Files
hq/00-META
jochen 7b1dabbce0 The operator's agent and its licence manager are modules: ADR 0181–0183, to-be 36 and 39
The predecessor's agent module was retired and its six files stayed on both workstations telling
every session to use tools that no longer exist. This is its successor's design, revised during
review on the operator's directions: the host is module-agnostic, the controller has no part, and a
real licence manager hands out the correct licence in every situation.

- ADR 0181 (reconstructed): the operator account is a node fact stated by the operator; the home is
  derived unless stated; a resource may be placed under it owned by the account; a node with no
  account refuses one. What the controller shipped on 2026-09-27 without a record.
- ADR 0182: inside a home the module owns the directory and the files it places, writes into the
  tool's own files for its few keys, never declares a credential's content, and holds everything
  else as found; a predecessor's leftovers are the operator's to remove once.
- ADR 0183: claude-licence-manager holds the mesh seat anthropic-licence-manager and owns the
  Anthropic licences, grants (encrypted with a key the vault made for it), bindings per touchpoint,
  usage and audit; one rotation source under a lease; a token travels module to module sealed to
  each node's module key on request/reply, never as an event; the agent module alone writes what
  the agent reads; the host delivers package and state and knows nothing else. A bounded exception
  to ADR 0113; dated mechanism notes on ADR 0050 and 0113.
- To-be 36 (claude-code): the mesh's part of the agent's configuration lives in the agent's
  machine-wide managed directory, owned whole by the module and written by its code; nothing under
  the home but the credentials file of a subscription licence; the API-key licence through the
  key-helper; the console as a node-scoped provision (to-be 34 amended); MCP servers as settings
  with an mcp_configure tool; one agent directory per machine shared by every session.
- To-be 39 (claude-licence-manager): store, the two licence kinds, keeping a grant alive, the
  hand-over, who gets which licence with the predecessor's fallbacks, adoption with the identity
  guard, the seat's verbs.

Numbers taken across main and every open branch at the time of the merge; to-be 14, 29 and 34
carry dated notes; the glossary gains "operator account".
2026-10-02 17:22:12 +02:00
..

00-META

The northern star. What the mesh is, the environment it runs in, and what changes when it works — plus the engineering practice that holds across everything Novox builds. Every research effort and design decision is checked against this folder.

File / folder Purpose
mission.md Vision, mission, and the values that decide arguments
context.md The environment — conditions, not aspirations
effect.md What is different when the work is done
how-we-build.md The rules that hold across the mesh, each one earned. The source of the mesh constitution — the governed page the mesh injects into design sessions is derived from it.
glossary.md One name per thing — the authority on vocabulary, and the words that were retired
repos.md Where implementation lives, and what each repository owns
process/ The playbooks — how work moves through this repository, for engineers and agents alike

Rules

  • Markdown only.
  • Stable by nature. Changes here reflect a genuine shift in intent, not iteration. The one exception is how-we-build.md, which changes whenever a rule is earned — and only through its amendment process.
  • Research and design must be traceable back to what is written here.
  • Instance-agnostic. These documents describe the mesh as a concept. No machine names, no counts, no topology.

On the architecture overview in the code repository

The code repository carries an architecture overview predating this folder. It is a useful description of how the mesh works, and its content now lives — anonymised and checked against the implementation — in 03-DESIGN/00-as-is/. GENESIS answers why; that document answered how, which is the design layer's job.

It had also drifted from the implementation in ways worth recording, since both were found by comparing it against the code rather than by anyone noticing:

  • It described the pipeline as having a separate builder process and a build stage that packages. Neither was true after 2026-08-04; the documents stayed stale until 2026-08-06 (ADR 0010).
  • It listed the mesh as spanning a fixed number of named machines, which is exactly the content this repository cannot carry.

It also lists "symlinks, not copies" as a key design principle, and that is a genuine contradiction rather than a stale detail. The mesh's stated intent is that it creates no symlinks at all — the rule is not merely "only the installer may link", and a founding document elevating linking to a principle points the opposite way from where this is going.

What exists today is that the installer owns and reconciles every link (ADR 0012) — an as-is fact, recorded in 03-DESIGN/00-as-is/05-runtime-and-installation.md. Centralising who may link narrowed the incident class; it did not close it. The intent is to remove the mechanism, recorded as ADR 0012.

A founding document contradicting the direction of travel is precisely the failure this folder exists to prevent.