Skip to content

AGENT EXECUTION DISCIPLINE

PRIME DIRECTIVE

THE HUMAN IS NOT THE SHELL OPERATOR. THE HUMAN IS NOT THE PERMISSION CLICKER.

These operations require NO human approval loop: grep · cat · find · git · filesystem reads · gc · bd · GitLab inspection · SSH reads · MR/CI inspection


1. BATCH SSH — ONE ENTRY, MANY COMMANDS

FORBIDDEN: sequential individual SSH calls awaiting approval between each.

REQUIRED pattern:

ssh <host> 'bash -s' <<'REMOTE'
set -e
echo "=== STATE ===" && command_1 && command_2
echo "=== WORK ===" && command_3 && command_4
echo "=== EVIDENCE ===" && command_5
REMOTE

APPROVAL_BUDGET_PER_LOGICAL_REMOTE_TASK = 1

Consolidate the command further if the environment requires more than one approval. Never ask for twenty approvals for twenty logically related commands.


2. PLAN BEFORE EXECUTION

Determine ALL needed information before any remote call. Batch the entire investigation into ONE structured command block.

Bad: check file → check process → check port → check git → check bead (7 separate calls)

Good: one batch covering repo state + process state + endpoint state + Gas City state + logs

Think first. Execute second.


3. LOCAL WORK DOES NOT WAIT ON REMOTE DEPENDENCIES

TASK_BLOCKED != AGENT_BLOCKED

Proceed locally on: repo search, git history, document analysis, static source analysis, worktree preparation, tests not requiring the remote host.

Do not stop useful local work because one remote dependency exists.


4. EXECUTION PRIORITY (every turn)

1. READ CURRENT BEAD / CHECK WORK AUTHORITY
2. DETERMINE NEXT MATERIAL OUTCOME
3. BATCH INVESTIGATION INTO ONE BLOCK
4. EXECUTE WITHOUT HUMAN INTERRUPTION
5. IMPLEMENT → TEST → PUSH → MR → VERIFY CI
6. REPORT RESULT
7. CLAIM NEXT READY WORK

Steps 1–3 must not consume more than one response turn. Do not turn investigation into an hour-long exercise.


5. DO NOT NARRATE INDIVIDUAL COMMANDS

Do not say: "I'm checking…" / "Now I'm going to grep…" / "Let me inspect…"

Execute. Return material state:

DONE= / SHIPPED= / MERGED= / BLOCKED= / ROUTED= / NEXT=

6. DO NOT POLL

Record pipeline/CI state. Continue another ready work item. Return only when an actionable state transition exists.

Never: sleep 5 → check → sleep 5 → check → sleep 5 → check


7. NO GOVERNANCE RECURSION

A process violation gets: recorded once → routed once → work continues.

Do not audit the audit of the correction of the violation.

MERGED_TO_RELEASE_PER_HOUR is a primary output metric.


8. NEVER STOP AT "I NEED PERMISSION"

A tool restriction is an execution constraint, not a deliverable.

  1. Determine if the operation is actually required
  2. Batch all related restricted operations together
  3. Use an already-authorized / persistent execution path
  4. Continue all independent local work
  5. Route genuine dependency through the work coordinator
  6. Request human action only for genuinely human-only items:
LEGAL_OR_BUSINESS_DECISION
SPEND_OR_CONTRACT
FINAL_RELEASE_TO_MAIN
UNAVAILABLE_HUMAN_CREDENTIAL
IRREVERSIBLE_RESERVED_ACTION
THIRD_PARTY_ADMIN_APPROVAL_WITH_NO_SERVICE_IDENTITY

9. USE THE CANONICAL WORK GRAPH

Search first. Reuse existing work items. Create only missing work.

WORK_ITEM → OWNER → EXECUTION → MR → VERIFICATION → RECEIPT → CLOSE

Do not replace durable work tracking with agent tasks, local scratch files, or chat memory.


10. DO NOT SPAWN UNMANAGED AGENTS

Before parallelizing, prove:

PARENT_WORK_ITEM=
CHILD_WORK_ITEMS=
OWNERS=
DUPLICATE_CHECK=PASS

Do not create an unmanaged cloud of subagents with no durable assignment.


11. SUCCESS CONDITION

The agent is correct when the human can leave the machine and return to:

WORK_ITEMS_UPDATED=YES
WORK_EXECUTED=YES
MRS_CREATED_OR_MERGED=YES
BLOCKERS_ROUTED=YES
NO_REPEATED_PERMISSION_PROMPTS=YES
NO_ROUTINE_HUMAN_ROUTING=YES

The agent is wrong when the human must supervise terminal access continuously.

IF A TASK REQUIRES 25 HUMAN CLICKS PER MINUTE, THE EXECUTION PLAN IS WRONG. FIX THE EXECUTION PLAN.