02
The seven-stage pipeline
Each stage has an owner, a gate, and an artifact.
A stage that cannot prove its evidence blocks the run rather than guessing past it.
01
Brainstorm & intake
Clarify the outcome, constraints, non-goals, and acceptance
evidence. Refuse any plan that would put secrets or private data into prompts. If orchestration
adds no real parallelism or arbiter value, say so and recommend a single agent instead.
02
Build the job graph
Turn the outcome into jobs with explicit task, cwd, timeout,
expected output, and file ownership. depends_on forms the stages. Same-stage jobs run
concurrently only when their ownership and outputs do not overlap.
03
Discover, profile, route, onboard
Build a live runtime inventory, profile each candidate's
permissions, isolation, capture and budgets, then resolve a route by capability and risk tier.
An optional System-1 layer may supply scored signals, and it may only raise a floor, never lower
one. A missing, unauthenticated, or under-controlled candidate cannot satisfy a route. A pinned
runtime that is missing is onboarded as a visible setup step.
04
Apply the safety gate
Confirm every cwd, writable root, and expected side effect.
Least privilege by default; a permission bypass is never enabled — a job that needs more privilege
gets scoped permissions with explicit approval, a stronger external boundary, or it is blocked.
Destructive, deployment, release, or credentialed work needs approval for that exact scope.
05
Dispatch, observe, verify
Create worktrees before dispatch, start independent jobs up
to the concurrency limit, and update state.json on every transition. Capture the
redacted command, bounded stdout/stderr, exit status, wall time, and artifacts, and observe every
attempt until it settles.
06
Arbiter review
A separate judgment route — preferably a different model
family — compares each escalated result against its expected output, runs the declared checks, and
flags contradictions, unsupported claims, and missing artifacts. R2, R3, any job whose artifact is
a verdict on another job's work, and any attempt whose tier a semantic signal raised always
escalate here. Read-only and scoped-write work may clear on a calibrated micro-arbiter gate only
when no risk-floor raise applied. With no different-family route the verdict is labeled
not-independent and the job is blocked, unless a fresh, independently configured
context substitutes.
07
Report
One report.md with per-job status, resolved
runtime and model, tiers, artifacts, errors, the arbiter verdict, reproduction commands, pending
worktree diffs, and the unresolved questions — listed plainly, last.