Operate an Agent Fleet
DHF keeps every agent flight correctly directed, explicitly authorized, evidence-backed, recoverable, and trusted on arrival.
One Route, Two Views
One system. Leaders see its evolution; practitioners use it to govern each action.
What matters → how capability evolves × how transitions stay safe → trusted outcomes
SessionStart → codex/hooks/dhf_preprompt.py → harness_guard.py → harness_observer.py → scripts/harness_checkpoint.pyBusiness concerns · Evolution · Safe transitions · Trusted outcomes
System view:CAP → BRIDGE × SAFE → TRUSTConcerns · Assurance · Reliability · Evolution
Action view:CAP → SAFE → TRUST → BRIDGECAP · Three Lifelines
Every flight must continue, stay accurate, and act only with authority. Select a card to inspect its control.
BRIDGE · Six Maturity Stages
Move from “the aircraft can fly” to “without authority, it truly cannot.” SAFE applies at every stage.
harness-state.mdphase / handoff
harness_observer.pyJSONL evidence
test_runner.pyschema / fixture
dhf-packet.schema.jsoncore / adapter
dhf_preprompt.pylight / standard / governed
sync_codex_home.shWAL + readback
AIRCRAFT · Eight Context Types
AIRCRAFT is the cockpit checklist: which eight kinds of information should an agent load and trust before acting?
SAFE · Before Every State Change
From gate to taxi, takeoff, flight, and landing, every transition must satisfy all four conditions.
Clear objective, valid authority
trusted facts, recoverable failure
requirements / schema / DoDtool-policy + owner grantobserver + evidence schemasrecover + WAL + checkpointSAFE decides whether work may advance; PROTECT makes that decision enforceable.
Prompts can advise the pilot. Runtime gates are what actually stop unsafe actions.
Before execution:PreToolUse decides; after execution: PostToolUse records; across sessions: SessionStart recovers state.PROTECT · Seven Runtime Controls
One protected promotion transaction advances seven runtime components together; if one target fails, the transaction restores all of them.
codex/hooks/task_state.pycodex/hooks/harness_guard.pycodex/hooks/harness_observer.pycodex/hooks/session_bearing.pycodex/bin/codex-taskcodex/runtime/harness-scope.jsoncodex/runtime/harness-guard-targets.json + scripts/sync_codex_home.shRECOVER · Controlled Resumption
Failure is not a reason to press the button again. Restore facts and continuity, then request fresh authority.
failure_class + receiptdeny / freezeevidence/*.jsonlscripts/harness_recover.pyfresh command receiptcodex/bin/codex-taskscripts/harness_checkpoint.pyTRUST · The Arrival Customers Buy
Customers do not buy checklists. They buy correct, continuous, traceable outcomes created by those controls.
Separate plans, execution, recovery, and success honestly so the result is credible.
Evidence:schema-valid output + independent readbackUse allowlists, canaries, scope, and rollback to bound the blast radius.
deny-by-defaultRisk grading keeps low-risk work light and avoids repeated archaeology.
light / standard / governedResume after interruption or failure from a verified state and next_safe_task.
checkpoint + recoveryA shared receipt schema makes commands, results, timestamps, and ownership auditable.
command / exit_code / key_output / timestampCAP protects the lifelines. BRIDGE grows capability. Load AIRCRAFT context, use SAFE for each transition, and let PROTECT enforce runtime boundaries. When failure strikes, RECOVER before resuming. Deliver TRUST.
Leaders use BEST for the system view · practitioners use CARE for the action view
Ask: Where is the rule? Who authorized it? What ran? Where is the evidence? How do we recover?