A node is a conversation, and that is not the employee model
Moving this out of 0003 and out of its vocabulary. I had spent three attempts fitting the node's own session into the agent-as-employee record, each time bending hired, draining, reassigned and retired to cover something none of them describe. 0003 is back to its original text. It belongs in 0004, under what a node is, because that is what it is -- not a program installed on a node but part of the node. It holds one session permanently, anything in the mesh can message it, and it remembers across callers and across weeks. Its system prompt is the engram, which is recorded here for the first time despite running on every node. Also recorded: it has its own narrower tool list, so it can go and look rather than only report about itself; there is no authorisation between nodes, because every node is the operator's own; and how a node passes a question on is its own business rather than a protocol field. Switched off it still answers, and that is the point of having an off state rather than an absent one. A node with nothing there is a silence somebody has to diagnose. A node that says it is switched off is not. Same rule the host follows about a service that does not exist. 0001's summary is corrected too: it had one row for "agents", which is the conflation being complained about. Two rows now. A node's own session and a hired worker are built from the same parts and run on entirely different terms. Left standing and NOT resolved here: 0001 says a node does not authenticate to a model provider, agents do. A node that holds a session does. That is a real conflict between what is recorded and what runs, and it needs deciding rather than a fourth reconciliation from me.
This commit is contained in:
@@ -51,81 +51,6 @@ when it expires. A temporary employee is still an employee.
|
||||
Some agents are **human**. What differs is modality — how the agent acts — not category. A node
|
||||
itself is an agent of a kind exempt from the hiring lifecycle.
|
||||
|
||||
### The node's own session
|
||||
|
||||
*Written 2026-08-29. The sentence above is the whole of this and had been left as one line, which
|
||||
is why it kept being read as a leftover rather than as the design.*
|
||||
|
||||
**Every node holds one session of its own, permanently.** It listens on its own queue, anything in
|
||||
the mesh may prompt it, and it remembers — what it was asked ten minutes ago and what it was asked
|
||||
last week, across every caller, the way any conversation is remembered by both sides. Its system
|
||||
prompt is the node's **engram**: the personality that makes one node's answers recognisably its
|
||||
own.
|
||||
|
||||
Nothing about it is request-response. A caller asks, the node answers, the exchange stays.
|
||||
|
||||
**It is the same mechanism as a hired agent, and deliberately not the same lifecycle.** That
|
||||
distinction is the answer to a question asked repeatedly and worth settling here:
|
||||
|
||||
| the same | different |
|
||||
|---|---|
|
||||
| a persistent session, accumulating memory, a system prompt, a scoped tool list, addressable by message | how it comes into existence, and whether it can stop |
|
||||
|
||||
**One implementation, two ways of existing: hired, or inherent to a node.** Building the mechanism
|
||||
twice is real duplication and the concern was right; collapsing the lifecycles is the other mistake
|
||||
and it is worse.
|
||||
|
||||
**It is provisioned the ordinary way and made immutable — not held outside the system.** The
|
||||
sentence above says *exempt from the hiring lifecycle*, and the precision matters: it is exempt
|
||||
from **hiring**, not from having a lifecycle. Its lifecycle is the **node's** — provisioned when
|
||||
the node enrols, retired when the node is retired. Same states, a different thing driving them.
|
||||
|
||||
That distinction is what keeps it inside the model. A thing genuinely held outside would have to be
|
||||
special-cased by everything that lists agents; a thing provisioned normally and constrained is one
|
||||
row like any other, and the constraints are **checkable** rather than remembered:
|
||||
|
||||
| | |
|
||||
|---|---|
|
||||
| **cannot be retired, reassigned, or deleted while its node exists** | it *is* that machine's voice — retiring it leaves a node nothing can talk to, moving it puts one machine's mind on another |
|
||||
| **exactly one per node** | with two, nothing decides which replies when the node is addressed; with none, the node is mute |
|
||||
| **may be disabled and re-enabled** | ordinary, and see below |
|
||||
| **its engram may be changed** | its existence is immutable, its personality is not — that is how a node is configured |
|
||||
|
||||
[ADR 0001](0001-mesh-brokers-nodes-host-agents-think.md)'s *the two agent rows per node merge* is
|
||||
the same fact from the other side: **one per node** — not zero, and not two.
|
||||
|
||||
**Disabled is a state that answers.** A node prompted while its agent is disabled replies saying
|
||||
so, immediately, without a model being invoked. It does not time out and it is not silence — the
|
||||
queue is still consumed, and the answer is the state.
|
||||
|
||||
That is the whole reason disabling is better than not provisioning. A node with no agent is a
|
||||
silence somebody has to diagnose; a node whose agent is disabled tells you what is wrong in the
|
||||
reply. It is the same rule the host follows about a service that does not exist, applied here:
|
||||
**absence must never be indistinguishable from a failure to answer.**
|
||||
|
||||
### What is scoped, and what is not
|
||||
|
||||
**Its tool list is its own and narrower than a session a person drives.** The same scoping any
|
||||
agent has; a different list.
|
||||
|
||||
**There is no authorisation between nodes.** Every node is the operator's own, and a prompt from
|
||||
one is a prompt from the operator. Asking a node something is asking a colleague, and colleagues do
|
||||
not present credentials.
|
||||
|
||||
Stated once so it is not discovered later: **the mesh boundary is therefore the security
|
||||
boundary.** Anything inside can reach whatever any node can reach, which is what makes the token
|
||||
and the overlay the entire perimeter ([ADR 0004](0004-a-node-and-how-it-joins.md),
|
||||
[ADR 0007](0007-connectivity.md)).
|
||||
|
||||
**How a node passes a question on is the node's own choice, not a field in a message.** Asked
|
||||
something it must ask a third node about, a node may say who is asking or may simply ask — the way
|
||||
a person relaying a question decides how to phrase it. That follows from the engram, not from a
|
||||
protocol. What it costs is a machine-readable chain of who ultimately asked; what each node was
|
||||
asked, and by whom, remains in that node's own record.
|
||||
|
||||
**A node thinks about one thing at a time**, being one session. Callers queue, and a long answer
|
||||
delays the others.
|
||||
|
||||
## Consequences
|
||||
|
||||
- Memory, workspace and reputation have a subject to belong to. Policy becomes possible: an
|
||||
|
||||
Reference in New Issue
Block a user