The operator's directions, taken during review: the host is module-agnostic and never writes a
vendor's file or anything under a home; the controller has no part; a real licence manager doles out
the correct licence in every situation; it talks to the agent module on every node over the bus; the
seat is named for the vendor, since the agent is coupled to an Anthropic grant, not to "a model".
- ADR 0178 rewritten: `claude-licence-manager` holds the mesh seat `anthropic-licence-manager`, owns
the licences, grants (encrypted with a key the vault made for it), bindings per touchpoint, usage
and audit; one rotation source under a lease; tokens travel module to module sealed to each node's
module key on request/reply, never as an event; the agent module alone writes what the agent reads;
the exception to ADR 0113 stated and bounded. Dated mechanism notes on ADR 0050 and 0113.
- To-be 37 (new): the manager — its store, the two licence kinds, keeping a grant alive, the hand-over,
who gets which licence with the predecessor's fallbacks, adoption with the identity guard, verbs.
- To-be 36 rewritten: the mesh's part of the agent's configuration lives in the agent's machine-wide
managed directory (settings, tool servers, instruction file), owned whole by the module and written
by its code; the home is found except the credentials file; the API-key licence through the
key-helper writes nothing under the home; the console as a node-scoped provision; MCP servers as
settings with an `mcp_configure` tool; the six predecessor files removed by the operator.
- Records 0169–0171 renumbered to 0176–0178 after main gained 0169–0175 today.
The predecessor's agent module was retired and its six files stayed on both workstations telling
every session to use tools that no longer exist. Before a successor module is written, the design
needs the decisions it rests on and nothing in the record stated them:
- ADR 0169 (reconstructed) records what the controller shipped on 2026-09-27 without a record: the
operator account is a node fact stated by the operator, the home is derived unless stated, a
resource may be placed under it owned by the account, and a node with no account refuses one.
- ADR 0170 generalises to-be 29 §3's found-vs-owned boundary to every directory under a home: the
module owns the directory and the files it places, writes into the tool's own files for its few
keys, never declares a credential's content, and holds everything else as found — a predecessor's
leftovers included, which the operator removes once.
- ADR 0171 draws the licence line the operator asked to have drawn rather than assumed: the mesh
binds and delivers (to-be 14 and 15 stand), the module alone writes the credential file, refresh
stays central (ADR 0050), a switch is the binding changed through a controller seat verb asked
for via the console, and the token-carrying shell helper is retired. The controller learns
nothing about the agent; that is what "no part" means.
To-be 36 is the module's design: the ownership map per path, the fate of the six predecessor
files, what the three instruction documents say, the licence tools and skill, the console as a
node-scoped provision, the package gap stated honestly, and the order of the build. To-be 14, 29
and 34 carry dated notes; the glossary gains "operator account".