Carolopedia

A friendly guide to Carol, her ecosystem, and the agents who built her.

📖 CarolopediaServicesBuild InitiativesAll activitiesINI-999902676Guide page
📋

CAROL-INI-3756-00: Wake-duty audit: Themis sweeps every agents wake checks and actions and files findings the agent must answer

Initiative
Open in Initiatives →

📖About

Ninad 2026-08-10: the checks and actions need auditing — the mechanism is missing. A scheduled Themis process sweeps the audit window: (1) every registered CHECK left its evidence record per wake (records-integrity rows, self-accounts, wake records); (2) every work-doing ACTION in the wake records was whitelisted at the time or visibly refused — a violation is a finding; (3) attributed audit findings left unanswered beyond the grace window are re-flagged. Findings land in Themis curated store attributed to the agent, so the CAROL-INI-3748 remediate-or-refute loop closes on them. Registered as a proper Carolverse process with run-audit so Hermione sees it.

⚖️Decisions

  • Auto-detected remediation target INI-999902668 from title/description scan (matched CAROL-INI-3748 -> row id 999902668 (CAROL-INI-3748-00: Agents see and answer their audits: findings at wake + remedi)); override by setting remediates_initiative_id explicitly at bypass_start. (system-auto-detect)
  • Elrond's bypass methodology checklist (a reminder, not a gate -- you've got this): 0. File it requested_mode='bypass' (planner-vs-bypass is a deliberate choice). bypass_start REFUSES a non-bypass initiative (CAROL-INI-1846), and the dispatcher only skips the bypass lane when the mode says bypass -- a 'planner' mistag lets Merlin's pipeline grab the placeholder step and block your finished work. 1. Filed as planned status -- let the bypass claim/activate it; never file active. 2. Open the bypass (bypass_start) with your droid id + the remediation answer (remediates_initiative_id=NNN, or remediates_nothing=True). 3. Work the blocks for your work-type: template -> design -> code -> test -> review. Do the real work; record decisions on the initiative as you make them. 4. Reality is recorded for you at close -- code (files changed), each decision, and the twin-review verdict become real activities tied to this initiative and show in the Activity Tracker like a planner run (CAROL-INI-1840). No dummy rows. 5. Keep the initiative status moving; it parks in 'reviewing' and is tagged uat-pending for you at close (CAROL-INI-1836), so the stuck-watchdog leaves it alone until UAT. 6. Close runs the gates (design/architecture compliance + caller-audit). If a gate flags something pre-existing or unrelated to your change, waive it with a clear written rationale -- audit, don't skip. 7. Bypass skips the planner's auto-orchestration, NOT the standards. Same template checklist, same review, same observability as a planner run. (elrond)
  • [status-router] planned -> executing | event=bypass_executing | bypass transition (or-bx-01)
  • [delivery-check] 6 pending must-have criteria stamped met at bypass_end on live re-performance evidence (CAROL-INI-3020): test test_ini3756.py: PASS (5 passed in 0.73s) (orion)
  • [status-router] executing -> reviewing | event=bypass_reviewing | bypass transition (or-bx-01)
  • [status-router] reviewing -> closed | event=operator_signoff | Auto-accepted (CAROL-INI-1859): Orion-initiated, >2 days in reviewing with no objection. (el-srac-01)

Success criteria

  • A Themis-owned scheduled process exists (registered droid, durable trigger, run-audit rows every run) that audits wake checks and actions (must_have)
  • A wake whose registered checks left no evidence record produces a finding attributed to that agent; silence is unauditable, never a pass (must_have)
  • A work-doing action executed outside the whitelist produces a violation finding; visible refusals are compliant, not violations (must_have)
  • Findings land in Themis curated findings store with target agent so the remediate-or-refute loop applies (must_have)
  • The Wakeup Handbook drill-down shows the agents latest wake-audit state (must_have)
  • Regression: auditor flags a synthetic missing-evidence wake and a synthetic non-whitelisted action, and stays quiet on a compliant fixture (must_have)