-
Study how OpenCode's session screen presents an agent conversation — OpenCode's session screen is an appending chat transcript with no header or timestamps; only tool output is truncated, submit never waits, Enter submits and Shift/Ctrl/Alt+Enter or Ctrl+J add a newline, the session id appears only on exit, and several of its rules need data Secant's Harness seam does not carry yet.
-
Study how OpenCode's home screen offers commands, themes, and settings — OpenCode's home is a single prompt where a leading / opens a fuzzy command list and ctrl+p a full palette over one registry Secant already depends on; themes preview live, toggled preferences persist in a state-directory KV file while hand-written settings live in a read-only config, and Secant today has a fixed menu, a fixed nord theme, and no saved preferences.
-
Establish which transports T3 Code uses for Claude Code and Codex, and how it switches model and effort mid-Session — T3 Code runs the user's installed claude under the Agent SDK and Codex through app-server; Codex switches model and effort per turn/start, while for Claude it relaunches with resume plus new --model/--effort from its own model manifest, at the cost of an SDK-versus-CLI version axis and claude.ai-login policy risk, and gives no stated reasons for either choice.
-
Study how T3 Code turns Claude Code and Codex events into a conversation — T3 Code normalises Claude Code and Codex traffic into one server-side event union and admits only messages and meaningful activities to the thread, keeping rate limits and usage out of it, pairing tool rows by id, summarising command output, and showing sends and work client-side; Secant's seam lacks call ids, failure states, command output, a Turn-accepted event, and a rule for reasoning summaries.
-
Establish whether Secant's current Harness transports can list and switch model and effort mid-Session — Codex's app-server lists models with effort levels and switches both per turn/start on its stable surface but reports little back; Claude Code's direct stream has no documented listing, switches only through /model and /effort prompt text (typed setters are SDK-internal), reports the serving model but never the effort, and lets CLAUDE_CODE_EFFORT_LEVEL override both.
-
Establish how an agent inside Claude Code or Codex can call a local Secant process, and how Secant can identify the calling Session — A per-Session Secant MCP server works in both Harnesses (Claude Code via --mcp-config, Codex via per-thread thread/start config) and runs outside the command sandbox, while a secant CLI call is blocked by Codex's default sandbox; the server instance itself can identify the Session, env vars are overridable, OS peer credentials are strong only on Linux, and Codex MCP approvals would fail the Turn in today's Adapter.
-
Decide how the gate enforces architecture and tells agents how to fix a violation — A dedicated structural step prints every Secant structural violation as file:line with a rule id, a code-only fix:, and a see: guidance anchor, from a typed rule catalogue; it adds a Module AGENTS.md section check and knip-enforced unused code (reversing "unused is not dead", test use still counts), fails lint on warnings, leaves size, cohesion, complexity, and classes to review, and opens the first pre-public-release milestone.
-
Define agent-declared completion for Interactive agent steps — An opted-in agent calls step done or stage done with a required one-line reason, and Secant applies it as End Step, Continue, or End Stage through the same settlement as the human, only once the Turn ends cleanly; the human keeps every control, an optional agent-Iteration checkpoint (default 100, no ceiling) keeps unattended loops stopping for a human, the manifest adds agentCompletion with optional Entry Turn hint texts, and ADR 0032 supersedes ADR 0020's human-only rule while its Verdict half stands.
-
Choose the channel and caller identification for agent calls to Secant — An agent calls step_done or stage_done on a Secant-hosted loopback MCP server attached to each Session that has an opted-in Step, attributed by a per-Session token to that Session's live Turn with no identity from the agent; Secant's tools are pre-approved in both Harnesses, the reply is accepted, held for review, or refused, the Harness Interface carries opaque call declarations, and Codex MCP approvals and MCP elicitations on both Harnesses stop failing Turns (ADR 0033).
-
Establish how T3 Code and the native Claude Code and Codex clients interrupt a Turn and queue a message typed mid-Turn — Claude Code's Esc keeps the partial work and a mid-Turn Enter is read after the running tool calls; Codex's Enter steers over turn/steer, Tab queues client-side, and Esc interrupts with a <turn_aborted> marker; T3 Code closes and resumes the Claude query, folds a mid-Turn Codex send into the active Turn, and queues in its web client; Secant's current transports can interrupt-and-continue, inject natively (Claude Code best-effort), and queue as the next Turn without a transport change, while today it halts the Run on Interrupt, offers Claude Code no Steer, and refuses a mid-Turn send.
