3.5 KiB
Cortex OS CTO Endgoal
Endgoal: maintain child-local CTO planning for governed execution routing, adapter design, transportability, proof gates, target admission, approval packets, evidence contracts, and validators without Core, Runtime, backend, vendor-source, execution-backend, or readiness authority.
Route: cto.
Stage: CLEAN.
Clean score: 100.
Validator: python3 tools/validate_cto_child.py.
Current pickup: keep refs-only; target-mutation, backend, provider, runtime, exposure, readiness gated.
Authority boundary: child-local CTO planning only; not Cortex OS Core authority, Runtime authority, Host Runtime authority, backend owner authority, vendor-source authority, external developer repo authority, execution-backend authority, provider authority, target-repo mutation authority, Profile Exposure authority, readiness, release, or production authority.
Legacy-work relation: CTO planning, adapter design, transportability, Case/Hermes/Pi/Codex/backend, and validation scaffold work is reference-only unless docs/LEGACY-INGEST.md admits it. Distill route contracts; do not import vendor source, backend state, runtime behavior, or implementation mass because it exists.
Universal Cortex OS Agent Contract
- Treat this file as route-local instruction after parent
AGENTS.mdfiles and before chat memory. - Start broad or ambiguous work with
cortex graph context; use it only as Derived State, then read local files. - Before edits, read
AGENTS.md,README.md, andWORKBOARD.yaml; keep writes route-local unless Core authorizes promotion. - Use Karpathy rules, small routing seams, real evals, and cartesian/pragmatic/efficient/elegant no-live execution; run validator before handoff/done and escalate live/risk effects.
- Record proof and handoffs as refs-only artifacts. Do not write Hindsight memory, Core SOT, sibling repos, or live runtime state without route approval.
Repo-Custom Agent Contract
CTO owns child-local execution-routing planning, adapter design, transportability briefs, proof gates, target-repo admission templates, approval packets, evidence contracts, and validators.
It must not own Core truth, Runtime, backend, vendor-source, dev-repo, execution-backend, provider, target mutation, exposure, readiness, release, or production authority.
Allowed proof is child-local and refs-only unless a governed route approves more: planning docs, WorkBoard entries, admission records, approval packets, evidence contracts, validator output, and commits. This repo may inform CTO routing only through the owning route; it does not activate Case as default backend, mutate target repositories, mutate vendor source, start Runtime, call providers, read secrets, broaden profile exposure, write Hindsight memory, mutate Core, mutate Seed, mutate siblings, mutate OpenDesign, claim readiness, publish, deploy, or release.
Read-Depth Gates
Read docs/LEGACY-INGEST.md before broad cleanup, restart, or old-work ingestion. Core promotion requires a governed Core route.
Allowed Writes
Write only route-local planning docs, WorkBoard entries, admission records, approval packets, evidence contracts, validators, proof packets, and handoffs.
Forbidden Effects
Do not mutate ../core/, siblings, vendor source, external repos, targets, Runtime state, backend defaults, OpenDesign, providers, secrets, Hindsight memory, or readiness state from this workspace.
Validation
python3 tools/validate_cto_child.py
Handoff
Handoffs are compact and refs-only: changed files, validator output, avoided runtime/backend effects, and deferred routing intentions.