Cmux contextcontrol
Pick 3: both, different scopes.
Do not replace CMUX with ContextControl, and do not keep ContextControl artificially narrow.
The split should be:
CMUX
= live operator cockpit
ContextControl.ai
= durable human control and governance console
That is the cleanest model.
The current docs already describe CMUX as “operator cockpit only,” alongside Beads as work authority, GitLab as source authority, Orbit/QMD as context aids, and Workspaces as the execution surface. That is still a valid role for CMUX; what is stale is treating it as the only human cockpit. The newer architecture adds a second, durable layer rather than replacing CMUX outright.
Use this answer for the agent:
Choose option 3.
Define the split as:
CMUX = LIVE OPERATOR COCKPIT
- real-time panes
- shell/terminal access
- active agent sessions
- browser/operator interaction
- incident response
- immediate runtime supervision
- ephemeral/current-session operational control
ContextControl.ai = DURABLE HUMAN FACTORY CONSOLE
- Drupal UI
- work graph projection from Beads
- agent and capability inventory
- GitLab MR/pipeline/release state
- Gas City run state
- memory/context review
- proposed/approved/conflicted/stale knowledge
- policy and Cedar decision visibility
- evidence and provenance
- human approvals
- curation and correction
- long-lived organizational state
Hard boundary:
CMUX does not become system-of-record.
ContextControl does not become shell/runtime execution authority.
CMUX answers:
"What is happening right now and how do I operate it?"
ContextControl answers:
"What does the factory know, what is it doing, what requires human judgment, and what becomes durable organizational knowledge?"
Backends retain ownership:
Beads = work authority
GitLab = source/MR/CI/release authority
Gas City = orchestration
GitLab Workspaces = engineering execution surface
Orbit = derived code/SDLC context
QMD = derived docs context
API Schema Registry = capability/contract discovery
Cedar = authorization
kb_cache + ai_context = governed memory
ContextControl.ai = durable human projection/governance UI over those owners
CMUX = live operator cockpit over the running factory
Do not write docs saying ContextControl replaces CMUX.
Instead update stale wording so the architecture has two human surfaces:
1. Operational cockpit: CMUX
2. Durable governance/control console: ContextControl.ai
Then continue the reconciliation using this split.
The shorthand I would standardize in the docs is:
CMUX = OPERATE
ContextControl = UNDERSTAND + GOVERN + CURATE
That resolves the conflict without creating another ownership collision.