-
Decide how model and effort are chosen and changed within a Harness Session — A Run carries one Model choice of real model and effort (no "Harness default"), preselected from the human's last choice or the Harness's own reported defaults, changeable while the Run is open and requested by every Turn in every Session; Codex applies it on the next turn/start, Claude Code takes typed set_model/apply_flag_settings at once (qualified by get_settings, --resume relaunch fallback), each Turn records requested and effective model and effort, and ADR 0034 supersedes the Run-level immutable Requested model.
-
Decide how the human interrupts a Turn and sends a message while a Turn is working — Interrupt ends only the Turn: the Run waits blocked on the human, an Interactive agent step continues the same Session, and an Agent step's follow-up Turn stays in the same Attempt and advances on a clean end; a mid-Turn message is a native Steer in both Step kinds (Codex turn/steer, Claude Code a uuid-stamped stdin frame), the Turn lasts until every Steer is delivered, Interrupt drops the undelivered ones back to the compose, Claude Code stops with the raw interrupt control request (SIGTERM fallback), headless is unchanged and its gaps are listed in docs/headless-parity.md, and ADR 0035 supersedes the halting Interrupt.
-
Establish how Secant can contain a Harness's descendant processes on Windows (addendum) — A Git Bash fork-and-exec leaves a dead Windows parent and escapes taskkill /T /F, including Claude Code's raw-interrupt kill. A kill-on-close Job Object that allows no breakaway contains every case and survives a Secant crash. bun:ffi CreateProcessW with a job list and node:net named-pipe stdio puts live Claude Code and Codex in it from creation. Such a job also kills processes a Harness detaches on purpose and makes their breakaway fail with error 5. Codex's turn/interrupt leaves commands running, and Git Bash cannot run in Codex's sandbox. Claude Code, OpenCode, and T3 Code rely on taskkill alone.
-
Decide how the Matt Bundle adopts agent-declared completion — grill and plan-tickets opt in to step done only (grill after asking whether the human has anything left; plan-tickets on the human's approval, default text), implement opts in to both with Secant's default step text and a stageDoneWhen that fires only when no open ticket is left (none ready or unreadable: say so and stop), a 50-Iteration Review checkpoint, a new tickets Session for plan-tickets and publish-tickets, prompts stripped of "only the human ends it" lines with skills untouched, and Interactive steps still produce no Run Artifacts (a following Agent step in the same Session does).
-
Prototype the Run Workbench as an agent screen — Layout B (ADR 0036): an appending agent transcript with no header, timestamps, or ids and a Steps sidebar above 120 columns; only shell output truncates, reasoning summaries show as collapsed Thought rows (not private under ADR 0022), OpenCode's scanner marks work, sends clear at once, the four interaction kinds stay distinct, keys move off bare letters, the mouse is on, the transcript overlay retires, everforest is the default theme, and ADR 0024's visibly-distinct rule becomes distinct-as-data; the seam and Projection gaps graduated into three tickets.
-
Establish whether Claude Code's direct stream-json transport emits reasoning summaries, and under which setting — Direct Claude Code 2.1.283/Sonnet 4.6 emits streamed and completed summaries with showThinkingSummaries: true; false/default suppress bodies, a hidden display flag overrides it, and normal Claude/Codex summary formats supply no title or duration, with Codex raw reasoning separate.
-
Decide how Secant contains a Harness's descendant processes on Windows — Process owns at-creation no-breakaway Job Object containment; Windows Interrupt confirms natively when possible, stops the whole owned tree, and exact native resume continues the conversation. Unavailable containment keeps launches available with ordinary cleanup and a polite informational notice; evidence states the active guarantee, and selective stopping that preserves background work is deferred.
