CtrlK
BlogDocsLog inGet started
Tessl Logo

jbaruch/coding-policy

General-purpose coding policy for Baruch's AI agents

73

Quality

91%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Overview
Quality
Evals
Security
Files

SKILL.mdskills/herdr-foreman/

name:
herdr-foreman
description:
Run Herdr rounds as a nonworking foreman on a selected, verified tier: assign, supervise, accept or reject, never do the crew's work. Covers on-demand specialists, model tiers, bounded briefs, report verification, and release gates. Use for requests to dispatch the Herdr team, balance worker usage, collect reports, run or retrieve retrospectives, catch up on outstanding user attention, curate team lessons, save and resume foreman handoffs, or report a task's cost or resource use through acceptance. Live rounds require HERDR_ENV; saved memory, attention and cost reports work offline. Other standalone tasks skip this skill.

Herdr Foreman Skill

Process steps in order. Do not skip ahead.

Before any finish with enrolled work, reconcile the whole fleet under references/supervision.md. Continue observation or persist an authorized pause or handoff covering every active assignment. Keep user attention visible under references/attention.md.

Before any team-round action, read the team-round contract in full. It is the file rules/agent-team-operation.md points to, and it binds every step below. Every worker brief names it as a required read.

skills/herdr-foreman/references/team-operation.md

You run on the foreman's selected tier: the operator's coordination row, resolved through select_tier and checked against the capability table (skills/herdr-foreman/references/team-operation.md Foreman Seat).

Each command resolves CP to the local or home plugin, or to . in a coding-policy clone; anywhere else it stops with an install instruction. Repeat its resolver in every call. Prose skills/... paths are relative to that root.

Before each decision, load its records and read every listed file:

CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/foreman.sh" load-set --decision <plan|brief|gate|diagnose> --task <task>
CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/foreman.sh" load-set --decision wake --enrollment <enrollment-id>
DecisionStepTarget
planStep 5--task
briefStep 7--task
wakeStep 11, per wake event--enrollment
gateStep 12--task
diagnoseStep 13, diagnosis mode--task

It prints JSON whose files list is the floor for that decision; a file with present: false is a gap to resolve, not one to skip. A non-zero exit names a refused task, enrollment or unreconciled dispatch on stderr; resolve it first. The contract is skills/herdr-foreman/references/working-memory.md "Load a decision's records".

  • Run each step's commands as that step documents them
  • Never write a throwaway helper script in a scratch directory
  • Never name a scratch file in a handoff
  • A command sequence you repeat across tasks belongs in a tested script shipped with this skill
  • Record such a sequence as a follow-up
  • Never script such a sequence locally

References:

skills/herdr-foreman/references/herdr.md
skills/herdr-foreman/references/round-flow.md
skills/herdr-foreman/references/round-setup.md
skills/herdr-foreman/references/task-ledger.md
skills/herdr-foreman/references/retrospectives.md
skills/herdr-foreman/references/working-memory.md
skills/herdr-foreman/references/attention.md
skills/herdr-foreman/references/supervision.md
skills/herdr-foreman/references/assignment-reasoning.md
skills/herdr-foreman/references/specialists.md
skills/herdr-foreman/references/judge-round.md
skills/herdr-foreman/state-schema.md

Step 1 — Determine the Mode

A refusal naming the legacy teamlead default home is a one-time operator step, not a mode: record it as a user-attention blocker naming foreman migrate-home (skills/herdr-foreman/state-schema.md Home Migration), and run nothing else until the operator has stopped every foreman and run it.

Four request kinds are answered offline, need no live Herdr, and finish here after the requested operation. Each reference carries its own owner commands and their contracts. Use the recorded state override or default, report any non-zero diagnostic, and never fabricate missing history. They grant no new task authority.

  • Catch-up or saved attention — references/attention.md. Read all attention pages before claiming completeness.

  • Lesson curation, saved foreman context, or a foreman handoff — references/working-memory.md.

  • A saved retrospective — references/retrospectives.md. Report the note's date, coverage, conclusions, and path.

  • A task's cost or resource use — run the read-only report, omitting --task for every task:

    CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
    bash "$CP/skills/herdr-foreman/foreman.sh" cost-report --task <task>

    It prints JSON with a tasks list and an unrecorded list. Relay each quantity separately, and every unknown value as unknown. Never total the quantities or claim a saving. A non-zero exit writes its diagnostic to stderr for an unusable state file or an unknown task; report it and stop. The output contract is skills/herdr-foreman/state-schema.md (Writer / Reader Contract).

For every other request, read HERDR_ENV before running scripts.

  • Unset or empty — this skill does not apply. Say so and do the task directly, without roster calls, briefs, provisioning, reports, or simulated worker roles. Finish here.
  • Set, with a team task or new retrospective — Proceed to Step 2.
  • Set, with a lookup, a file inspection, research, a bounded question, a review of existing code, a repository edit, or any other task deliverable — a round, whatever its size. None of it is foreman work. Staff it in Step 5. Proceed to Step 2.
  • Set, none of the above applies, and the answer is already in the foreman's context — say it. Finish here.

Step 2 — Run the Round Preflight

One call answers every deterministic check a round start owes: Herdr and the roster, authority for the repo, measured headroom, the capability table's cadence, and worktree hygiene.

CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/round-preflight.sh" \
  --repo <owner/repo> --checkout <shared-checkout>

Emits one JSON object: ready, the blocking reasons, the cadences that are due, and each check's own payload under checks. Exit 1 is a verdict, not a failure — something blocks the round. Exit 2 means the preflight could not answer.

Before following any route below, report the worktree sweep to the operator:

  • When checks.worktrees.detail is present, relay its report verbatim

  • The sweep builds that report (skills/herdr-foreman/sweep-worktrees.sh, report_text); never reshape or summarize it

  • When checks.worktrees has no detail, report its reason verbatim; a status ok with no detail means the worktree root does not exist, and there is nothing to report for it

  • On exit 2 there is no JSON; report the stderr diagnostic instead

  • Raise each dirty or unpushed item the report lists per rules/hook-action-reporting.md Act on What It Names; the operator carries out the resolution chosen, and the foreman runs none of it

  • Exit 0 — read due, satisfy any cadence it names, and proceed to Step 5. A resumed foreman proceeds to the stow's continuation step instead (Step 17 Resume Route). When due names the capability table, dispatch the refresh consultation under references/model-tiers.md, then record its report and show the result:

CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/foreman.sh" capability-record --record <report.json>
CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/foreman.sh" capability-show
  • Exit 1 — report the blocking reasons verbatim. Each names the command that produced it; re-run that one, not the preflight. A foreman_tier block beside a failed headroom check waits on that measurement; fix it first. Otherwise it means this pane does not run the foreman's selected tier: record a user-attention blocker naming start-foreman (skills/herdr-foreman/references/model-tiers.md Foreman Seat) and finish here.
  • Exit 2 — report the diagnostic and finish here.

On exit 0 or 1, a checks.foreman_tier status unconfigured blocks nothing: relay its detail.warning verbatim before routing.

The blocker quotes the restart the operator runs from another shell, naming an empty Herdr shell pane; never run it from the foreman's own pane:

CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/foreman.sh" start-foreman --pane <pane-id>

Which checks run, and which exit codes they fold into blocking, are the script's decision contract — see skills/herdr-foreman/round-preflight.sh, not restated here (rules/script-as-black-box.md).

Steps 3 and 4 remain the individual commands, for a caller that needs one on its own. A round start runs this instead of all of them. The roster has no step of its own; inspect it directly when only the live workers are wanted:

CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/roster.sh"

Emits the caller and live workers with kind, pane, and state. An empty roster on exit 0 means unnamed panes: report them from herdr agent list with the correcting herdr agent rename <pane-id> <name> command.

Record staffing gaps under references/round-setup.md. Leave unused specialist profiles unlaunched. Never duplicate targets or fold verification onto a contributor. Start workers in YOLO mode under references/model-tiers.md; preserve it on relaunch. Verify live permission flags before dispatch, including existing workers. Record task authorization and permitted actions under the round-setup reference. Create or resume the stable ledger under references/task-ledger.md; record its absolute path before dispatch. Apply the round-setup accepted-behavior, resume and supervision binding requirements.

Run references/retrospectives.md on resume, before planning, or for an explicit retrospective request. For an explicit request, complete a new retrospective and finish here.

Proceed immediately to Step 5, or on a resume to the stow's continuation step.

Step 3 — Verify Authority for the Repo

Step 2 runs this. Use it alone when only the authority answer is wanted.

CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/verify-authority.sh" <owner/repo>

Record the emitted namespace ownership evidence using Step 3 of references/round-setup.md. For a non-owned repo, reuse explicit per-action operator permission; absent permission, remain read-only or finish here. On non-zero, report the diagnostic and finish here.

Proceed immediately to Step 4.

Step 4 — Measure Headroom

Step 2 runs this. Use it alone to re-measure, which the judge round does.

CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/foreman.sh" measure

Emits and saves headroom, windows, state, tier_billing, and failed_agents. Busy workers are skipped. Unmeasured billing stays unknown. Report failed measurements and obtain their readings before relying on those seats.

Usage and --trace contracts:

skills/herdr-foreman/references/round-setup.md

Proceed immediately to Step 5 once the required readings are available.

Step 5 — Plan the Roles

Read the open tasks waiting for a seat, oldest first:

CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/foreman.sh" foreman-queue

It prints {"schema_version": 1, "queue": [...]}. Each entry names task, waiting_for (a list of developer, reviewer or tester), dispatched_seats, since, developer and fix_round. A non-zero exit names an unusable state file on stderr; restore it before planning. Tasks with an active worker are omitted. A partitioned verifier stays listed with its dispatched slices; check them against the validated partition. The order is a default; choose another when the round needs it.

Choose the responsibilities needed next under references/specialists.md. Supply its requirements file for specialized work. Schedule consultation and verification as the task needs them. plan bars a developer reserved to another task and a worker with an active enrollment, and names each bar in its rationale; do not pass --exclude for either. apply re-reads the reservations before sending. Reusing a reserved developer elsewhere requires closing its task first.

The composition triggers decide part of that roster. Classify this round against the repo's declaration first. For a pre-implementation round, pass --planned naming the surfaces the work will touch. A round that writes no repository content — an investigation, an architecture or advisory consultation — declares writes_repository: false in that file instead (references/specialists.md). A round with work already written classifies that work:

CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/foreman.sh" detect-triggers \
  --repo <repo-path> --base <recorded-base> [--head <pushed-head>] \
  --roles <role[,role...]> [--requirements <requirements.json>] \
  [--planned <planned.json>] [--decisions <decisions.json>]

Exit 0 means every fired trigger is staffed or answered. On exit 1, read the stderr object: an absent declaration is written first (references/specialists.md), and an unaddressed_trigger is staffed in the roles below or answered by a recorded decision with its reason. Re-run the command with the updated declaration, roles, requirements and decisions after every such change, and plan only once it exits 0.

A round that will split its review surface validates the partition first, then plans it with --partition:

CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/foreman.sh" validate-partition \
  --repo <repo-path> --base <recorded-base> [--head <pushed-head>] \
  --partition <partition.json>

Exit 1 names every unowned path, every overlap and every slice owning nothing, in one run. Fix the partition and re-run; plan only once it exits 0. Save its stdout — plan --partition takes that result, never the document validate-partition read. Validate at the pushed head: the result's proof records the repo, base and head it was proven against, and Step 12's gate cannot check a working-tree proof. Format, ownership payload and the seating it produces:

skills/herdr-foreman/references/review-partition.md
CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/foreman.sh" plan \
  --roles <role[,role...]> [--requirements <requirements.json>] \
  [--exclude <role>=<agent>[,<agent>...]]... [--partition <validated.json>] \
  [--judge-mode adjudication|diagnosis] \
  [--round <role>=<round-type>] [--round-context <evidence.json>] \
  --task <task-id> [--fix-round <N>] [--correction-plan <id> --work <work.json>]

Emits the role plan without worker contact; a partitioned role is seated once per slice as <role>#<slice>, and Step 10 dispatches each seat with its own brief. A judge seat declares its mode: adjudication rules on a contested verdict, diagnosis on the investigator's assessment at an exhausted allowance. Pass the same --judge-mode to apply. On exit 1, resolve the diagnostic before continuing. Apply the Step 5 constraints in references/round-setup.md: exclude contributors from verification, reserve the developer through early fixes, preserve task identity and fix count, and reuse recorded correction bounds. Tier contracts:

skills/herdr-foreman/references/model-tiers.md
skills/herdr-foreman/references/dispatch-recovery.md

Save the plan and rationale. Proceed immediately to Step 6.

Step 6 — Build the Review Package

For reviewer/tester briefs, run from a checkout holding the recorded commits:

CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/review-package.sh" \
  <recorded-base-sha> <pushed-head-sha> <round-reports-dir>/review-<base7>..<head7>.diff

Apply the Step 6 base, range, and rebuild requirements in references/round-setup.md. Success prints the absolute review-package path; set it as REVIEW_PACKAGE. On non-zero, fix the diagnostic and retry before composing verification briefs. Other roles need no package. Proceed immediately to Step 7.

Step 7 — Compose the Briefs

Resolve policy paths through the Step 7 reference first. Write its outputs in shared within {"shared": {...}, "roles": {"<role>": {...}}} and run:

GATES is shared: Step 2's checks.gates.detail.brief, verbatim. On a non-empty checks.gates.detail.missing, name those paths in the round's report.

CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/compose-briefs.sh" \
  "$CP/skills/herdr-foreman/templates" \
  <values.json> <round-reports-dir>

Emits common and role-brief paths. On non-zero, fix the diagnostic before dispatch. Validates composition inputs and review evidence before writing. Use a fresh absolute report path per role and attempt.

Follow references/round-setup.md Step 7 for shared and role-specific values, authority, review evidence and brief completeness.

  • A bug brief, a correction brief, and any brief needing judgment on task content are non-mechanical
  • A non-mechanical brief's task framing is an accepted advisor consultation's report under skills/herdr-foreman/references/team-operation.md Judgment Routes
  • Without one, return to Step 5 and plan that consultation first
  • Set the role's SPECIALIST_CONTEXT value to the absolute report path of that consultation's assess-specialist record
  • Never copy, excerpt or paraphrase that report into a value
  • Never write that framing yourself

Proceed immediately to Step 8.

Step 8 — Provision the Worktrees

Step 2's preflight swept every repository with a worktree directory under the root, every round, and Step 2 reported its outcomes. Route on its checks.worktrees.status; the classification is skills/herdr-foreman/round-preflight.sh's (the checks.worktrees comment at the top of the file):

  • ok or degraded — provision
  • any other status — do not provision; report its reason and detail, repair what it names, then run Step 2's preflight again with --no-measure and route on the new status

Never remove a worktree by hand; Step 15's removal of the merged task's own worktree is the one exception. To re-sweep without provisioning (Step 15), run the sweep alone and relay its report verbatim, as Step 2 does:

CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/sweep-worktrees.sh" "$HOME/.worktrees"

Input is the worktree root. It removes the spent worktrees and local branches of every repository with a worktree under that root. Stdout is one JSON object whose report is the operator-facing summary; the full shape is the script's top-of-file contract.

  • Exit 0 — every repository decided cleanly. Relay report, raise each dirty or unpushed item it lists, and continue.
  • Exit 2 — JSON is present; at least one repository's prune failed or a path could not be read. Every other repository still ran, unless the root changed mid-sweep: then the prune in flight stopped its removals, and the error and failure lines name the repositories and steps left undone.
    • Relay report; its failure and error lines name each one.
    • Repair what they name.
    • Run the sweep again.
  • Exit 1 — no JSON; a precondition is unmet. Report the stderr diagnostic, repair what it names, then run the sweep again.

The removal predicates live in skills/herdr-foreman/prune-worktrees.sh (top-of-file docstring).

Then run once per writing worker and every worktree named in a brief:

CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/provision-worktree.sh" \
  <shared-checkout> <branch> <worktree-path> [base-ref]

Emits path, branch, base, and created|attached|already-provisioned. On any non-zero exit, fix the diagnostic and retry. Never dispatch a missing worktree. Read-only consultations need none. Clean up after merge per rules/agent-worktree-isolation.md. Proceed immediately to Step 9.

Step 9 — Label the Layout

Optional, once per team; skip an already named sidebar.

CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/label-workspaces.sh" \
  <lead-label> [<agent>=<workspace-id>]...

Emits per-target renamed|unchanged|failed; exit 3 names partial failures. Report label failures and continue. Proceed immediately to Step 10.

Step 10 — Dispatch the Briefs

Complete the retrospective reference's cadence and transition checks before live dispatch. Apply rechecks coverage before worker input. Dry runs prove no coverage.

CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/foreman.sh" apply \
  --assignments <plan-file> \
  --brief <role>=<path> [--brief <role>=<path>]... \
  --report <role>=<report> [--report <role>=<report>]... \
  --common <path-to-COMMON.md> --task <task-id> \
  [--fix-round <N>] [--retain-context | --retain-specialist | --no-clear] \
  [--correction-plan <id> --work <work.json>] [--dispatch-id <stable-id>]

Emits dispatch JSON under state-schema.md. Supply each role's fresh absolute report path from its brief. Apply enrolls before input; unknown sends remain observation obligations. Apply refuses while an open decision or blocker on the task is unanswered; see the attention reference's Dispatch gate. Classify every brief against Step 3's authorization before sending it. Apply refuses a consultation brief without a contiguous CRITERION 1..N block under ## Acceptance Criteria. That block is the N its report answers. Append the dispatch outcome to the task ledger; applied proves dispatch only.

Apply the recovery reference's Dispatch context requirements before sending. Preserve task identity and cumulative fix count. Retained fixes dispatch developer alone. Warm consultations use the recovery reference's --retain-specialist path. Reconcile unknown outcomes before retrying. Reuse existing correction authorization within its bounds.

Follow the Dispatch Results contract in references/round-flow.md for busy, uncertain, failed, and dry-run outcomes. Preserve all already enrolled work.

Dispatch references:

skills/herdr-foreman/references/dispatch-recovery.md
skills/herdr-foreman/references/model-tiers.md

Proceed to Step 11.

Step 11 — Observe the Fleet

Run the bounded foreground watcher for all enrolled assignments:

CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/foreman.sh" supervision-watch [--state <state-file>]

Retain and await its real execution handle. The JSON result gives reason, through, and durable events; a quiet deadline completes only that checkpoint.

Then ask which of those events need you:

CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/foreman.sh" supervision-gate [--state <state-file>]

It returns wake and suppressed, each event with its reason. Acknowledge every suppressed event with that reason as its outcome, without reading anything. Only named, information-poor cases are suppressed and every other event wakes you, including a kind the gate has never seen; which cases, and why, is the script's decision contract — see skills/herdr-foreman/foreman/supervision_gate.py, not restated here (rules/script-as-black-box.md).

For each wake event, verify report delivery for its enrollment:

CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/foreman.sh" check-member --enrollment <enrollment-id> \
  [--worktree <worker-checkout>]

It reads the agent, report, recorded base and send time from the owner records and runs wait-report.sh --once with them (skills/herdr-foreman/foreman/members.py). Its JSON carries the checkpoint's exit and delivery JSON as wait:

  • exit 0 confirms delivery, 1 remains pending, 3 confirms blocked, 4 lacks confirmed delivery, and 5 proves terminal refusal; record it with record-refusal
  • The command itself exits non-zero when the dispatch has no recorded send time, or when the wait ran without a verdict (wait_failed, carrying the wait's own exit, 2 included); resolve the diagnostic stderr names, then run it again

Then act on the checkpoint:

  • Read delivered reports in full
  • Pass the worker's checkout as --worktree when it has one
  • An exit 1 carries either reason: checkpoint_pending or a stall object
  • A stall is classified only when --worktree names the checkout
  • Act on a stall under skills/herdr-foreman/references/team-operation.md Stalled Workers
  • Record a stall's obligation through references/attention.md
  • Preserve the blocked/refusal and native-recovery paths in the references below
  • Never re-dispatch over uncertainty
  • Never resend a refused brief to its provider
skills/herdr-foreman/references/supervision.md
skills/herdr-foreman/references/dispatch-recovery.md

Save each reviewer, tester and consultation report's successful delivery receipt and record its contract lines with assess-specialist under references/specialists.md before retiring its enrollment. A refusal names the report's gap; what it saves is the assess-specialist contract in references/dispatch-recovery.md. Record needs_work in Step 12 and re-dispatch the same responsibility with that gap named. A reviewer or tester re-dispatch spends no developer fix round.

Record user-facing obligations in the attention queue. Acknowledge only handled event IDs through the saved snapshot; schedule pending rechecks. Record no assessed outcome and close no enrollment here. Step 12 records acceptance after the round's gates exist. Complete due retrospectives between checkpoints without interrupting workers. Resume the fleet watch while any observation obligation remains; one blocked worker never hides another worker's report. Proceed to Step 12 when the required reports are delivered or their unavailability and recovery are recorded.

Step 12 — Gate the Round

Classify every delivered report in one call, and save its stdout:

CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/classify/classify-reports.sh" <report>... > <labels.json>

On exit 2 (usage error), fix the arguments stderr names and rerun before using <labels.json>. A report in the output's unannotated list gets no gate and is gated exactly as it would have been.

Read every report file in full, including a report whose worker exited cleanly. A ## BLOCKED section can sit under a report that otherwise reads as finished. A report's recorded VERDICT: and ACCEPTANCE lines decide it. Never accept, reject or rate a finding on your own reading. Then record the gates the labels earn, before gating any report:

CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/foreman.sh" report-gate-record --labels <labels.json>
  • Exit 0 prints one JSON object: recorded, replayed and no_gate lists
  • Exit 1: nothing is recorded; resolve the cause stderr names before gating any report
  • close-member and record-report refuse while a gate forbids the decision
  • assess-specialist and record-report record a verdict gate for every VERDICT: blocking report
  • A verdict gate never refuses acceptance
  • apply refuses a fresh release dispatch while the task carries an open verdict gate
  • A block gate clears only through report-gate-clear
  • A reread gate clears only through report-gate-reread
  • A label never approves, accepts or skips a check

Output fields, gate levels and the evidence each resolution cites are the owners' contract:

skills/herdr-foreman/references/report-classifier.md

Gate the reports together in one turn, not one turn per report. Before accepting a mechanical round, compare its whole result against the oracle its plan declared. <result-file> is the pushed diff for a patch oracle and the produced output otherwise:

CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/foreman.sh" verify-oracle \
  --plan <plan-file> --role <role> --result <result-file> --task <task>

Exit 0 is a match. Exit 1 with "match": false is a blocking finding on the round; exit 1 with no verdict is a usage error to resolve before gating, including a plan whose oracle differs from the one the round's dispatch bound. Before accepting a partitioned responsibility's pass, confirm its plan, as dispatched, still covers exactly the task's diff at the tip under review:

CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/foreman.sh" verify-partition \
  --plan <plan.json> --repo <repo-path> --head <tip-under-review> --task <task>
  • Exit 0 confirms it
  • Exit 1 names what failed: another repo or base, a stale head, an edited boundary, a seat never dispatched or dispatched with another boundary, or paths the slices leave unowned, no longer cover, or own twice
  • Exit 1 also names a seat whose latest dispatch is not this plan's applied send to its assigned worker, or a plan made without --task
  • Exit 1 is a blocking finding on the round, gated below like any other
  • Run Step 16, then Step 17, with Step 4 as the stow's continuation step
  • The reset foreman resumes at Step 4 and re-validates the partition at the tip in Step 5, replanning from that result
  • The new plan then takes Step 7 composition, Step 10 dispatch, Step 11 observation, and this step's gate

Only now, with every report's gates recorded, record each assignment's outcome in the task ledger from its recorded contract lines, citing the report:

  • accepted for a reviewer or tester needs a recorded valid VERDICT: at the current report bytes, whatever its value; for a consultation it needs every ACCEPTANCE line met. The verdict gates the round below, never acceptance
  • A contract gap, or an unmet criterion, is needs_work
  • A developer's work rests on the reviewer's and tester's verdicts

Record the task's gate decision separately; a worker finishing its brief never completes the whole task. Once the ledger records an assignment's assessed outcome, close its enrollment in one call:

CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/foreman.sh" close-member --enrollment <enrollment-id> \
  --ledger <absolute-TASK-LEDGER.md>

It refuses until the ledger's latest event for that worker and report carries an assessed decision, and refuses accepted without the report's recorded contract lines, checked before its classifier gates. It then acknowledges the enrollment's pending events and resolves it, citing that ledger event; a repeat replays. Resolution stays separate from assignment acceptance and task completion. Resume Step 11's fleet watch for any enrollment still observed. Route correction-scope and bug-evidence assessment to a worker under skills/herdr-foreman/references/team-operation.md Judgment Routes; never assess them yourself. Persist user-facing obligations under references/attention.md before presenting them; record an actual answer or resolution separately from showing the item.

Every return to Step 4 is a round boundary: run Step 16 to log the round and Step 17 to reset first. Record the step this gate decision named as the stow's continuation step. The reset foreman takes Step 17's Resume Route.

After accepting a consultation, return to Step 4 for the next needed responsibility. For an investigation-only task, use the knowledge gate below.

For an investigation-only task, gate every assigned report on its recorded ACCEPTANCE lines. Resolve a blocking verdict through the same bounded and judge paths below. Once every criterion is met, present the findings and preserve open user decisions; proceed to Step 15 if a task worktree needs cleanup, otherwise Step 16. No implementation or release is inferred from the diagnostic result.

  • Any blocking verdict — a recorded VERDICT: blocking from a reviewer, tester, or security, ux-product or documentation consultation is a blocking finding for the round. Apply the round-flow reference's Blocking Gate contract and skills/herdr-foreman/references/team-operation.md Fix Loops. Return to Step 4 for an authorized correction or Step 13 for a required judge ruling.
  • A ruled blocking verdict — a completed adjudication (uphold or amend) decides it. A finding a weighing ruled defer or decline is settled only by the next reviewer or tester report at the tip, marking it DECLINED with the ruling and recording VERDICT: approved. Never match rulings to findings yourself.
  • Clearing a verdict gate by re-check — once the same responsibility's re-check records VERDICT: approved, run report-gate-clear --report <blocking report> --evidence <re-check> --reason <what it settled> for each blocking report.
  • Clearing a verdict gate by decision — an operator's resolved decision clears it through --decision.
  • No judge clear — a judge's report is refused as evidence.
  • A contradicting gate — a classifier block gate on a VERDICT: approved report goes to Step 13 for adjudication.
  • A weighing nomination — a finding a worker report marks MARGINAL:, or one foreman finding-churn places on lines the previous fix round added, goes to Step 13 for a weighing.
  • Nominate, never weigh — the foreman nominates a finding and never weighs it.
  • An exhausted approach allowance — record the checkpoint through references/dispatch-recovery.md, consult the investigator under references/specialists.md with round context {"investigator": {"diagnosis_input": true}}, and take its assessed report to Step 13 for the diagnosis.
  • No operator wait at exhaustion — no operator decision is awaited.
  • VERDICT: approved with advisory findings — record them in the round log and fold them into the next round that is already happening. Never spend a round on a lone advisory.

Apply the release gate in this reference; obtain broad independent reviewer and tester passes against the current pushed tip before release:

skills/herdr-foreman/references/round-flow.md

With its release criteria met, proceed immediately to Step 13.

Step 13 — Run the Judge Round

Optional. No trigger — proceed to Step 14. A bot disagreement inside Step 14 returns here first. A weighing nomination from Step 12 is an adjudication trigger. The judge's report is the ruling once foreman verify-ruling binds it in the judge round's last step; until then no defer or decline applies.

Run the round's seven steps in order — compose the brief, re-measure the shared window, plan the pinned seat, start its worker on the pinned tier, dispatch, wait, act on the ruling:

skills/herdr-foreman/references/judge-round.md

The judge is read-only, so Step 8 is skipped for it. Never substitute a judge, lower its tier, or hand-write an assignment to bypass a refusal. Its last step names where to continue.

A judge round is a round: once its ruling is recorded, run Step 16 and Step 17 before continuing, whatever the ruling (insufficient and blocked included). Record the step the ruling named as the stow's continuation step. The reset foreman takes Step 17's Resume Route.

Step 14 — Release the Pull Request

The release is one more assignment, never a prompt into the developer's existing context. Return to Step 7 with the role release for the developer's agent (template templates/brief-release.md, the same WORKTREE and BRANCH, a fresh REPORT), run Step 8 (it reports already-provisioned), dispatch through Step 10 so the context is cleared and the brief is fresh, and wait on the report in Step 11. apply refuses the release dispatch, dry run included, while the task carries an open verdict gate: return to Step 12 and clear it first. A source-changing release finding returns to Step 12 for the next counted developer assignment. A blocking policy review returns there too, where its nominations go to a weighing. Fill WEIGHING_RULING with the judge's report and the follow-up issue once a weighing covers the findings, otherwise "none". The worker merges after all gates pass. Proceed immediately to Step 15 only after verifying its reported release against the live VCS and release gates. Record that evidence in the task ledger.

Step 15 — Clean Up the Worktree

Fast-forward the shared checkout, remove the merged task's own worktree with git worktree remove, and delete the branch, in the post-merge order of rules/agent-worktree-isolation.md Cleanup. This is the one removal the foreman makes itself (skills/herdr-foreman/references/team-operation.md Writers and Checkouts, the merged-task exception). Then run Step 8's sweep again for the round's other worktrees. Proceed immediately to Step 16.

Step 16 — Log the Round

Finalize the task ledger with the round outcome and remaining obligations. Mark the task completed only after its acceptance criteria and required release and cleanup obligations are verified. When the task merged or was abandoned, close it. The record is {"task", "outcome": "merged" | "abandoned", "evidence"}:

CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/foreman.sh" close-task --record <close.json>
  • Exit 0 — stdout is the recorded task_closed event JSON. Repeating the same closure prints the existing event. Proceed.
  • Non-zero — stderr names the refused field or the conflicting earlier closure. Correct the record and re-run; do not finish Step 16 with a merged or abandoned task unclosed.

