Files
hq/00-GENESIS/mission.md
T
jschoubben 702efca6bb Base layer: the mesh as it is, under the mesh as it should be
HQ held only the to-be. Every reader had to already know the system the
decisions were about, and an as-is claim had nowhere to live except inside
an intention.

Adds 02-DESIGN/00-as-is — eleven documents written from the implementation
and the operational record, not from intent, including the parts nobody
would choose again. The two existing designs move under 01-to-be. Layers
are declared in frontmatter and never mix: a design that ships does not
move, its as-is counterpart is written, and both stand.

Back-fills adr/0001-0014 for decisions taken in implementation and never
recorded — the broker, the module abstraction, the mesh database, managed
files, provisioning, migrations, the workspace removal, failing loudly,
the constitution, application placement, linking, the employee model, the
artifact, the three silos. Each marked reconstructed, dated from the
history, and citing the evidence it was recovered from. The two existing
records renumber to 0015 and 0016 so the ledger runs oldest first;
0017 extends 0015 to modules outside the core, principle only — the
domain list is deliberately not invented here.

how-we-build.md becomes the source of the mesh constitution, with a sync
playbook, so the enforced copy stops being the only one that is true.

Process becomes explicit: five playbooks, eight thin skills that defer to
them, a repository map, and AGENTS.md with CLAUDE.md as its include.

The five Observations become 04-ISSUES 001-005 where they can be owned and
closed. 006 is new and uncomfortable: HQ is not indexed into the knowledge
base. That claim is what decision 27 rests on, it was never checked, and
the README now says so instead of repeating it.

Also corrects the ADR index into something generated, the "02-DESIGN is
empty" claim, the VISION.md pointer that did not survive the repo split,
and a note asserting the symlink rule was contradicted — it was a
misreading; the rule forbids hand-made links, the installer links by design.
2026-08-23 03:08:26 +02:00

73 lines
3.2 KiB
Markdown

---
status: canonical
updated: 2026-08-22
---
# Mission
## Vision
**A mesh that controls itself.**
An agent states an intent — in words, from wherever they already are — and the mesh
carries it out. It takes the request in, works out what it means, does the work across
whichever nodes it needs, and returns a result. No console to open, no runbook to follow,
no remembering which node holds which thing.
Not automation, which does what it was told to do in advance. Self-control: the mesh
holds the context, decides how, and acts.
## Mission
Build the layer that turns a set of nodes into one self-controlling mesh.
- **Intake, process, deliver.** A request arrives, is understood, becomes work, and
returns an answer. That loop is the product; everything else exists to make it possible.
- **Agents inhabit the mesh.** They are not scripts that run and exit. They hold identity,
memory and skills, run on whichever node has room, and act continuously.
- **The mesh brokers everything the work needs.** Storage, credentials, compute,
knowledge, delivery — requested by capability, resolved by the mesh, never by the
requester knowing where things are.
## Agents, some of whom are human
There is one kind of participant: the **agent**. Some agents are human and some are not,
and the mesh does not treat that as a category difference. Both hold identity, both hold
credentials, both act, remember and coordinate. What differs is **modality** — how an
agent acts:
- a non-human agent acts through a spawned session and the record
- a human agent acts through a shell, a desktop, a message from a phone
That is why a desktop environment is as much a core concern as a knowledge store. One is
how some agents remember; the other is how some agents act. Neither is a courtesy
extended to a user outside the system.
### What belongs in the mesh's own domain
A **core** module supports an agent's *participation* — acting, remembering,
coordinating, or interfacing with the mesh.
A media server supports a human, but not their participation. It is therefore not a core
module. It is still a perfectly valid HAL module — the
mesh installs it, provisions for it, brokers its capabilities and ships it through the
same pipeline. Entirely legitimate as a module, and no part of the mesh's own domain.
The distinction is **core module** versus **module the mesh runs**, not module versus
not-a-module. Both use the same manifest, the same pipeline, the same provisioning —
which is exactly what makes the mesh's own components no more privileged than anything
else it carries.
## Core values
- **Evidence over assertion.** A claim that cannot be checked will quietly stop being
true. Say what was measured.
- **Failure must be loud.** The expensive faults are always the silent ones — work that
reported success and did nothing. Prefer failing to lying.
- **The mesh owns the truth.** State lives in the mesh and is derived onto nodes. A file
edited on a node is a bug with a delay on it.
- **Sovereignty.** The mesh runs on nodes it owns. External dependencies are
deliberate and few.
- **Dogfood everything.** The mesh's own components ship through the same machinery as
anything else it runs. If they need an exception, the machinery is not finished.