-
Decide what the home screen offers: commands and settings — Home is a command launcher with no slash prefix or initial selection; one catalog serves its relevance-ranked search and Ctrl+P's Themes/Quit palette, the 25 themes preview in dark/light, applied appearance survives save failure, and Preferences live in Catalog behind the shared Projection Port with headless settings and next-launch cross-process refresh.
-
Decide the Harness Seam's tool, command, diff, and reasoning-summary events — Identified typed tool rows carry native outcomes, bounded optional live command output, and supplied patches; summaries inherit Harness settings with native duration only, context is reported-only, protocol noise stays out, and Projection retention/history/headless choices remain separate.
-
Decide how a Turn's history grows mid-Turn in the Run Projection and headless --json — Turn rows are stored at item start and settle, never per chunk, with opaque Turn-scoped identity; one per-Session history family serves the newest 200 rows with per-row live previews (full conversation on demand from the details panel); each call keeps a 30,000-character output tail, the Turn diff collapses to changed files, transcript_entry retires, and headless stays stored-only with additive transcript fields (ADR 0039).
-
Decide how typed commands work in the Run Workbench compose — One Secant-owned catalog of App commands serves a / list (first character, prefix highlight, hidden when unavailable, Secant names never forwarded, no inline arguments) and Ctrl+P; ctrl+e is End Step only and End Stage has no key; each Harness declares Harness input rules (Claude Code reserves /clear /new /reset /resume /continue /fork /model /effort /fast /config, Codex nothing), checked on sends, Steers, and Bundle prompts at build, install, launch, and Turn start, with Claude Code commands refused as mid-Turn Steers; @ mentions graduated into their own ticket (ADR 0040).
-
Decide how the Run Workbench compose mentions Workspace files with @ — The @ menu searches filtered Workspace files and folders in both Harness text fields, inserts a path cue with optional textual line range, and sends the same text to both Harnesses; manually typed outside paths pass through, headless gains no picker, and neither content loading nor agent reading is guaranteed.
-
Approve the first pre-public-release Amendment: the no-decision fixes — M7 adds the structural gate before the settled installer, catalog, launch, Transcript, Workbench, Matt Bundle, guidance, and interrupt/Steer fixes; the model picker and full agent-screen redesign follow in the second Amendment.
Destination
A second
Amendmenton Sequence vertical slices, refactoring gates, and legacy deletion adds themilestone(s) for every report on this issue that needed a decision, each backed by a decision closed on this map and ready for
/to-spec. A firstAmendment ships the no-decision fixes earlier. Cutting the public release follows as a human Task outside this map.
Notes
docs/agents/milestones.md: an Amendment addsa spine row, then
/to-spec,/to-tickets, slices underdocs/agents/slicing.md, and an audit.catalog, 4 Start a Run, 5 Run Workbench, 6 Transcript, and the idea "let the agent tell Secant it is done". The
Charting record holds what charting settled, including the no-decision fix
list and answers to the questions the reports raised.
/home/rgarg/Documents/Software_Stuff/opencode) is the default answer for TUI questions: what to show,truncate, colour, and animate. T3 Code (local clone
/home/rgarg/Documents/Software_Stuff/t3code) carriesthe same default authority for Harness orchestration, where OpenCode differs. Either yields to an ADR or to Secant's domain. Code is copied only
through ADR 0018's vendor route for OpenCode, or with MIT attribution for T3 Code.
protocol names, and recovery states move to the details panel or headless diagnostics, or disappear. The Run id stays in Previous Runs and is shown
whenever a Run leaves an active state. Glossary terms stay canonical in code and docs, and on-screen copy uses plain words.
src/branches on a Bundle's identity (slicing rule 6). Behaviour a Bundle author may switch or tune isdeclared in the Bundle manifest, and Secant parses, validates, and applies it. The Matt Bundle is one consumer of a capability, never its design
target.
docs/agents/module-design.md,topology.md, anddependencies.md. Consult/codebase-designwhen adecision moves ownership or adds a Seam.
/grillingand/domain-modeling. Prototype tickets use/prototype. Research tickets are resolved by/researchsubagents, whose findings land under
docs/research/on aresearch/<name>branch. Research reachesmainthrough one PR merged with amerge commit, never squash or rebase, so the pinned links in resolution comments survive; then the branches are deleted.
part by ADR 0032 for opted-in Steps (the agent-declared completion decision).
and Declare supported models and accept a requested model at the Harness Seam #186: a Run-level immutable Requested model, effort left to the user's Harness configuration, and free-text model entry for Claude Code.
