A node is a conversation, and that is not the employee model

Moving this out of 0003 and out of its vocabulary. I had spent three attempts
fitting the node's own session into the agent-as-employee record, each time
bending hired, draining, reassigned and retired to cover something none of them
describe. 0003 is back to its original text.

It belongs in 0004, under what a node is, because that is what it is -- not a
program installed on a node but part of the node. It holds one session
permanently, anything in the mesh can message it, and it remembers across
callers and across weeks. Its system prompt is the engram, which is recorded
here for the first time despite running on every node.

Also recorded: it has its own narrower tool list, so it can go and look rather
than only report about itself; there is no authorisation between nodes, because
every node is the operator's own; and how a node passes a question on is its
own business rather than a protocol field.

Switched off it still answers, and that is the point of having an off state
rather than an absent one. A node with nothing there is a silence somebody has
to diagnose. A node that says it is switched off is not. Same rule the host
follows about a service that does not exist.

0001's summary is corrected too: it had one row for "agents", which is the
conflation being complained about. Two rows now. A node's own session and a
hired worker are built from the same parts and run on entirely different terms.

Left standing and NOT resolved here: 0001 says a node does not authenticate to
a model provider, agents do. A node that holds a session does. That is a real
conflict between what is recorded and what runs, and it needs deciding rather
than a fourth reconciliation from me.
This commit is contained in:
2026-08-29 14:17:25 +02:00
parent 079c488d5e
commit 066f14b5f8
3 changed files with 56 additions and 84 deletions
@@ -81,17 +81,18 @@ Four layers. Naming them honestly is worth more than the word on the tin:
| **machines are linked by a private network** | and every machine reaches every other over it |
| **one node holds knowledge of all of them** | the control plane, and only it |
| **modules are how anything is built and delivered** | this *is* the CI/CD, not something beside it ([ADR 0010](0010-delivery.md)) |
| **agents are hired onto nodes and do the work** | the layer the other three exist to carry |
| **every node is a conversation you can address** | it holds a session, it remembers, and any node can message any other ([ADR 0004](0004-a-node-and-how-it-joins.md)) |
| **workers are hired onto nodes to do tasks** | employees, with a lifecycle — a different thing from the row above ([ADR 0003](0003-agents-are-persistent-employees.md)) |
**The fourth row is where the value is, and the first three are what make it possible.** An agent
hired onto one node can reach any other — a shell, a service, a file — because the private network
makes every node reachable and `identity` decides which agents may reach which. **That is the
capability being built**: not machines that can be configured centrally, which is ordinary, but a
set of machines an agent can work across as though they were one.
**The last two rows are not the same thing and the vocabulary of one does not describe the other.**
A node's own session belongs to the node: nobody hires it, it holds no tasks, it is never
reassigned, and it is gone when the node leaves. A worker is an employee — named, hired, drained,
retired, movable. They are built from the same parts and run on entirely different terms, and
collapsing them is how the employee vocabulary ends up stretched over something it does not fit.
The credential belongs to the **agent**, never to the node it is sitting on
([ADR 0006](0006-the-substrate-and-the-control-plane.md)), which is the same rule as *nodes and
agents are decoupled* below, applied to access.
**Where the value is** is that both can reach across the whole set: a shell, a service, a file, or
simply a question to another node. Not machines that can be configured centrally, which is
ordinary, but a set of machines that can be worked across as though they were one.
**This is not a mesh in the peer-to-peer sense and will not become one.** The word describes what
machines can reach, not how they are governed: