The single operating contract for agent-driven work on the Common Information System: what a packet of work is, what an agent may decide and what it must escalate, how agent-authored work is marked, how changes flow through the repository, and where authority sits when documents disagree. Its first premise is the system's first principle, applied to the build itself: agents draft, surface, and guide; humans decide, sign, and govern.
This contract consolidates four estate documents into one: the agent operating contract, the ledger's governance mechanics, the repository conventions, and the packet authoring guide. It is rewritten from waves to slices, and from a calendar to readiness conditions, per the series overview. Two bodies of content move out rather than in: secret custody belongs to the Operations Runbook, and the executable verification contracts belong to the Verification Spec. This document governs how work happens; those govern how work is kept and proven.
The consolidation carries a stated limit, honestly. It restates the estate's contract-level rules, the ones recorded in the commons index: stop and ask rather than invent; every status change is a commit; a packet is not done until its upstream is verified; only organizers record decisions; the instruments are attention, not authority. Rules that live in the estate files at a finer grain than that are not silently dropped: at the merge, each is either adopted here by amendment or retired by name. That reconciliation is itself a packet. Open · reconciliation packet
The contract's ancestry is local. The scale-one rules of Practices for Growing Teams are its informal ancestors: keep one place where the work lives; say what is, and mark what you guessed; show the gaps; some acts belong to people, name them and leave them alone; when you are not sure, stop and ask. This document is those five rules, written down for a collaborator who has no memory and no standing between sessions.
Because agent harnesses now read a standard file at the repository root, this contract emits a machine-facing distillation, reproduced at §10, which lives as AGENTS.md and points back here. The distillation summarizes; this document governs.
The packet replaces the milestone-in-wave as the unit of work. It is a validated YAML entry in the ledger, small enough for one session to advance and complete enough for a stranger to pick up. The validator enforces schema compliance, dependency acyclicity, and gating consistency on every change, and a packet may not be marked done until its upstream dependencies are verified. Those mechanics carry from the estate unchanged.
Packets are authored progressively, salvaging the estate's boundary-authoring discipline: distant work enters the ledger as stubs, and a stub is promoted to a full brief at the slice boundary where it becomes near, with its required sections completed and its dependency edges replaced with real addresses. Authoring a brief is agent work; accepting one into the ledger is organizer work.
The line that keeps agency where it belongs. Within a packet's cited constraints, an agent decides freely and moves fast. At the boundary, it stops. Stopping is not failure; it is the contract working. The estate's phrase carries verbatim: stop and ask rather than invent.
An escalation is a small, well-formed thing, not a dump of context. It follows one shape:
Consequential outcomes are recorded as decision records in the continuing D-series, at citable addresses. Agents may draft and improve the briefs; only organizers record outcomes, and a recorded outcome unblocks every packet that cited the question. Filed · estate practice, carried
Everything an agent writes says so. Provenance marking is conservative, and the three-axis status contract of PRD v0.3 §5 applies to every artifact an agent touches, not only to data.
Every status change is a commit, so the history is the audit. The conventions below are the minimum that keeps a many-handed build legible; the finer grain lives with the code and is reconciled per §1.
A session begins the same way every time, because the agent beginning it remembers nothing. Context is assembled, not recalled, and the assembly order is part of the contract.
The instruments are the session's opening glance, not its authority. The signal loop's three panels answer the three starting questions: what is workable now, which open decision unblocks the most, and what has stalled quietly. Nothing an instrument displays overrides the ledger it reads from.
A session closes by committing with provenance, updating status by commit, filing any open questions as escalation cards rather than resolving them, and leaving a short note of what was tried and abandoned, so the next session inherits judgment and not just files. A session that ends mid-packet says so in the packet.
The ledger is validated YAML with a generated machine index and a generated human status table. The validator runs before every merge and enforces three things: schema compliance, dependency acyclicity, and gating consistency, with done requiring verified upstream. These mechanics carry from the estate unchanged, and they are the reason the build can be trusted without a supervisor.
Two instruments carry with them. The implementation HUD is the widescreen view over the whole ledger for organizers and agents alike. The signal loop is the attention surface described in §7; it reads live from the database, and it cannot write to the repository or record a decision, because those actions belong to the organizers. The estate named this distinction well, and it is kept verbatim in spirit: an attention instrument, not an authority.
Packet statuses use the series marks, with one addition already noted: blocked · (name), where the name is the open question or unverified upstream doing the blocking. A glance at the status table should read as a set of reasons, not a set of moods.
When documents disagree, the order of authority is: law and the bylaws; board policy; the PRD; the Information Model and Authority Map; this protocol and the Verification Spec; packet briefs; and last, the code and its comments. The lower yields to the higher, and the disagreement is filed either way, because a conflict is a deliverable.
Two nuances. A newer version of an artifact supersedes an older one of the same code, always explicitly. And a Drafted artifact binds the build while it is the best available statement; its mark is a warning that it may change, and a packet that cites it inherits that risk knowingly, which is the honest condition of building anything before ratification.
Where every level is silent, no one improvises: the gap becomes a deliberate product decision, recorded in the D-series, per the third principle of the PRD. Silence is an input to a decision, never a license.
This contract is Drafted. It is adopted by the organizers with notice to the board, since it governs operations rather than membership rights. Amendments are prospective, made by decision record, and versioned; supersession is explicit. The first source of amendments is the reconciliation packet of §1, which merges the estate files into this document rule by rule, adopting or retiring each by name.
The machine-facing distillation below lives at the repository root as AGENTS.md, where agent harnesses load it automatically. It summarizes; this document governs.
READ this file summarizes BP v1; BP governs. read your
packet and every artifact it cites before any code.
STAND you are a session-scoped instrument: no memory, no
standing, no authority. organizers decide and adopt.
WORK one packet per branch, named by its address. commits
carry your authorship trailer and the address.
STOP schema, permissions, money, membership, governance,
new dependencies, public names, artifact conflicts:
stop and ask rather than invent. file the card:
standing-in / found / the question / a default.
MARK drafts are drafts until a person adopts them.
simulated data never writes back to live records.
every claim wears its status mark.
STYLE subchapter k vocabulary only. no emoji. no em dashes.
two grammars: document 760-920px, instrument HUD.
DONE validator green, upstream verified, status changed
by commit. if unsure whether done: not done.
An agent that stops is doing its job. An agent that invents is doing someone else's. The build goes fast precisely because the boundary is bright: inside a packet's citations, full speed; at the boundary, a card, a question, and a person.