Grilling
Software Factory Runtime and Autonomy Grill Status
| Branch | Completion | Locked direction | Still open |
|---|
| Human-to-factory boundary | 45% | A human explicitly enters Finder, Requirements, or Design. Accepted backlog is the autonomy handoff. Raw ideas and unresolved Fogs never start delivery. | Select the schedulable backlog unit, its exact readiness proof, and trigger semantics. |
| Agent topology | 100% | One factory-managed Main Factory Agent runs the existing Harness Full Delivery flow and orchestrates its ordinary plan-derived worker subagents inside the same thread. No fixed Vercel agent roles. | None. |
| Delivery authority | 45% | Full Delivery continues automatically across its ordinary in-bounds phase and review boundaries. | Select the terminal delivery outcome and authority for merge, deploy, and release actions. |
| Tool and credential security | 45% | A self-hosted Executor Cloudflare Worker behind Cloudflare Access is the MCP/tool gateway. The factory never inherits a human user's credentials. | Select approval semantics, Git transport credentials, policy scope, and rotation. |
| Runtime isolation | 35% | The persistent factory control plane uses a dedicated factory Unix identity and home. Executor is not a shell, filesystem, resource, or network sandbox. | Select where delivery commands and shared worker files execute. |
| Operator experience | 60% | Herdr is the live portal for agent presence, terminals, attention, and inspection. | Decide its command authority, durable history boundary, and whether Backoffice retains a factory graph. |
| Orchestration and evidence | 55% | The retained design uses a Hetzner control plane, Effect for effects and cleanup, XState for legal transitions, Neon for durable event/ledger state, and distinct run/attempt identities. | Reconcile these identities with the selected Story/Task delivery unit, retries, concurrency, and closeout evidence. |
Overall completion: 56%. Shared-understanding confirmation is not-ready.
- Round: R1
- Current frontier: Q5-Q9
- Shared-understanding confirmation: not-ready
| Question id | Prerequisites | Question | State |
|---|
| Q5 | none | What backlog object owns one autonomous Factory Delivery Run? | open |
| Q6 | none | What successful outcome ends the factory's authority for one run? | open |
| Q7 | none | How does an Executor require_approval decision interact with uninterrupted Full Delivery? | open |
| Q8 | none | How does a run receive Git transport credentials? | open |
| Q9 | none | Where do the Main Factory Agent and its worker subagents execute shell and filesystem work? | open |
- Human entrypoints remain human-invoked Finder, Requirements, and Design flows.
- Accepted backlog marks the transition from human decision-making to autonomous delivery.
- Existing Harness Full Delivery is the factory's executable delivery graph.
- One Main Factory Agent owns the run and orchestrates the existing scoped worker model in its thread.
- The factory does not introduce Vercel's four-role agent architecture.
- Executor is self-hosted on Cloudflare and protected by Cloudflare Access.
- Herdr is the live inspection and terminal portal.
- The server uses a dedicated
factory Unix account and home; it does not reuse a human operator identity.
- The existing manual remote environment and factory environment remain distinct identities and lifecycles.
- None yet. Round R1 determines which deployment and operator branches belong to v1.
- Human Intake: Explicit human use of Finder, Requirements, or Design to close product and technical decisions before autonomous delivery.
- Factory Admission: The evidence-backed transition from accepted backlog state into one autonomous delivery run.
- Factory Delivery Run: One durable Main Factory Agent lineage executing one admitted delivery slice through Harness Full Delivery.
- Main Factory Agent: The parent Codex agent managed by the factory. It owns the delivery thread and orchestrates scoped worker subagents.
- Factory Attempt: One execution epoch of a Factory Delivery Run. A retry creates a new attempt without changing the run's accepted goal.
- Executor Gateway: The self-hosted Cloudflare Executor MCP proxy that stores integration credentials and applies tool policies.
- Factory Workspace: The filesystem and command-execution boundary shared by the Main Factory Agent and its worker subagents for one run.
- Herdr Portal: The live operator surface for viewing agents, terminals, attention, and reconnectable sessions.
