Contracts
Who talks to whom
Members talk to each other only through typed contracts wired into real call sites. No member reads another’s files or tables.
authorize
packages/bouncer/src/authorize.ts
Whether a principal’s roles hold one named privilege on a resource. Every control-plane route calls it with exactly one privilege.
checkHold
packages/bouncer/src/decisions.ts
Whether an outbound request is held for a person’s approval, using the agent’s hold rules.
checkToolApproval
packages/bouncer/src/decisions.ts
Whether a tool call needs a person’s approval, and whether an approval already covers it.
checkStanding
packages/budget/src/standing.ts
Whether an agent is inside its limits. Returns ok, or the first window exceeded: perRun, perDay or perMonth.
costUsd / priceFor
packages/budget/src/pricing.ts
Turns the Executive’s token counts into dollars. TokenUsage is input, output, cacheRead and cacheWrite.
complete
packages/executive/src/complete.ts
Serves one model call: validates the request, finds the provider’s adapter and calls it. Never throws.
checkModel / offeredModels
packages/executive/src/model-policy.ts
Whether an agent may use a model, and which models it may choose from.
createInspector
packages/inspector/src/inspector.ts
The one door for run events, live progress and ledger taps.
createTimekeeper
packages/timekeeper/src/index.ts
Each minute, tells the Landlord which cartridge crons and which schedules are due.
admit
packages/registrar/src/admission.ts
Admits or refuses a pinned commit. The Landlord injects the image build.
AgentRegistry
packages/registrar/src/registry.ts
The agent record and the store behind it.
VersionedConfigStore
packages/registrar/src/config-store.ts
Versioned deployment configuration, including the owners the Bouncer reads.
SystemsStore
packages/registrar/src/systems.ts
System definitions (E10). The Keymaster derives a connection provider from one.
Keymaster.checkout
packages/keymaster/src/keymaster.ts
A credential for one outbound call, as a lease.
SecretProvider
packages/secrets-bind/src/index.ts
Maps a secret’s name to the vault that holds it. One provider per landing zone.
pullMind / pushMind
packages/hydrate/src/index.ts
Copies an agent’s prefix between the mind store and $MEMORY_DIR.
LedgerStore / verifyChain
packages/ledger/src/index.ts
Append a redacted, hash-chained row; verify the chain; seal checkpoints.
AuthProvider / Principal
packages/auth/src/index.ts
Who is calling and with what roles. Authentication only.
GatekeeperIngress
packages/gatekeeper/src/ingress/index.ts
How a message reaches a sleeping agent, and how the Landlord reports the agent’s state back.
createRun and the run lifecycle
packages/landlord/src/lifecycle.ts
Wake, run and stop an agent. Every wake path goes through createRun.