ11–GQ13 qualify two-cycle small-team coordination, with GQ07–GQ09 continuity; GQ06/GQ10/GQ14–GQ15 extend materials, attention and replanning. GQ16/GQ17 remain later cross-host/scale qualification. These are scenario tests over existing A1–A24, not new Core protocol states.

When routing fails, distinguish unread/unavailable sources, incomplete or stale directory coverage, no relevant registered owner, unauthorized scope, missing binding, unknown runtime readiness, capacity wait and receiver rejection. Probe/refresh permitted sources and repair an eligible binding through its owner before asking the user to locate an Agent. Registration grants neither reachability nor authority. If no existing receiver qualifies, an already-authorized creation path is valid; otherwise retain the request and ask only for the concrete missing decision. Never select an irrelevant sole candidate or silently replace an explicitly requested model. A well-written recommendation with no requested dispatch is still an undelivered task.

Ordinary follow-ups retain the responsible owner; direct small reads need no team. One binding retains one execution driver. Existing request/outbox and continuous-monitor owners handle event-driven continuation and delayed return; do not compensate with faster polling. Retain useful constraints through scoped context, distinguishing preference, current fact and action grant; optional memory providers remain optional. GQ03's CI example requires causal evidence and all other review blockers, not a blanket approve policy.

## 6. Alternatives and disposition of #4306

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -206,7 +206,9 @@ LoopX 不是只有任务队列。交接应让接收方结合权威状态和持

### 5.5 职责发现与接收方重规划

在已授权主机范围发现所有注册的活跃 Goal 和 Agent。默认排除停止的 Goal,用户明确询问时可读。能发现、能读、能投递上下文、能执行,是四种不同事实。best effort 指管家认真检查职责、当前工作、仓库和可用性;不是群发私人背景或猜身份。
**主人管家默认广泛发现。** 私有管家应发现本机以及已授权接入来源中,主人已登记的 Goal 和 Agent;仅为了找到负责人,不要求逐个加入委派名单。搜索与分页可达完整的允许目录,prompt 或首屏条数上限不能缩小发现范围。停止的 Goal 保留历史/搜索入口,默认不参与工作指派;离线、未绑定、容量不足和在线状态未知的 Agent 仍可发现,并标明实际状态。

能发现、能读证据、能委派、当前能执行,是不同事实。窄委派名单不能充当主人的发现目录,更不能据此回答“没有 Agent”。发现相关负责人但未获委派授权时,明确说明委派缺口及既有配置/恢复入口;缺运行证据则说明就绪状态未知。先复用广泛的已授权目录调查,再按请求效果判断准入。共享/外部受众只能看到该受众已授权的元数据与证据;主人私有可见范围不会自动变成群聊可见范围。不群发私人背景、不探测任意未接入主机,不通过发现扩张执行权限。这是目标默认行为,当前接收者名单本身尚未实现。

优先用户指定接收方;否则基于当前状态选合适责任人。缺少便捷 routing profile 不应让一个已知、已授权的 worker 变得不存在。不能把固定请求目录当唯一职责模型。多个接收者适合时,先选一个评估负责人并说明依据;仅在歧义实质影响权限或结果时询问。没有合适 worker,则自己做允许的工作,或报告真实能力缺口;不偷偷新建用户任务或唤醒已停止 Goal。

Expand Down Expand Up @@ -471,7 +473,13 @@ Stage A 替换当前 Todo note,不提供不可变历史版本或私有 memory

路由沿用 §5.5,而非固定 Agent 名单。管家收到产品设计请求时,先查看获授权的当前 Goal、注册、已认领工作及新鲜的 session 可达性;再按职责与上下文选择合格接收者,单独约束模型/profile 适配和实际容量。说明选择理由或真实缺口。接收者要确认、评估包含历史修正的完整意图,随后执行或明确延期条件和负责人。通过 §5.6 将评估与有证据的最终结果送回原对话;候选列表、已存入收件箱、正在处理是三种不同的未完成状态。对真实活跃 worker 与已停止、仅注册、过期、模型不适配的干扰候选都验收后,才能宣传自动委派。

交付顺序:(1)在 Chat、前端和飞书验收可复用的报告、活动与停止/纠偏界面;(2)通过现有 collaboration owner 做好管家的上下文亲和选择;(3)让同一原始对话经过真实接收方评估、执行与最终回传。各阶段可独立审阅,管家产品主张要等第三阶段。等价行为刻画通过后,消除重复的回答格式说明和消息/Turn 归属规则。
交付改为优先跑通一条已支持的意图→接收者→执行→结果旅程,同批带上它需要的共用报告、活动与停止/纠偏能力。路由不再等待所有渠道的展示打磨;宣称前端/飞书等价前,仍分别完成真实验收。等价行为刻画通过后,消除重复的回答格式说明和消息/Turn 归属规则。

[Golden-query 集](../../product/use-cases/steward/golden-queries.md)提供简短用户请求及独立的结果/注意力验收。GQ01/GQ02 验收创建与接入已有 Agent;GQ03/GQ04 验收找负责人派单;GQ05/GQ11–GQ13 验收两轮小团队协调,GQ07–GQ09 验收连续性;GQ06/GQ10/GQ14–GQ15 扩展材料、注意力和重排。GQ16/GQ17 保留为后续跨主机/规模验收。这些是既有 A1–A24 上的场景,不新增 Core 协议状态。

路由失败要区分:来源未读/不可用、目录不完整/过期、没有职责匹配的注册人、未获授权、缺少绑定、runtime 可执行性未知、容量等待、接收者拒绝。先在许可范围刷新来源、探测和通过原 owner 修复合格绑定,再要求用户定位 Agent;注册本身既不授权,也不证明可达。没有现成接收者时可沿已有授权的创建路径处理;否则保留请求,只询问确实缺失的决定。不误投给唯一但不相关的候选,也不暗中替换用户指定模型。只给出好看的建议却没有执行用户要求的委派,仍是未交付。

普通追问保留原负责人,简单查询直接处理;同一绑定只保留一个执行驱动。事件续接和延迟回传复用既有 request/outbox 与 continuous-monitor owner,不靠提高轮询频率补偿。通过有作用域的上下文复用约束,分别保存偏好、当前事实和动作授权;可选记忆 provider 不变成前置条件。GQ03 的 CI 例子要求查明因果和其他 review blocker,不是无条件 approve 政策。

## 6. 备选与 #4306 裁决

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -727,6 +727,24 @@ same identity, interruption, replay and audience-isolation cases at their own
display densities. This shared contract reuses Chat/session, artifact, and
presentation owners; it creates no second conversation store or scheduler.

**Attention-oriented return.** The original conversation distinguishes requested
results, routine progress and decisions needing the owner. Requested results
return normally; unchanged progress folds into a digest; material decisions show
the concrete object, recommendation, evidence and consequence of inaction.
Keep deeper evidence and the responsible Agent's conversation directly reachable.
A correction made there returns its relevant decision/work change to the steward
through the same request lineage, without copying the entire private dialogue.
Source coverage and unresolved work remain visible. An empty directory or a
saved answer with failed delivery cannot be presented as a successful conclusion.

Creation and first submission are part of this shared surface: preserve the
message and its pending/failed state across navigation or reload, expose a safe
retry/readback, and distinguish Goal created, Agent connected and work started.
An optimistic disappearing composer is not an accepted request. The
[golden-query pack](../../product/use-cases/steward/golden-queries.md) checks these
entry states alongside the full conversation, in packaged frontend and each
claimed channel; it does not specialize activity presentation to reports.

Botmux is an interaction reference: its [live card](https://github.com/deepcoldy/botmux/blob/982e2c9f16e4f45ae2581967bc1a35a286e7bfa2/docs-site/docs/zh/cards.md)
keeps final text ahead of collapsible recorded activity, its [session model](https://github.com/deepcoldy/botmux/blob/982e2c9f16e4f45ae2581967bc1a35a286e7bfa2/docs-site/docs/zh/session-model.md)
distinguishes talk and operation rights, and its [Codex steering study](https://github.com/deepcoldy/botmux/blob/982e2c9f16e4f45ae2581967bc1a35a286e7bfa2/docs/design/2026-05-28-codex-type-ahead-steer-design.md)
Expand Down Expand Up @@ -1065,6 +1083,14 @@ Measure both attention cost and outcome quality:
- model-advice override, hallucination, over-escalation, and dangerous
suppression rates.

