Inspector
Watches the factory and says what it sees. The Inspector publishes run events, streams live progress, keeps prompt traces, measures the runs, and groups failed runs into incidents. It never decides or acts on what it finds.
- Design rules
- §6.5
- Contracts offered
- 1
- Key flows
- 4
On the job
- Publishes run events to subscribers and the event bus
- Keeps a short, sanitized progress ring per run for live viewing
- Writes and prunes prompt traces when tracing is on
- Groups failed runs into incidents
Not my job
- Block or retry anything. That is a decision, and it belongs to someone else.
- Write the ledger. The Auditor does. The Inspector only taps it.
What Inspector does, step by step
Publish a run event
One hub, many readers.
The Landlord or the Gatekeeper calls publish or publishRun.
The EventHub delivers it to local subscribers such as the console’s live view.
If the event is worth sending to the bus, a sink writes it to the landing zone’s event bus.
tapLedger copies ledger rows into the same hub without writing to the ledger.
Stream a run’s live progress
What the agent is doing right now, safe to show.
The egress’s ProgressEmitter reports each call as it starts and ends.
sanitizeProgress strips anything sensitive and RunProgress keeps a bounded ring for the run.
The console long-polls readProgress and shows the run move.
Keep a prompt trace
Off by default. On when FACTORY_TRACE_PROMPTS is set.
writeTrace stores the call for debugging in the agent’s mind.
pruneTraces removes old traces by the configured limits.
Spot an incident
Triage, not alerting.
incidentsFromRuns groups recent failed runs by agent and cause.
The control plane serves the list and the console shows it. Nobody is paged.
Contracts Inspector keeps 1 offered
- createInspectorused by Landlord, Gatekeeper, Auditor