The predecessor's agent module was retired and its six files stayed on both workstations telling
every session to use tools that no longer exist. Before a successor module is written, the design
needs the decisions it rests on and nothing in the record stated them:
- ADR 0169 (reconstructed) records what the controller shipped on 2026-09-27 without a record: the
operator account is a node fact stated by the operator, the home is derived unless stated, a
resource may be placed under it owned by the account, and a node with no account refuses one.
- ADR 0170 generalises to-be 29 §3's found-vs-owned boundary to every directory under a home: the
module owns the directory and the files it places, writes into the tool's own files for its few
keys, never declares a credential's content, and holds everything else as found — a predecessor's
leftovers included, which the operator removes once.
- ADR 0171 draws the licence line the operator asked to have drawn rather than assumed: the mesh
binds and delivers (to-be 14 and 15 stand), the module alone writes the credential file, refresh
stays central (ADR 0050), a switch is the binding changed through a controller seat verb asked
for via the console, and the token-carrying shell helper is retired. The controller learns
nothing about the agent; that is what "no part" means.
To-be 36 is the module's design: the ownership map per path, the fate of the six predecessor
files, what the three instruction documents say, the licence tools and skill, the console as a
node-scoped provision, the package gap stated honestly, and the order of the build. To-be 14, 29
and 34 carry dated notes; the glossary gains "operator account".
The work order's group-3 question answered: an ordinary module the mesh assigns to the machine a
person sits at, holding a minted credential, calling tools under a manifest grant (invokes), serving
MCP on loopback. Design 34; pointers in 33, 25 and 0095; module check designed into 12 (issue 148);
README stops claiming an indexing nothing provides (issue 006).