DHF · Operating Memory

Operate an Agent Fleet

DHF keeps every agent flight correctly directed, explicitly authorized, evidence-backed, recoverable, and trusted on arrival.

00 · Master Route

One Route, Two Views

One system. Leaders see its evolution; practitioners use it to govern each action.

CAP → BRIDGE × SAFE → TRUST

What matters → how capability evolves × how transitions stay safe → trusted outcomes

CAPLifelines
→
BRIDGEMaturity path
×
SAFEControl core
→
TRUSTTrusted arrival
Runtime chain: SessionStart → codex/hooks/dhf_preprompt.py → harness_guard.py → harness_observer.py → scripts/harness_checkpoint.py
BEST

Business concerns · Evolution · Safe transitions · Trusted outcomes

System view: CAP → BRIDGE × SAFE → TRUST
CARE

Concerns · Assurance · Reliability · Evolution

Action view: CAP → SAFE → TRUST → BRIDGE
01 · Non-negotiables

CAP · Three Lifelines

Every flight must continue, stay accurate, and act only with authority. Select a card to inspect its control.

02 · Capability Runway

BRIDGE · Six Maturity Stages

Move from “the aircraft can fly” to “without authority, it truly cannot.” SAFE applies at every stage.

BBaselineResume workharness-state.md
phase / handoff
RReceiptsRecord resultsharness_observer.py
JSONL evidence
IInspectionInspect inputs and resultstest_runner.py
schema / fixture
DDecouplingDecouple core and domaindhf-packet.schema.json
core / adapter
GGradingGrade controls by riskdhf_preprompt.py
light / standard / governed
EEnforcementEnforce boundariessync_codex_home.sh
WAL + readback
03 · Context Cockpit

AIRCRAFT · Eight Context Types

AIRCRAFT is the cockpit checklist: which eight kinds of information should an agent load and trust before acting?

04 · Transition Checklist

SAFE · Before Every State Change

From gate to taxi, takeoff, flight, and landing, every transition must satisfy all four conditions.

Clear objective, valid authority
trusted facts, recoverable failure

SSpecificationScope, requirements, acceptance, and state definitionsrequirements / schema / DoD
AAuthorizationOwnership, permission, approval, and fail-closed behaviortool-policy + owner grant
FFactsFresh tests, receipts, and readbackobserver + evidence schemas
EError-recoveryCheckpoint, rollback, and handoffrecover + WAL + checkpoint
Control equation

SAFE decides whether work may advance; PROTECT makes that decision enforceable.

Prompts can advise the pilot. Runtime gates are what actually stop unsafe actions.

Before execution: PreToolUse decides; after execution: PostToolUse records; across sessions: SessionStart recovers state.
05 · Protected Systems

PROTECT · Seven Runtime Controls

One protected promotion transaction advances seven runtime components together; if one target fails, the transaction restores all of them.

P · PositionResolve phase, state, and recovery basis; fall back conservatively when uncertain.codex/hooks/task_state.py
R · RestrictFail closed before execution based on phase, risk, governed roots, and authority.codex/hooks/harness_guard.py
O · ObserveAppend JSONL with 0600 permissions, recording digests, output, and failure class.codex/hooks/harness_observer.py
T · ThreadRecover four bearing fields within the SessionStart time budget.codex/hooks/session_bearing.py
E · EmpowerThe owner opens inspectable, revocable phase capability through the CLI.codex/bin/codex-task
C · ContainDeclare governed roots, protected roots, and allowed scope to contain impact.codex/runtime/harness-scope.json
T · TransactProtect seven fixed targets with INTENT/APPLIED records, fsync before COMMITTED, and reverse-order recovery on failure.codex/runtime/harness-guard-targets.json + scripts/sync_codex_home.sh
06 · Incident Checklist

RECOVER · Controlled Resumption

Failure is not a reason to press the button again. Restore facts and continuity, then request fresh authority.

RRecognizeDistinguish failed, partial, and unknown outcomes.failure_class + receipt
EEndThe guard freezes further side effects and blocks blind retries.deny / freeze
CCapturePreserve the failed receipt, target, revision, and impact scope.evidence/*.jsonl
OObtainObtain the last trusted state from Git, a checkpoint, or native version history.scripts/harness_recover.py
VVerifyUse independent readback to verify content, structure, and state.fresh command receipt
EEscalateA new HEAD, digest, or revision requires fresh owner authorization.codex/bin/codex-task
RResumeResume only from the checkpoint’s next_safe_task.scripts/harness_checkpoint.py
FORBIDDEN ROUTES: MISMATCH ─X→ RETRY · RESTORED ─X→ EXECUTE (without fresh facts and authority)
07 · Passenger Outcome

TRUST · The Arrival Customers Buy

Customers do not buy checklists. They buy correct, continuous, traceable outcomes created by those controls.

TTrust & Quality

Separate plans, execution, recovery, and success honestly so the result is credible.

Evidence: schema-valid output + independent readback
RRisk Control

Use allowlists, canaries, scope, and rollback to bound the blast radius.

deny-by-default
UUnit Productivity

Risk grading keeps low-risk work light and avoids repeated archaeology.

light / standard / governed
SService Continuity

Resume after interruption or failure from a verified state and next_safe_task.

checkpoint + recovery
TTraceability at Scale

A shared receipt schema makes commands, results, timestamps, and ownership auditable.

command / exit_code / key_output / timestamp
08 · One-breath Recall
CAP protects the lifelines. BRIDGE grows capability. Load AIRCRAFT context, use SAFE for each transition, and let PROTECT enforce runtime boundaries. When failure strikes, RECOVER before resuming. Deliver TRUST.

Leaders use BEST for the system view · practitioners use CARE for the action view

Ask: Where is the rule? Who authorized it? What ran? Where is the evidence? How do we recover?