Agent-cadence operating design
Status: design record; operational interpretation amended by MP-STREAMLINED-EXECUTION-001
This document records the withdrawal of the proposed nine-day programme activation in pull request #493. It does not create a second execution control plane.
Decision
Programme work proceeds campaign by campaign, not under one global countdown.
- Existing constitutional, programme, repository, and certification authority remains unchanged.
- Each campaign names its bounded question, governed material closure, checks, terminal condition, and nonclaims.
- Every repository workflow passes mandatory execution routing. Work requiring unattended persistence uses an admitted persistent controller; a conversational agent is never the sole long-running controller.
- Multi-session or asynchronous governed work uses admitted durable checkpoint control when available.
- Evidence is bound to the material evidence closure defined by
MP-STREAMLINED-EXECUTION-001. Unrelated movement ofmain, byte-identical synchronization, or commits outside that closure do not invalidate checks, delegated dispositions, or specialist review. - Standing delegated authority executes routine bounded work through merge and protected readback. There is no generic fresh Human Steward approval or independent-review approval gate for routine work.
- Specialist non-author review is reserved for material mathematical certification, source-semantic adjudication, constitutional authority expansion, security-sensitive protection weakening, or external claim promotion. It binds to the material object under review rather than repository-head freshness.
- CI is impact-routed. Expensive formal replay, external replay, full-estate conformance, and publication work runs only when relevant governed inputs change, on explicit dispatch, or on scheduled assurance.
- A campaign may end in success, bounded negative result, characterized blocker, supersession, or withdrawal. Time pressure never upgrades evidence or claims.
Concurrent development
Protected main may advance while a candidate is under review or validation. A candidate does not need a synchronization commit merely to become numerically current with main.
A candidate remains valid when GitHub reports it mergeable, its material closure and relevant protected dependencies are unchanged, its required affected checks pass, and its scope/authority has not widened. A conflict or relevant dependency change requires renewed validation only for the affected closure.
Capacity and priority
Priority is deterministic:
- integrity, protection, and recovery defects;
- completion or safe parking of already-active bounded transactions;
- validated bounded campaign candidates;
- new exploratory work.
Maintenance automation must coalesce obsolete generated candidates instead of accumulating stale branches. CI and review capacity are not reasons to run unaffected work again.
Completion and recovery
There is no programme-wide T0, observation cutoff, or terminal packet. Completion is established separately for each governed work item by its material evidence and protected readback. A replacement agent reconstructs the current position from protected repository and GitHub state, not from conversation.
Historical note
The exact P9D candidate at 4abe7653e74a3a1fd16e8b9e72e5c61646718241 was returned for revision by all ten Council offices. Its fixed clock required unnecessary activation, lineage, state, dependency, cutoff, resource, retirement, and custody machinery. That architecture remains withdrawn. Its adverse review history remains historical evidence and must not be represented as an approval.
MP-STREAMLINED-EXECUTION-001 supersedes the earlier exact-head-everything interpretation and routine approval ceremony recorded in the first version of this document.