diff --git a/02-DECISIONS/0003-agents-are-persistent-employees.md b/02-DECISIONS/0003-agents-are-persistent-employees.md index 5bbe516..3f9945c 100644 --- a/02-DECISIONS/0003-agents-are-persistent-employees.md +++ b/02-DECISIONS/0003-agents-are-persistent-employees.md @@ -51,6 +51,62 @@ when it expires. A temporary employee is still an employee. Some agents are **human**. What differs is modality — how the agent acts — not category. A node itself is an agent of a kind exempt from the hiring lifecycle. +### The node's own session + +*Written 2026-08-29. The sentence above is the whole of this and had been left as one line, which +is why it kept being read as a leftover rather than as the design.* + +**Every node holds one session of its own, permanently.** It listens on its own queue, anything in +the mesh may prompt it, and it remembers — what it was asked ten minutes ago and what it was asked +last week, across every caller, the way any conversation is remembered by both sides. Its system +prompt is the node's **engram**: the personality that makes one node's answers recognisably its +own. + +Nothing about it is request-response. A caller asks, the node answers, the exchange stays. + +**It is the same mechanism as a hired agent, and deliberately not the same lifecycle.** That +distinction is the answer to a question asked repeatedly and worth settling here: + +| the same | different | +|---|---| +| a persistent session, accumulating memory, a system prompt, a scoped tool list, addressable by message | how it comes into existence, and whether it can stop | + +**One implementation, two ways of existing: hired, or inherent to a node.** Building the mechanism +twice is real duplication and the concern was right; collapsing the lifecycles is the other mistake +and it is worse. + +**The exemption is not bureaucracy — it removes four states that make no sense.** If a node's own +voice were an ordinary hired agent it could be **retired**, leaving a node nothing can talk to; +**reassigned**, moving one machine's mind onto another; hired **twice**, with no answer to which +replies when the node is addressed; or hired **not at all**, leaving a node with no voice. The +exemption is what makes those unreachable. + +[ADR 0001](0001-mesh-brokers-nodes-host-agents-think.md)'s *the two agent rows per node merge* is +the same fact from the other side: **one per node** — not zero, and not two. + +### What is scoped, and what is not + +**Its tool list is its own and narrower than a session a person drives.** The same scoping any +agent has; a different list. + +**There is no authorisation between nodes.** Every node is the operator's own, and a prompt from +one is a prompt from the operator. Asking a node something is asking a colleague, and colleagues do +not present credentials. + +Stated once so it is not discovered later: **the mesh boundary is therefore the security +boundary.** Anything inside can reach whatever any node can reach, which is what makes the token +and the overlay the entire perimeter ([ADR 0004](0004-a-node-and-how-it-joins.md), +[ADR 0007](0007-connectivity.md)). + +**How a node passes a question on is the node's own choice, not a field in a message.** Asked +something it must ask a third node about, a node may say who is asking or may simply ask — the way +a person relaying a question decides how to phrase it. That follows from the engram, not from a +protocol. What it costs is a machine-readable chain of who ultimately asked; what each node was +asked, and by whom, remains in that node's own record. + +**A node thinks about one thing at a time**, being one session. Callers queue, and a long answer +delays the others. + ## Consequences - Memory, workspace and reputation have a subject to belong to. Policy becomes possible: an