Files
jschoubben 93a1231e00 Retire the HAL name where it points forward
Skills take the hq- prefix: they are HQ process workflows, not mesh
workflows, and HQ is company-scoped now. hq-new-research, hq-graduate,
hq-new-issue, hq-diagnose, hq-amend-design, hq-handoff,
hq-sync-constitution, hq-status.

Forward-looking prose becomes Novox Mesh or simply the mesh — the root
README, AGENTS.md, the 00-META README, the mission's module example, and
one to-be document that addressed 'someone working on HAL'.

Three categories deliberately keep HAL, per ADR 0027:

The monorepo is still called hal on the forge. repos.md, every code: field
and every located-in: field name a repository that exists under that name,
and renaming them in prose would make them false.

The as-is layer and the research that measured it describe the system that
runs, and that system is called HAL. 124 modules, 9 daemons, a dead
containerised node — those are observations, not intentions.

Records 0001-0026 are immutable. A record says what was decided when it
was decided, and no record is edited for a name.

Also repoints ADR 0022's link at the renamed skill — a path fix, which the
immutability rule permits, not a change of meaning.
2026-08-23 21:26:09 +02:00

73 lines
3.2 KiB
Markdown

---
status: canonical
updated: 2026-08-22
---
# Mission
## Vision
**A mesh that controls itself.**
An agent states an intent — in words, from wherever they already are — and the mesh
carries it out. It takes the request in, works out what it means, does the work across
whichever nodes it needs, and returns a result. No console to open, no runbook to follow,
no remembering which node holds which thing.
Not automation, which does what it was told to do in advance. Self-control: the mesh
holds the context, decides how, and acts.
## Mission
Build the layer that turns a set of nodes into one self-controlling mesh.
- **Intake, process, deliver.** A request arrives, is understood, becomes work, and
returns an answer. That loop is the product; everything else exists to make it possible.
- **Agents inhabit the mesh.** They are not scripts that run and exit. They hold identity,
memory and skills, run on whichever node has room, and act continuously.
- **The mesh brokers everything the work needs.** Storage, credentials, compute,
knowledge, delivery — requested by capability, resolved by the mesh, never by the
requester knowing where things are.
## Agents, some of whom are human
There is one kind of participant: the **agent**. Some agents are human and some are not,
and the mesh does not treat that as a category difference. Both hold identity, both hold
credentials, both act, remember and coordinate. What differs is **modality** — how an
agent acts:
- a non-human agent acts through a spawned session and the record
- a human agent acts through a shell, a desktop, a message from a phone
That is why a desktop environment is as much a core concern as a knowledge store. One is
how some agents remember; the other is how some agents act. Neither is a courtesy
extended to a user outside the system.
### What belongs in the mesh's own domain
A **core** module supports an agent's *participation* — acting, remembering,
coordinating, or interfacing with the mesh.
A media server supports a human, but not their participation. It is therefore not a core
module. It is still a perfectly valid mesh module — the
mesh installs it, provisions for it, brokers its capabilities and ships it through the
same pipeline. Entirely legitimate as a module, and no part of the mesh's own domain.
The distinction is **core module** versus **module the mesh runs**, not module versus
not-a-module. Both use the same manifest, the same pipeline, the same provisioning —
which is exactly what makes the mesh's own components no more privileged than anything
else it carries.
## Core values
- **Evidence over assertion.** A claim that cannot be checked will quietly stop being
true. Say what was measured.
- **Failure must be loud.** The expensive faults are always the silent ones — work that
reported success and did nothing. Prefer failing to lying.
- **The mesh owns the truth.** State lives in the mesh and is derived onto nodes. A file
edited on a node is a bug with a delay on it.
- **Sovereignty.** The mesh runs on nodes it owns. External dependencies are
deliberate and few.
- **Dogfood everything.** The mesh's own components ship through the same machinery as
anything else it runs. If they need an exception, the machinery is not finished.