- Factory Identity: The dedicated Unix
factory account and machine identity used by the persistent factory control plane.
- Full Delivery: Uninterrupted Harness delivery routing through closeout inside accepted goal bounds.
- Human Steering Required: A durable terminal state reached when progress needs authority outside the admitted goal or an explicitly approval-gated action.
- Human Intake produces accepted artifacts and provider backlog state.
- Factory Admission starts one Factory Delivery Run.
- One Main Factory Agent owns one run and its thread.
- The Main Factory Agent and its workers share one Factory Workspace.
- A run may have several sequential Factory Attempts.
- Tool calls cross the Executor Gateway; live inspection occurs through the Herdr Portal.
- The persistent control plane runs as the Factory Identity.
- Humans create or change delivery authority; the factory executes accepted authority.
- Raw ideas, unresolved Fogs, and incomplete decision frontiers are not factory-admissible.
- Backlog existence alone does not prove readiness.
- Full Delivery does not ask for confirmation between ordinary in-bounds steps.
- The Main Factory Agent uses Harness's existing phase and worker graph; the factory does not duplicate it with fixed agent roles.
- Personal Unix homes, personal access tokens, and human browser sessions never become factory credentials.
- Executor protects integration tools and secrets but does not isolate shell, filesystem, CPU, memory, or network activity.
- Herdr exposes live operation; it does not silently become delivery authority or the durable system of record.
- Retry preserves the accepted run goal and creates a new attempt rather than a new product decision.
| Branch | Evidence anchors | Applicable dimensions | Open decisions | Grounding |
|---|
| Human-to-factory boundary | apps/cli/skills/phases/requirements-phase/SKILL.md; apps/cli/skills/phases/design-phase/SKILL.md; apps/wiki/content/docs/harness/entrypoints/finder-phase.mdx; Project Backlog Operating Model grill | authority, readiness, artifact identity, provider state | Q5; later readiness and trigger round | grounded |
| Agent topology | apps/cli/skills/phases/delivery-phase/SKILL.md; apps/cli/skills/agnostic/planning/implement-spec/SKILL.md | orchestration, worker ownership, phase routing, thread lineage | none | grounded |
| Delivery authority | apps/cli/skills/phases/delivery-phase/phases/router.md; Agent Workflow Architecture, Rules, and Autonomy grill | closeout, review budget, handback, external mutation | Q6-Q7 | grounded |
| Tool security | Executor MCP Proxy, Policies, and self-hosted Cloudflare documentation; Executor packages/core/sdk/src/policies.ts | credentials, policy precedence, approval, connection scope | Q7-Q8 | grounded |
| Runtime isolation | Factory resumption handoff; Executor Local CLI and hosted deployment documentation | Unix identity, filesystem, shell, network, secret boundary | Q9 | grounded |
| Operator experience | Factory resumption handoff and accepted Herdr role | presence, terminal attachment, attention, control authority | later round | grounded |
| Orchestration and evidence | Factory resumption handoff and original factory design lineage | state machine, durable ledger, attempt identity, cleanup | later round after Q5-Q9 | grounded |
- “Backlog” names the autonomy boundary but not yet the exact schedulable object or readiness predicate.
- “Autonomous after backlog” does not yet say whether success ends at a reviewed pull request, merge, staging, or production.
- The dedicated Unix account is accepted, but it is not yet clear whether it is only the persistent control-plane identity or also the delivery-workload isolation boundary.
- Executor approval policies can introduce a human stop; their relation to ordinary Full Delivery authority is unresolved.
- Executor can protect GitHub API tools, but ordinary
git fetch, push, and credential helpers need a separate explicit credential path.
- Q5 unlocks exact Factory Admission fields, provider claiming, run identity, and concurrency.
- Q6 unlocks merge/deployment authority, Fog completion evidence, and terminal state design.
- Q7 unlocks Executor policy templates and Herdr attention behavior.
- Q8-Q9 unlock secret injection, workspace lifecycle, cleanup, and retry design.