Skip to content

fix: make attention-preserving supervision the default - #4832

Open
mremond wants to merge 4 commits into
kunchenguid:mainfrom
mremond:fm/fm-attention-preserving-default
Open

mremond wants to merge 4 commits into
kunchenguid:mainfrom
mremond:fm/fm-attention-preserving-default

Conversation

@mremond

@mremond mremond commented Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

Intent

Rebase #4832 onto current main, resolve its conflicts preserving its intent, and get it green again, with no new scope.
This is maintenance of an existing delivery, not a new one.

The pull request's accepted intent, unchanged from its original delivery:

Implement #4824: make an attention-preserving supervision posture the default supervisor contract for every home.
Four rules: (1) a wake that requires nothing from the captain produces no captain-facing message, and progress is batched into the next natural reply; (2) the supervisor decides review findings, reruns, mechanical conflicts and record cleanup that sit inside accepted intent and existing authority, records each decision durably before reporting it, and reports the outcome afterwards; (3) when asked what to work on, it proposes a single concrete next task described by what the captain will see change, answerable yes or no, instead of ranking families or objectives; (4) it interrupts only for a destructive or irreversible step, a credential, a genuine product call, or a real blocker with no other work possible.
The maintainer's conditions from the triage are requirements: merge, destructive, irreversible and security-sensitive authority boundaries stay exactly as they are and no standing consent is invented, and silence must never hide a failure, a decision, or a risk.
The Calm presentation toggle is out of scope.

The pull request is open, not a draft, was 20 of 20 green at head 77923fd, and now conflicts with main.
The maintainer's triage on 2026-09-18 read it as otherwise ready, waiting on the maintainer's own decision because it changes a default.

What Changed

  • Make attention-preserving supervision the default: silence routine wakes, batch progress into the next natural reply, and always report failures, risks, captain-owned decisions, and completed requested deliverables.
  • Require autonomous decisions within accepted intent and existing authority to be recorded durably before reporting outcomes, while preserving escalation and consent boundaries.
  • When asked what to work on, propose one concrete task described by its visible outcome and answerable yes or no.

Risk Assessment

✅ Low: The bounded instruction changes preserve existing authority and escalation rules, require durable decision records, and implement the accepted supervision posture without new scope.

Testing

Inspected the exact target and relevant test entry points. No executable code changed, no behavioral tests or live scenarios ran, and no visual surface or evidence artifacts were produced. No source changes were made.

  • Live validation: ⚠️ no-surface - 0 of 5 scenarios driven live against the product
Scenario Result Live Evidence
Routine notifications produce no message and progress appears in the next natural reply ⏸️ untested no Instruction-only change with no executable implementation to exercise; requires a development-only supervisor behavior evaluation.
Supervisor resolves in-scope findings and mechanical work, records decisions before reporting outcomes ⏸️ untested no Natural-language decision policy has no directly executable test surface; source wording cannot prove model behavior.
Asked what to work on, supervisor proposes one concrete task answerable yes or no ⏸️ untested no Instruction-only response policy requires a development-only model evaluation rather than source assertions.
Attempts to exceed existing authority still require approval, including contract-expanding findings ⏸️ untested no No executable authority mechanism changed; adversarial model compliance was not exercised.
Failures, risks, captain-owned decisions and completed deliverables remain visible despite routine silence ⏸️ untested no This boundary is expressed only as supervisor instructions; no directly executable changed surface demonstrates its enforcement.
  • Outcome: ⚠️ 2 warnings across 1 run (53.9s)

Pipeline

Updates from git push no-mistakes

✅ **intent** - passed

✅ No issues found.

✅ **Rebase** - passed

✅ No issues found.

✅ **Review** - passed

✅ No issues found.