The [golden-query evaluation](../../product/use-cases/steward/golden-queries.md)
operationalizes these measures with paired baseline/candidate tasks and separate
per-surface results. Count avoidable finding/context/repetition/chasing/relay work;
report legitimate authorization, goal changes and voluntary learning separately.
Include failed/abandoned attempts and unknown cost/coverage. Silence, a short
answer or fewer messages alone cannot improve the score. All live case outcomes
remain unqualified until their independent evidence exists.

Reducing clicks while lowering accepted outcome quality is a regression, not a
success.

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -568,6 +568,10 @@ Adaptive policy 必须 inspectable、resettable,其输出携带 reason codes

停止和修正绑定当前 session 与 Turn,旧控件不能影响后来的 Turn。停止读回区分真实中断、已经结束、不支持或拒绝。忙时修正要么作为本轮原生 steering 接收,要么带可恢复入口回执明确排入后续回合;完成竞态与丢失 ACK 不能使它无声消失。停止对话 Turn 不隐式影响被委派 worker 的 Todo/lease 或待回传义务。前端与飞书以各自展示密度验收同一身份、中断、重放及受众隔离用例。此共用合同复用 Chat/session、工件和展示 owner,不新增第二套对话存储或调度器。

**以注意力为中心回传。** 原对话区分用户请求的成果、日常进展、需要主人决定的事项:成果正常返回,未变化的进展合并进摘要,重要决定给出具体对象、建议、证据和不处理的影响。保留深入证据及负责人对话的直接入口;在负责人处形成的纠偏,通过同一请求关系将相关决定/工作变化带回管家,不复制整段私人对话。来源覆盖和未完成工作保持可见;空目录或已保存但投递失败的答案都不算成功交付。

创建与首次发送同样属于共用界面:切换页面或刷新后保留消息及 pending/failed 状态,提供安全重试/读回,区分 Goal 已创建、Agent 已接入、工作已开始。乐观清空输入框不等于请求已接收。[Golden-query 集](../../product/use-cases/steward/golden-queries.md)在打包前端及每个对外承诺的渠道检查这些入口和完整对话;中间过程展示不为报告特化。

Botmux 是交互参考:[实时卡片](https://github.com/deepcoldy/botmux/blob/982e2c9f16e4f45ae2581967bc1a35a286e7bfa2/docs-site/docs/zh/cards.md)优先保留最终答复、折叠真实过程;[会话模型](https://github.com/deepcoldy/botmux/blob/982e2c9f16e4f45ae2581967bc1a35a286e7bfa2/docs-site/docs/zh/session-model.md)区分对话权与操作权;[Codex 纠偏研究](https://github.com/deepcoldy/botmux/blob/982e2c9f16e4f45ae2581967bc1a35a286e7bfa2/docs/design/2026-05-28-codex-type-ahead-steer-design.md)记录忙时消息会合并或分开回复。停止能力因后端而异。这些公开来源指导竞态和展示验收,不能替代 LoopX adapter 的真实资格,也不要求把 Botmux 装到已有飞书 token 上。

## 9. 覆盖长程工作的完整生命周期
Expand Down Expand Up @@ -824,6 +828,8 @@ Attention cost 与 outcome quality 必须同时度量:
- Agent throughput、acceptance quality 与 safety outcomes;
- model-advice override、hallucination、over-escalation 与 dangerous suppression rate。

[Golden-query evaluation](../../product/use-cases/steward/golden-queries.md)用成对基线/候选任务及逐入口结果落实这些指标。计量可避免的找人、补背景、重复、催办、搬运;必要授权、主动改目标和自愿学习分开报告。保留失败/放弃样本及未知成本/覆盖,不能靠沉默、短回答或少消息刷高分。真实案例在取得独立证据前均未验收。

减少点击但降低 accepted outcome quality 是回归,不是成功。

## 15. Failure 与 Fallback Rules
Expand Down
Loading
Loading