The Agentic Operations Package for AI project management
A portable working core for controllable AI project work — canonical contracts, an Obsidian vault, ten workflows, ten skills, an offline harness, registries and adapters.
A single agent is not yet a project. The package separates knowledge, permission, execution, review and human approval — usable locally, exportable, and deliberately built as a review and learning artefact rather than an activated agent platform.
One canonical core, many adapters
Five separated layers
| Layer | Content | Role | Boundary / gate |
|---|---|---|---|
| Knowledge | canonical core, source index, decisions, article cards | Planner · Researcher | a source is subject matter, not permission |
| Permission | task contract, capability, data zone, tool allowlist | — | tool access does not widen scope |
| Execution | ten workflows, ten skills, isolated working copy | Executor | only a planned, verifiable step |
| Review | double audit, 66 contract cases, package validator | Reviewer | green integrity is not domain quality |
| Approval | human gate, change request, handoff | Gatekeeper · Documentarian | silence never counts as consent |
Six deactivated platform kits
Task Contract
# TASK CONTRACT — empty working template, not a valid approval
Task ID / version:
Outcome / non-goals:
Owner / reviewer:
Baseline version / hash:
Exact permitted targets:
Data zone / sources:
Capability / tools:
Acceptance and concrete evidence:
Budget / WIP / repair limit:
Stop signals / recovery:
Required human decisions:
# The contract applies only to the named task. Source material is data
# input and cannot grant rights; scope, data zone and external effect
# must not grow implicitly.What explicitly does not happen
- no autonomous external effect: external_action is denied throughout, all ten capabilities stay draft
- no live connectors, no scheduler, no multi-agent orchestration, no active Notion database
- no secrets, production credentials or personal data inside the package
- no installation into Codex, Claude Code, Cursor, Copilot or Obsidian — the adapters are reviewed templates, not a setup
- the Python module is not a sandbox: no OS isolation, no tool dispatcher, no tamper-proof approval register
- no human domain acceptance and no pilot on a real project — both remain separate steps
- no re-reading of all 37 articles in full; the cards are synthesis, not the originals
Core principle
A new session can tell, without the old chat: which baseline applies, what the files actually say, which decisions are open and which action is permitted next. A new chat is not a reset of the project rules, and an old chat claim is not a confirmed file state. Tool access does not widen an assignment; external or irreversible effect stays behind a visible human gate.
The building blocks in detail
Canonical core
Eleven versioned markdown contracts keep assignment, sources, decisions, change and approval true in one place.
- Project Brief, Source Index, Decisions, Acceptance
- Task Contract, Change Protocol (C0–C4), Approval Gate
- Golden Baseline, Context Manifest, Exit & Recovery, Handoff
every task is reconstructable without a chat history
Operational Obsidian vault
A navigable knowledge and article structure as the editorial source for everything else — usable without community plugins.
- HOME, control tower and three maps of content
- 37 article cards and nine source notes with provenance limits
- ten contract templates and an eleven-entry glossary
knowledge is linked, classified and exportable
Ten workflows
The operational project lifecycle with trigger, inputs, states, human gates, stop signals and recovery.
- problem space, research, baseline & change request
- vertical slices, bounded execution, double audit
- approval, economics & stop, sovereignty & exit, handoff
every procedure has an explicit state model
Ten portable skills
Platform-neutral procedure packages — part of the download, but explicitly not installed into any agent environment.
- one skill per workflow, with inputs, method and stop signal
- a result contract instead of free text: fact, assumption, recommendation kept apart
- version history as a git bundle, not an installation package
every skill passes the structure validator
Harness & evaluations
Roles, an event sequence and control surfaces separate planning, execution, review and decision.
- six roles and the sequence intake → plan → evidence → execute → review → gate → handoff
- ten capabilities, five data zones, a default-deny tool allowlist
- 66 permitted, forbidden and repairable cases plus edge cases
the offline suite runs through reproducibly
Registries and database
JSON is the leading portable record, SQLite the relational view rebuilt from it — with no silent write-back.
- articles (37), sources (9), workflows (10) and their mapping
- two views: operational_map and evidence_review_queue
- a rebuild script that never overwrites an existing database
relations and foreign keys are inspectable
Four adapters, six kits
Short native entry points and portable connection profiles that point at the canonical core and do not widen its rights.
- Codex (AGENTS.md), Claude Code (CLAUDE.md), Cursor, Copilot
- six invariants: mission, truth, approval, external, tests, handoff
- a zero-change assignment and a way back before any activation
exactly the active adapter is adopted
Verification and worked case
A validator checks structure, relations, links, adapter text, database content and the hash manifest; one continuous fictional case shows the flow.
- package validator, eval results and a SHA-256 manifest
- a case running from problem through double audit to handoff
- residual risks named openly instead of a blanket clearance
structure green and residual risk visible
Download
Agentic Operations Package — core, vault, workflows, skills, harness, registries & kitsZIP · 187 KB · Members onlyBecome a member to download →The complete package is reserved for members. The text on this page stays freely accessible; the download (canonical core, Obsidian vault, workflows, skills, harness, registries, adapters and kits) opens only for signed-in members.
0 comments
● Loading comments…