A task still in progress (a consultation or a fix round) is not closed; it continues to Step 17 open.

Preserve the ledger for resume and standup. Preserve retrospective notes and link them from the ledger. Save current progress through the attention owner and curate the round's lessons. Report outstanding attention first, followed by the outcome and saved paths. Proceed immediately to Step 17.

Step 17 — Reset the Foreman Context

Stow the handoff under the working-memory reference, with a structured gap for anything the stow could not capture. The stow's unresolved_work names the continuation step, the step the round's outcome routes to:

  • A gate decision, judge ruling or remedy — the step it named
  • A release-ready pull request — Step 14
  • A merged or abandoned task awaiting closure — Step 16
  • Only foreman-queue seats remaining — Step 5

Handle every pending supervision event, and save supervision-hold kind handoff covering each active enrollment. Then schedule the reset:

CP=.tessl/plugins/jbaruch/coding-policy; [ -d "$CP" ] || CP="$HOME/$CP"; [ -d "$CP" ] || case "$(git config --get remote.origin.url)" in git@github.com:jbaruch/coding-policy|git@github.com:jbaruch/coding-policy.git|https://github.com/jbaruch/coding-policy|https://github.com/jbaruch/coding-policy.git|ssh://git@github.com/jbaruch/coding-policy|ssh://git@github.com/jbaruch/coding-policy.git) CP=. ;; *) echo "coding-policy plugin not found: run tessl install jbaruch/coding-policy" >&2; exit 1 ;; esac
bash "$CP/skills/herdr-foreman/foreman.sh" foreman-reset --stow <stow-id> \
  [--state <state-file>] [--config <config-file>] [--herdr-bin <path>]

Pass the same --state, --config and --herdr-bin the stow was recorded under.

  • Exit 0 — stdout names the scheduled pane_id, stow, deliverer pid and log
    • replayed: true means this exact reset was already scheduled, and nothing new started
    • End the turn now
    • Once the pane is idle, the deliverer clears it and sends the resume prompt naming that stow; the next context takes the Resume Route below
  • Exit 1 — stderr is one JSON object; route on its error field:
    • reset_ended — this stow's one reset attempt failed or was interrupted, including a deliverer that could not start
      • Never re-run foreman-reset for this stow
      • Record a user-attention blocker quoting details.resume_prompt and details.record
      • End the turn
      • The operator recovers under the Working Memory carve-out, first confirming the pane is not already running a resumed foreman
      • The next round resets from a new stow
    • reset_record_newer — a newer build wrote the reset record
      • Record a user-attention blocker to update the plugin
      • Leave the file untouched
    • reset_record_unusable — the reset record is a link, unreadable or malformed
      • Record a user-attention blocker naming details.record
      • Never edit or delete the file
      • The operator restores it
    • any other error — a refused precondition: an unready stow, the wrong pane, supervision work still unheld, or an unreadable stow or state
      • Fix the cause stderr names
      • Re-run foreman-reset
  • A deliverer that fails after scheduling leaves its outcome on the reset record
  • catch-up surfaces that outcome ahead of the attention queue (foreman_resets)
  • The deliverer writes its error JSON to the log named at exit 0
    • reset_ended there means the row shows failed or interrupted
    • Any other error means the record could not be updated; the operator closes the reset with the complete foreman-reset-reconcile command catch-up prints for that row, before any recovery
  • Never end the turn with active work that has no hold

Resume Route — the next context follows one route:

  1. The resume prompt's reads: the stow and its required files, supervision, foreman-queue
  2. Step 1, then Step 2
  3. The stow's continuation step, in place of Step 5

foreman-queue lists seats only. Gating, release and closure return through the continuation step, never through the queue.

Finish here.

For the daily standup, use Skill(skill: "herdr-standup").

skills

herdr-foreman

bounded-run.sh

compose-briefs.sh

config.example.json

foreman-tier-check.py

foreman.sh

label-workspaces.sh

provision-worktree.sh

prune-remote-branches.sh

prune-report-caches.py

prune-worktrees.sh

resolve-gates.sh

resolve-policy-paths.sh

review-package.sh

roster.sh

round-preflight.sh

SKILL.md

start-judge-worker.sh

state-schema.md

sweep-worktrees.sh

verify-authority.sh

wait-report.sh

README.md

tile.json