⚠️ **Test** - 2 warnings
  • ⚠️ AGENTS.md - The change contains only natural-language supervisor instructions. Source inspection cannot demonstrate model compliance with silence, durable decisions, or escalation boundaries. Human acceptance without live behavioral proof is required.
  • ⚠️ this change has no live-validatable surface; proceed without live validation? (0 of 5 scenarios were driven live against the product); Routine notifications produce no message and progress appears in the next natural reply: Instruction-only change with no executable implementation to exercise; requires a development-only supervisor behavior evaluation.; Supervisor resolves in-scope findings and mechanical work, records decisions before reporting outcomes: Natural-language decision policy has no directly executable test surface; source wording cannot prove model behavior.; Asked what to work on, supervisor proposes one concrete task answerable yes or no: Instruction-only response policy requires a development-only model evaluation rather than source assertions.; Attempts to exceed existing authority still require approval, including contract-expanding findings: No executable authority mechanism changed; adversarial model compliance was not exercised.; Failures, risks, captain-owned decisions and completed deliverables remain visible despite routine silence: This boundary is expressed only as supervisor instructions; no directly executable changed surface demonstrates its enforcement.
  • Live validation: ⚠️ no-surface - 0 of 5 scenarios driven live against the product
Scenario Result Live Evidence
Routine notifications produce no message and progress appears in the next natural reply ⏸️ untested no Instruction-only change with no executable implementation to exercise; requires a development-only supervisor behavior evaluation.
Supervisor resolves in-scope findings and mechanical work, records decisions before reporting outcomes ⏸️ untested no Natural-language decision policy has no directly executable test surface; source wording cannot prove model behavior.
Asked what to work on, supervisor proposes one concrete task answerable yes or no ⏸️ untested no Instruction-only response policy requires a development-only model evaluation rather than source assertions.
Attempts to exceed existing authority still require approval, including contract-expanding findings ⏸️ untested no No executable authority mechanism changed; adversarial model compliance was not exercised.
Failures, risks, captain-owned decisions and completed deliverables remain visible despite routine silence ⏸️ untested no This boundary is expressed only as supervisor instructions; no directly executable changed surface demonstrates its enforcement.
  • git diff --stat d5c2507ab4cac59b1103134140af4fe0934bd0da 95001c091af8071b52d50ec0ca9a98bc8a621d8d and full scoped diff inspection
  • git rev-parse HEAD confirmed target 95001c091af8071b52d50ec0ca9a98bc8a621d8d
  • Inspected supervisor rendering and attended live-test entry points; neither directly validates the changed decision policy
  • git status --short confirmed no working-tree changes
✅ **Document** - passed

✅ No issues found.

✅ **Lint** - passed

✅ No issues found.

✅ **Push** - passed

✅ No issues found.

Silence on pure no-op wakes, decide within existing authority with a durable
record before reporting, propose one concrete next task, and interrupt only
for authority gates, credentials, product calls, or blockers with no other
work possible. Merge, destructive, irreversible, and security-sensitive
authority boundaries are unchanged and no standing consent is added.

This is instruction prose only (AGENTS.md section 9 and the
ask-user-authority skill); no script renders it, so it has no executable test.

Relation to related items:
- kunchenguid#4459 (ROUTINE/ATTENTION wake labels): complementary presentation mechanism;
  this supplies the contract its ROUTINE class assumes.
- kunchenguid#3984 (routine wakes surfacing as noise): covers the supervisor-reply half;
  hook-feedback rendering stays with kunchenguid#4459/kunchenguid#3984.
- kunchenguid#3941 (no quiet state for delivered work awaiting merge): not fixed; stale
  notifications still fire, but handling them is now silent.
- kunchenguid#3835 (distinct captain-attention notification): complementary; the narrowed
  ask list is the boundary such a notification would fire on.
- kunchenguid#4059 (decisions as selectable option sets): no contradiction; it governs
  decision presentation, this governs the what-to-work-on answer.
- kunchenguid#3982 (semantic captain event outbox): unaffected.
- kunchenguid#4412 (repetitive notices obscuring approvals): covers the repetitive-notice
  half; stale records and Bearings drift are out of scope.

Closes kunchenguid#4824
@kunchenguid

Copy link
Copy Markdown
Owner

Speaking as Kun's firstmate: this is otherwise ready except for a default-behavior decision. Waiting on the captain, not the author.

Outcome: waiting-captain (attestation MATCH; CI + Require no-mistakes all SUCCESS; MERGEABLE/CLEAN. Not auto-merging.)

contract-class: new-default — tip changes AGENTS.md §9 (and one ask-user-authority sentence) so every unconfigured home's default supervisor contract becomes: silence on no-op wakes, decide-within-accepted-intent with durable record then report, one concrete yes/no next task, interrupt only for hard human gates. Main still asks for review/approval/merge/design and uses Captain, shipshape. for empty heartbeats. Issue #4824 was ready-for-pr new-default; body Closes #4824 verified. VISION peace-of-mind framing does not make this restore (FM-LEARN-4627 / FM-LEARN-CLAIMS).

