diff --git a/02-DECISIONS/0003-agents-are-persistent-employees.md b/02-DECISIONS/0003-agents-are-persistent-employees.md index 3f9945c..3f26127 100644 --- a/02-DECISIONS/0003-agents-are-persistent-employees.md +++ b/02-DECISIONS/0003-agents-are-persistent-employees.md @@ -75,15 +75,34 @@ distinction is the answer to a question asked repeatedly and worth settling here twice is real duplication and the concern was right; collapsing the lifecycles is the other mistake and it is worse. -**The exemption is not bureaucracy — it removes four states that make no sense.** If a node's own -voice were an ordinary hired agent it could be **retired**, leaving a node nothing can talk to; -**reassigned**, moving one machine's mind onto another; hired **twice**, with no answer to which -replies when the node is addressed; or hired **not at all**, leaving a node with no voice. The -exemption is what makes those unreachable. +**It is provisioned the ordinary way and made immutable — not held outside the system.** The +sentence above says *exempt from the hiring lifecycle*, and the precision matters: it is exempt +from **hiring**, not from having a lifecycle. Its lifecycle is the **node's** — provisioned when +the node enrols, retired when the node is retired. Same states, a different thing driving them. + +That distinction is what keeps it inside the model. A thing genuinely held outside would have to be +special-cased by everything that lists agents; a thing provisioned normally and constrained is one +row like any other, and the constraints are **checkable** rather than remembered: + +| | | +|---|---| +| **cannot be retired, reassigned, or deleted while its node exists** | it *is* that machine's voice — retiring it leaves a node nothing can talk to, moving it puts one machine's mind on another | +| **exactly one per node** | with two, nothing decides which replies when the node is addressed; with none, the node is mute | +| **may be disabled and re-enabled** | ordinary, and see below | +| **its engram may be changed** | its existence is immutable, its personality is not — that is how a node is configured | [ADR 0001](0001-mesh-brokers-nodes-host-agents-think.md)'s *the two agent rows per node merge* is the same fact from the other side: **one per node** — not zero, and not two. +**Disabled is a state that answers.** A node prompted while its agent is disabled replies saying +so, immediately, without a model being invoked. It does not time out and it is not silence — the +queue is still consumed, and the answer is the state. + +That is the whole reason disabling is better than not provisioning. A node with no agent is a +silence somebody has to diagnose; a node whose agent is disabled tells you what is wrong in the +reply. It is the same rule the host follows about a service that does not exist, applied here: +**absence must never be indistinguishable from a failure to answer.** + ### What is scoped, and what is not **Its tool list is its own and narrower than a session a person drives.** The same scoping any