Define the truthful Harness capability and Adapter contract: the direct Claude Code CLI transport.
no-work reports.
hard size cap (file growth triggers a cohesion review). "Unused is not dead" came from the M1 audit, not this decision, and is superseded by
the architecture-enforcement decision.
## Starting contextcomment and thewayfinder:context-readylabel(
docs/agents/issue-tracker.md). Whoever closes a ticket curates Starting context for each ticket it unblocks.CONTEXT.mdand its glossary clusters. Agent-declared completion, Human-declared completion, Stage, and EndStep are glossary terms since ADR 0032 (PR docs(adr): let opted-in Interactive agent steps accept agent-declared completion (#243) #251), and Agent call since ADR 0033 (PR docs(adr): carry agent calls to Secant over a per-Session loopback MCP server (#244) #252). Steer and Interrupt are
redefined by ADR 0035 (PR docs(adr): interrupt ends only the Turn and a mid-Turn message is a native Steer (#255) #257), and Reasoning summary is a glossary term since ADR 0036 (PR docs(adr): record ADR 0036, the Run Workbench mirrors the agent (#247) #265).
Decisions so far
Study how OpenCode's session screen presents an agent conversation — OpenCode's session screen is an appending chat transcript with no header or timestamps; only tool output is truncated, submit never waits, Enter submits and Shift/Ctrl/Alt+Enter or Ctrl+J add a newline, the session id appears only on exit, and several of its rules need data Secant's Harness seam does not carry yet.
Study how OpenCode's home screen offers commands, themes, and settings — OpenCode's home is a single prompt where a leading / opens a fuzzy command list and ctrl+p a full palette over one registry Secant already depends on; themes preview live, toggled preferences persist in a state-directory KV file while hand-written settings live in a read-only config, and Secant today has a fixed menu, a fixed nord theme, and no saved preferences.
Establish which transports T3 Code uses for Claude Code and Codex, and how it switches model and effort mid-Session — T3 Code runs the user's installed claude under the Agent SDK and Codex through app-server; Codex switches model and effort per turn/start, while for Claude it relaunches with resume plus new --model/--effort from its own model manifest, at the cost of an SDK-versus-CLI version axis and claude.ai-login policy risk, and gives no stated reasons for either choice.
Study how T3 Code turns Claude Code and Codex events into a conversation — T3 Code normalises Claude Code and Codex traffic into one server-side event union and admits only messages and meaningful activities to the thread, keeping rate limits and usage out of it, pairing tool rows by id, summarising command output, and showing sends and work client-side; Secant's seam lacks call ids, failure states, command output, a Turn-accepted event, and a rule for reasoning summaries.
Establish whether Secant's current Harness transports can list and switch model and effort mid-Session — Codex's app-server lists models with effort levels and switches both per turn/start on its stable surface but reports little back; Claude Code's direct stream has no documented listing, switches only through /model and /effort prompt text (typed setters are SDK-internal), reports the serving model but never the effort, and lets CLAUDE_CODE_EFFORT_LEVEL override both.
Establish how an agent inside Claude Code or Codex can call a local Secant process, and how Secant can identify the calling Session — A per-Session Secant MCP server works in both Harnesses (Claude Code via --mcp-config, Codex via per-thread thread/start config) and runs outside the command sandbox, while a secant CLI call is blocked by Codex's default sandbox; the server instance itself can identify the Session, env vars are overridable, OS peer credentials are strong only on Linux, and Codex MCP approvals would fail the Turn in today's Adapter.
Decide how the gate enforces architecture and tells agents how to fix a violation — A dedicated structural step prints every Secant structural violation as file:line with a rule id, a code-only
fix:, and asee:guidance anchor, from a typed rule catalogue; it adds a ModuleAGENTS.mdsection check and knip-enforced unused code (reversing "unused is not dead", test use still counts), fails lint on warnings, leaves size, cohesion, complexity, and classes to review, and opens the first pre-public-release milestone.Define agent-declared completion for Interactive agent steps — An opted-in agent calls step done or stage done with a required one-line reason, and Secant applies it as End Step, Continue, or End Stage through the same settlement as the human, only once the Turn ends cleanly; the human keeps every control, an optional agent-Iteration checkpoint (default 100, no ceiling) keeps unattended loops stopping for a human, the manifest adds
agentCompletionwith optional Entry Turn hint texts, and ADR 0032 supersedes ADR 0020's human-only rule while its Verdict half stands.Choose the channel and caller identification for agent calls to Secant — An agent calls
step_doneorstage_doneon a Secant-hosted loopback MCP server attached to each Session that has an opted-in Step, attributed by a per-Session token to that Session's live Turn with no identity from the agent; Secant's tools are pre-approved in both Harnesses, the reply is accepted, held for review, or refused, the Harness Interface carries opaque call declarations, and Codex MCP approvals and MCP elicitations on both Harnesses stop failing Turns (ADR 0033).Establish how T3 Code and the native Claude Code and Codex clients interrupt a Turn and queue a message typed mid-Turn — Claude Code's Esc keeps the partial work and a mid-Turn Enter is read after the running tool calls; Codex's Enter steers over
turn/steer, Tab queues client-side, and Esc interrupts with a<turn_aborted>marker; T3 Code closes and resumes the Claude query, folds a mid-Turn Codex send into the active Turn, and queues in its web client; Secant's current transports can interrupt-and-continue, inject natively (Claude Code best-effort), and queue as the next Turn without a transport change, while today it halts the Run on Interrupt, offers Claude Code no Steer, and refuses a mid-Turn send.Decide how model and effort are chosen and changed within a Harness Session — A Run carries one Model choice of real model and effort (no "Harness default"), preselected from the human's last choice or the Harness's own reported defaults, changeable while the Run is open and requested by every Turn in every Session; Codex applies it on the next
turn/start, Claude Code takes typedset_model/apply_flag_settingsat once (qualified byget_settings,--resumerelaunch fallback), each Turn records requested and effective model and effort, and ADR 0034 supersedes the Run-level immutable Requested model.Decide how the human interrupts a Turn and sends a message while a Turn is working — Interrupt ends only the Turn: the Run waits
blockedon the human, an Interactive agent step continues the same Session, and an Agent step's follow-up Turn stays in the same Attempt and advances on a clean end; a mid-Turn message is a native Steer in both Step kinds (Codexturn/steer, Claude Code a uuid-stamped stdin frame), the Turn lasts until every Steer is delivered, Interrupt drops the undelivered ones back to the compose, Claude Code stops with the rawinterruptcontrol request (SIGTERM fallback), headless is unchanged and its gaps are listed indocs/headless-parity.md, and ADR 0035 supersedes the halting Interrupt.Establish how Secant can contain a Harness's descendant processes on Windows (addendum) — A Git Bash fork-and-exec leaves a dead Windows parent and escapes
taskkill /T /F, including Claude Code's raw-interrupt kill. A kill-on-close Job Object that allows no breakaway contains every case and survives a Secant crash.bun:ffiCreateProcessWwith a job list andnode:netnamed-pipe stdio puts live Claude Code and Codex in it from creation. Such a job also kills processes a Harness detaches on purpose and makes their breakaway fail with error 5. Codex'sturn/interruptleaves commands running, and Git Bash cannot run in Codex's sandbox. Claude Code, OpenCode, and T3 Code rely ontaskkillalone.Decide how the Matt Bundle adopts agent-declared completion — grill and plan-tickets opt in to step done only (grill after asking whether the human has anything left; plan-tickets on the human's approval, default text), implement opts in to both with Secant's default step text and a
stageDoneWhenthat fires only when no open ticket is left (none ready or unreadable: say so and stop), a 50-Iteration Review checkpoint, a newticketsSession for plan-tickets and publish-tickets, prompts stripped of "only the human ends it" lines with skills untouched, and Interactive steps still produce no Run Artifacts (a following Agent step in the same Session does).Prototype the Run Workbench as an agent screen — Layout B (ADR 0036): an appending agent transcript with no header, timestamps, or ids and a Steps sidebar above 120 columns; only shell output truncates, reasoning summaries show as collapsed Thought rows (not private under ADR 0022), OpenCode's scanner marks work, sends clear at once, the four interaction kinds stay distinct, keys move off bare letters, the mouse is on, the transcript overlay retires, everforest is the default theme, and ADR 0024's visibly-distinct rule becomes distinct-as-data; the seam and Projection gaps graduated into three tickets.
Establish whether Claude Code's direct stream-json transport emits reasoning summaries, and under which setting — Direct Claude Code 2.1.283/Sonnet 4.6 emits streamed and completed summaries with
showThinkingSummaries: true; false/default suppress bodies, a hidden display flag overrides it, and normal Claude/Codex summary formats supply no title or duration, with Codex raw reasoning separate.Decide how Secant contains a Harness's descendant processes on Windows — Process owns at-creation no-breakaway Job Object containment; Windows Interrupt confirms natively when possible, stops the whole owned tree, and exact native resume continues the conversation. Unavailable containment keeps launches available with ordinary cleanup and a polite informational notice; evidence states the active guarantee, and selective stopping that preserves background work is deferred.
Decide what the home screen offers: commands and settings — Home is a command launcher with no slash prefix or initial selection; one catalog serves its relevance-ranked search and Ctrl+P's Themes/Quit palette, the 25 themes preview in dark/light, applied appearance survives save failure, and Preferences live in Catalog behind the shared Projection Port with headless settings and next-launch cross-process refresh.
Decide the Harness Seam's tool, command, diff, and reasoning-summary events — Identified typed tool rows carry native outcomes, bounded optional live command output, and supplied patches; summaries inherit Harness settings with native duration only, context is reported-only, protocol noise stays out, and Projection retention/history/headless choices remain separate.
Decide how a Turn's history grows mid-Turn in the Run Projection and headless --json — Turn rows are stored at item start and settle, never per chunk, with opaque Turn-scoped identity; one per-Session history family serves the newest 200 rows with per-row live previews (full conversation on demand from the details panel); each call keeps a 30,000-character output tail, the Turn diff collapses to changed files,
transcript_entryretires, and headless stays stored-only with additive transcript fields (ADR 0039).Decide how typed commands work in the Run Workbench compose — One Secant-owned catalog of App commands serves a
/list (first character, prefix highlight, hidden when unavailable, Secant names never forwarded, no inline arguments) and Ctrl+P;ctrl+eis End Step only and End Stage has no key; each Harness declares Harness input rules (Claude Code reserves/clear /new /reset /resume /continue /fork /model /effort /fast /config, Codex nothing), checked on sends, Steers, and Bundle prompts at build, install, launch, and Turn start, with Claude Code commands refused as mid-Turn Steers;@mentions graduated into their own ticket (ADR 0040).Decide how the Run Workbench compose mentions Workspace files with @ — The
@menu searches filtered Workspace files and folders in both Harness text fields, inserts a path cue with optional textual line range, and sends the same text to both Harnesses; manually typed outside paths pass through, headless gains no picker, and neither content loading nor agent reading is guaranteed.Approve the first pre-public-release Amendment: the no-decision fixes — M7 adds the structural gate before the settled installer, catalog, launch, Transcript, Workbench, Matt Bundle, guidance, and interrupt/Steer fixes; the model picker and full agent-screen redesign follow in the second Amendment.
Not yet specified
CLAUDE_CODE_EFFORT_LEVELlock, and"this model has no effort setting" (decided in ADR 0034). The Run Workbench's pending and applied display is settled by ADR 0036.
Out of scope
Preserving background work on Windows Interrupt through selective foreground stopping: deferred to a future release, beyond this pre-public-release effort (Decide how Secant contains a Harness's descendant processes on Windows — future-version option).
Cutting the public release itself: the human release Task through ADR 0027's protected path, after the milestones close.
Production implementation during wayfinding.
Adopting the Effect library: a whole-codebase paradigm change, not a pre-release fix; revisit as its own effort after the public release
(the architecture-enforcement decision, item 15).