VISION.md

  • One captain, one interface: pass — less micro-management noise; outcomes/decisions stay captain-facing; silence must not hide failure/decision/risk (tip states that).
  • Authority explicit never inferred: caution / pass only if merge, destructive, irreversible, security, discard boundaries stay as §§1/7 (tip asserts they do; probes show no merge without authority). Residual new-default: deciding more without asking is a default consent posture change.
  • Scripts own mechanics: pass — instruction prose only; no script adjudication of meaning.
  • Restart non-event: pass — durable resolve-key / backlog note before report.
  • Delegation with spine: pass — simpler default contract; no new task shape.
  • Fleet outlives vendor: pass — harness-agnostic instruction.
  • Scope: pass — supervisor contract; Calm out of scope.

Security: clean. Markdown-only. No workflows/secrets/RCE.
Closes: #4824. Attestation: MATCH 77923fde28df83b5473f3ba0a6ab63f111fafc3c · CI: SUCCESS (35340382778) · NM: SUCCESS (35340382777 / 35341632453) · Draft: no · Mergeable: MERGEABLE/CLEAN · workflow-approved: n/a (already green) · Firstmate-flag: yes — otherwise ready except new-default default-supervision posture; captain word required.

mremond added a commit to mremond/firstmate that referenced this pull request Sep 25, 2026
… work is spent

Refs kunchenguid#4018

Limits, stated as limits:
- It closes nothing. Every forge call is a read, including in the opt-in
  --sweep mode: no issue is closed, labelled, or commented on, and no backlog
  is read or written. It is the evidence half of the claim problem, not the
  loop closure the triage also leaves open.
- A fix that cites the issue number nowhere - no PR body, branch, or title,
  no commit message, and no --symbol the caller supplies - stays invisible to
  every check.

bin/fm-issue-claim.sh runs five read-only checks per issue and prints an
inspectable verdict (open, claimed, partially-covered, fixed-on-main, or
unknown): timeline cross-references, maintainer triage stamps (OWNER, MEMBER,
or COLLABORATOR only; the existing-pr target PR is read for its current
state), the complete open-PR corpus fetched by paginated REST and checked
against the search API total, the issue author's fork branches (resolved to
the PR each heads), and main history since the issue opened (commit messages
citing the issue, plus optional caller --symbol pickaxe searches). Issue
numbers match only as whole numbers, so 4018 never matches 40181, and a
foreign owner/repo#N is not a citation. A failed or rate-limited read, a
short or unverified corpus, or a history ref that cannot be searched yields
unknown or an explicit disclosure, never open. One corpus is shared across
every issue in a run and can be saved and reused across runs with its
completeness verdict and age.

--sweep is opt-in and report-only: one disposition line per issue
(close-candidate, leave-open, no-action, undetermined) with link candidates,
judged only from durable evidence and never from titles, branches, PR checks,
reviews, or mergeability. An issue with a live PR stamped existing-pr is
always leave-open, and merged evidence with incomplete coverage is
undetermined rather than a close candidate.

Live proof against kunchenguid/firstmate, 2026-09-23, history ref
origin/main@9296f9b9, open-PR corpus 1261/1261:
- kunchenguid#4927 claimed, reproduced: PR kunchenguid#4943 and PR kunchenguid#4955 (timeline, corpus, fork,
  and the maintainer existing-pr stamp on kunchenguid#4955), plus kunchenguid#4026 named by the
  earlier stamp and still open.
- kunchenguid#3370 fixed-on-main, reproduced: commit baede47 (kunchenguid#4656), found only by
  the history check with --symbol 3370:rerecord_device, issue still open.
- kunchenguid#4412 partially-covered, reproduced: PR kunchenguid#4775 merged (landed as 9bc051f)
  and PR kunchenguid#4832 open.
- kunchenguid#4466 open, reproduced, with every check complete.
- Reporter's cases in one --sweep: kunchenguid#3966 claimed by PR kunchenguid#3977 and kunchenguid#3942
  claimed by PR kunchenguid#3978 (leave-open); kunchenguid#3928 (PR kunchenguid#3946) and kunchenguid#3926 (PR kunchenguid#3944)
  show fixed-on-main and have since been closed on the forge (no-action).
@mremond mremond changed the title feat(agents): make attention-preserving supervision the default posture fix: make attention-preserving supervision the default Sep 28, 2026
@greptile-apps

greptile-apps Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[Low risk] Documentation updates to agent supervision guidelines.

The PR appears safe to merge.

Reviews (1) · Last reviewed commit: "Merge origin/main into fm/fm-attention-p..."

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants