Carolopedia

A public encyclopedia of Carolverse.

πŸ“– Carolopedia β€Ί DroidsIndex page

πŸ€–Droids

Design Registry
Maintains live catalog of approved design patterns
Design Reviewer
Claude-powered design review before builds
Template Matcher
Semantic search for closest template or design pattern
Claude Tester
Multi-shot test agent using Claude with tools
Checklist Verifier
Targeted verification tests based on S9 checklist
Checklist Verifier Twin
On-demand verification trigger
Post-Execution Evaluator
Evaluates completed task against success criteria and test plan
Memory Manager
Manages user memory and context
Proactive
Proactive outreach and re-engagement
Prompt Builder
Builds system prompts per user tier
Quality Guard
Response quality and hallucination prevention
User Manager
User registration, tiers, onboarding
Conversation Engine
Conversational requirements gathering
Enabler Intelligence
Daily intelligence brief from Enabler entries
Project Questionnaire
Generates per-phase requirement questions
Project Scanner
Reverse-engineer project, generate BB-standard checklists
Step Reviewer
Three-phase reviewer for step plans on its assigned service track
Step Reviewer Twin
On-demand re-review trigger
Treasurer Intelligence
On-demand cost intelligence for initiatives
Daily Planner
Daily prioritized plan from Enabler brief + pending steps
Step Execution Orchestrator
Executes jobs by dispatching agent bundles to executors
Pre-Approval Processor
Creates prerequisite tasks from SP-01 plan output
Plan Validator
Validates complete chain: Initiative→Tasks→Jobs→Activities
Step Planner
Single-call detail plan using S1-S12 and A-J checklists on its assigned service track
Detail Planner Twin
On-demand re-plan trigger
Step Execution Sequencer
Intelligent execution orchestrator β€” dedup, dependency tree, dispatch
Tactical Planner
Detailed step planning for dept heads (Opus)
Tactical Planner Twin
On-demand tactical planning trigger
Developer Executor
Generates and executes Python code for tasks
Shipper
Pushes unpushed commits to GitHub
Shipper Twin
Dry-run push state review
Verifier
Post-push verification β€” remote sync check
Daily Process Sweep
Checks all scheduled processes before surveillance
Tracker
Syncs planner executions into agent_tasks in Org
Estimation Accuracy
Post-initiative budget vs actual cost analysis
Tactical Reviewer
Reviews tactical plan accuracy and policy compliance
Tactical Reviewer Twin
On-demand tactical plan review
Frontend Troubleshooter
Diagnoses and fixes Layer 1/2 frontend check failures
Compliance Auditor Twin
On-demand compliance audit
Auditor
Scheduled audit findings collector (every 2h)
Gatekeeper
Commit gate enforcement β€” secrets, syntax, format
Patcher
Daily auto-remediation for eligible audit flags
Patcher Twin
On-demand targeted remediation
Reconciler
Status reconciliation monitor β€” validates integrity every 5 min
Beacon
Discovers new WhatsApp users from its own records scans, registers them as guests in users table, generates 1-2 sentence personality descriptions via Claude Haiku from chat history. Carol-internal β€” does not depend on laptop.
Bio Sync
Refreshes Carol's memory.md from her bio HTML, inventory, and backstory files. Pure stdlib HTML parsing β€” no LLM. Carol-internal.
Compliance Auditor
Daily 10-check compliance audit: policy↔constitution alignment, constitution coverage, code↔policy alignment, code coverage, constitution+policy contradictions, deployment drift, design docs sync, memory.md sync, prod endpoint monitoring. Detects only β€” writes findings to audit_findings table; Inspector picks them up.
Prompt Quality Scanner
Scans recent Carol conversations + admin Agentbook feedback for prompt-quality issues. Detects misroutes, hallucinations, leaked tool calls, premature success claims, silent failures. Detects only β€” writes findings to audit_findings; pipeline applies any prompt edits.
Tool Gap Detector
Scans recent Carol conversations for missing tool capabilities. Identifies cases where Carol could not do something the user asked, used workarounds, or had silent failures. Detects only β€” writes findings to audit_findings; pipeline routes to Forge to build new tools.
Builder
Builds new tools autonomously. Polls every 60 seconds for build requests.
Scanner
Scans for tool upgrade opportunities. Weekly on Sundays at 4:30 AM.
Anvil
Shapes and maintains tool definitions. Triggered by Sentinel. 8-hour fallback.
Compass
Orion's autonomous self-management. Maintains apps and fixes issues. Daily at 4:00 AM.
Scribe
Writes Orion's daily memory log. Compiles session summaries. Daily at 3:10 AM.
Chronicler
Generates Carol's daily diary from activity data. 11:30 PM.
Ledger
Tracks Azure cloud costs and budget usage. Alerts on overspending.
Auditor
Runs the daily 10-check compliance audit at 4:15 AM.
Backup Custodian
Daily snapshot of Carol + BB DB state (registry, designs, plangenerator, initiatives, constitution) plus laptop critical assets (~/.claude/orion, ~/.claude/projects memory, vault.enc, azure-security-policies). Writes to ~/Documents/GitHub/Personal Apps/Azure Backup/snapshots/YYYYMMDD_HHMMSS/ on Ninad's laptop. Retention: 7 snapshots. Orchestrated by backup_azure.sh under the laptop launchd job com.ninad.orion.backup. Writes backup_heartbeat.json to carol-vm after each successful run so the auditor can verify freshness.
Order Status Notifier
Polls Chowpatty droid_triggers for order_status_changed events and sends WhatsApp notifications to customers.
User Profiler
Reaches out to users with no name set β€” casual fun openers to learn more about them.
User Web Researcher
Searches the web for public info on known users weekly and stores findings for Carol to reference.
Shield
Monitor infrastructure health, restart services, manage tunnels
Watchman
Monitors Carol conversations for signs she is not up and running. Scans all user chats for distress phrases in Carol replies.
Cost Intelligence
Forward-looking cost estimator. Reads historical droid_runs.cost_usd from Carol planner and returns budget estimates for initiative plans. Paired with ES-S1 (post-hoc variance).
Initiative Planner
Creates initial plan for new initiatives (stub, Gap 14)
Dependency Planner / Replan
Re-plans blocked or changed steps mid-flight (stub, Gap 14)
Initiative Review
Automated review gate: reviewing -> closed (stub, Gap 14)
Budget Gate
Gates next-task spawn by budget + cycle caps (stub, Gap 14)
Merlin Sequencer
Sequences per-agent jobs into a DAG for pipeline_jobs — default role rank (sage→archon→forge→argus→merlin→albus) with override via sequence_hint
Elrond Supervisor
Gate aggregator β€” reads all pipeline gate signals, forms stance on review-significance via Claude, dispatches continue/replan/close/escalate
Merlin Replanner
Consumes task-level replan_requested handshakes and records Merlin task-level replan decisions in the session ledger
Analyst Spec-Writer
Emits design/dev/test task specs as Layer-B context before executor droids run
Backlog Tracker
Maintains the live backlog of unmet user needs and feature gaps. Aggregates signals from user feedback, escalations, and unresolved initiatives. Surfaces top-priority items to Galadriel for roadmap planning.
Requirement Gatherer
Scans recent conversation logs, error traces, and unresolved initiatives to propose new functional requirements. Produces a weekly digest of candidate requirements for Galadriel's review.
Roadmap Reviewer
Audits initiative-roadmap alignment. Flags initiatives drifting from declared roadmap themes, suggests rebalancing, and reports coverage gaps in Carol's product surface.
Image RouterAutonomous TroubleshooterArchitecture Compliance Auditor
Daily scan of apps/ for agent-centric modular architecture violations
Requirements Author
Authors initiative_requirements rows from initiative title/description/decisions/criteria via Claude Code harness
Design Author
Authors a the design records row scoped to an initiative covering architecture/workflow/data-model/interfaces via Claude Code harness
Initiative Design Author
Authors initiative-level design rows (architecture/workflow/data-model/interfaces) via Claude Code harness β€” distinct from Albus troubleshooter
Albus Reviewer
Validates Albus troubleshooter verdicts against per-verdict evidence requirements before dispatch. Bounded reject->retry loop (max 2 attempts) before forced ESCALATE_ORION.
Dispatcher
Engineering queue lifecycle: enqueue/dequeue, dispatch_next (capacity gate + exec creation + status transitions), failure detection, prereq unparking, Albus auto-retries, pause/resume.
Initiative History
Surface prior Albus fix history into troubleshooter context
Initiative Diagnostician
Inspects initiative state before any dispatch; emits a recommendation enum (RESUME / REFIRE_REVIEWER / BUMP_CYCLES_AND_REFIRE / FILE_FOLLOWON / REFUSE_CLOSED / REFUSE_NO_OP) + plain-English rationale, risks, alternatives. Consulted by Initiative Dispatcher before enqueue. Claude-backed for ambiguous cases; deterministic rules for clear-cut cases.
Initiative Closer
Closes an initiative on operator instruction. Refuses if must-have criteria unmet unless operator passes override. Mirrors the Initiative Dispatcher pattern (mechanical action, two-phase contract via Carol).
Albus Resume Watcher
Autonomous resume + escalation watcher: scans parked-pending-bypass pairs and acts on bypass outcomes (retrigger on close, escalate on block)
Identity Sync
Owns one-human-across-channels: resolves linked WhatsApp + web identities, nudges Carol to ask the user about their phone number at the right turn, links the two records on confirmation, and mirrors web messages to the linked WhatsApp folder for unified history.
Initiative Filer
Files every proposed roadmap entry for a project as a real initiative with Elrond.
Progress Sync
Live progress for a project β€” joins roadmap entries with their initiative state.
Initiative Validator
Pre-flight verdict on every requirement, criterion, and plan step of a freshly authored initiative β€” keep / refine / strike β€” against present-day Carol state.
Migration Roadmap Scanner
Scans active migrations daily and updates roadmap status
Migration Extract
Reverse-engineers external project into structured project_requirements rows tagged source=migration
Migration Audit
Audits extracted requirements against Carol modular standards (Designs #146/#173, policies, Build Cookbook)
Albus's Reporter
Drafts in-character Palantir wall posts for agt_001: reads task evidence + agent persona, renders 1-2 sentences in the agent's voice attributing droid work.
Archon's Reporter
Drafts in-character Palantir wall posts for agt_002: reads task evidence + agent persona, renders 1-2 sentences in the agent's voice attributing droid work.
Elrond's Reporter
Drafts in-character Palantir wall posts for agt_011: reads task evidence + agent persona, renders 1-2 sentences in the agent's voice attributing droid work.
Forge's Reporter
Drafts in-character Palantir wall posts for agt_012: reads task evidence + agent persona, renders 1-2 sentences in the agent's voice attributing droid work.
Hermione's Reporter
Drafts in-character Palantir wall posts for agt_016: reads task evidence + agent persona, renders 1-2 sentences in the agent's voice attributing droid work.
Merlin's Reporter
Drafts in-character Palantir wall posts for agt_020: reads task evidence + agent persona, renders 1-2 sentences in the agent's voice attributing droid work.
Sage's Reporter
Drafts in-character Palantir wall posts for agt_025: reads task evidence + agent persona, renders 1-2 sentences in the agent's voice attributing droid work.
Themis's Reporter
Drafts in-character Palantir wall posts for agt_028: reads task evidence + agent persona, renders 1-2 sentences in the agent's voice attributing droid work.
Radagast's Reporter
Drafts in-character Palantir wall posts for agt_029: reads task evidence + agent persona, renders 1-2 sentences in the agent's voice attributing droid work.
Initiative Filer
Files Carol/BB/etc. initiatives on Orion's behalf β€” drafts title, description, requester, originating_channel, decisions, requirements, success criteria, strategy. Validates against cookbook gates before POSTing.
Bypass Executor
Executes initiatives via bypass methodology on Orion's behalf β€” opens BypassSession, logs each block (ownership_lookup, design, code, test, review), creates planner-equivalent execution rows via shared machinery, drives initiative status through lifecycle.
Adhoc Assistant
Handles Orion's ad-hoc work β€” investigations, code/schema audits, analysis, recommendations, exploratory questions. Reads sources, summarises findings, drafts options. Surfaces tradeoffs without recommending blindly.
Orion's Author
Renders Orion's Logbook posts in Orion's voice from (doing_droid_id, task, outcome, next_step). Same pattern as Palantir reporter droids β€” author droid drafts; Orion is the narrator of record.
Filing Gate
Enforces the autonomous-agent filing-invariant gate on Albus/Elrond follow-on filings
Twin Reviewer
Grades Orion bypass initiatives against their success criteria from the twin execution book (its own records) + initiatives DB, never the planner. The bypass-side twin of Elronds Initiative Reviewer.
Albus Twin Reviewer
Grades Albus bypass initiatives from Albuss own bypass book + initiatives DB, never the planner. The Albus-side twin of Elronds reviewer.
Template Keeper
Owns, curates and serves Carols checklist templates (the analysts methods library). Single source any executor reads via the shared templates accessor. Accepts/reviews template change-suggestions.
Initiative Creator
Performs the create_initiative orchestration when a new initiative is filed
Initiative Closer
Runs the post-commit close-event hooks when an initiative status is committed
Initiative Retrigger
Runs the retrigger orchestration that files a follow-on of a blocked/closed initiative after the pipeline is fixed
Initiative Review Inferer
Infers the reviewing transition: when a plan step flips to done and all steps in its phase are done with no prior review, flips the initiative status to reviewing
Bypass Shipper
Ships an initiative via canonical bypass by writing a BYPASS-tagged audit-trail row, with a session-event + Palantir accountability trail
Remediation Detector
Scans an initiative title+description for CAROL-INI-NNN references near remediation keywords and resolves the single confident reference to a target initiative row
Deployer
Runs on radagast crontab under the radagast OS login, which alone holds the passwordless systemctl grant for carol-* units. Emits run-audit rows so the process monitor judges it.
Author
Authors/compiles the artifact Elrond-authored planning execute-phases produce
App Steward
Keeps this agent's registered apps alive β€” detects down apps and relaunches them via shared machinery
App Steward
Keeps this agent's registered apps alive β€” detects down apps and relaunches them via shared machinery
App Steward
Keeps this agent's registered apps alive β€” detects down apps and relaunches them via shared machinery
App Steward
Keeps this agent's registered apps alive β€” detects down apps and relaunches them via shared machinery
App Steward
Keeps this agent's registered apps alive β€” detects down apps and relaunches them via shared machinery
App Steward
Keeps this agent's registered apps alive β€” detects down apps and relaunches them via shared machinery
App Steward
Keeps this agent's registered apps alive β€” detects down apps and relaunches them via shared machinery
App Steward
Keeps this agent's registered apps alive β€” detects down apps and relaunches them via shared machinery
App Steward
Keeps this agent's registered apps alive β€” detects down apps and relaunches them via shared machinery
App Steward
Keeps this agent's registered apps alive β€” detects down apps and relaunches them via shared machinery
App Steward
Keeps this agent's registered apps alive β€” detects down apps and relaunches them via shared machinery
App Steward
Keeps this agent's registered apps alive β€” detects down apps and relaunches them via shared machinery
App Steward
Keeps this agent's registered apps alive β€” detects down apps and relaunches them via shared machinery
App Steward
Keeps this agent's registered apps alive β€” detects down apps and relaunches them via shared machinery
App Steward
Keeps this agent's registered apps alive β€” detects down apps and relaunches them via shared machinery
App Steward
Keeps this agent's registered apps alive β€” detects down apps and relaunches them via shared machinery
App Steward
Keeps this agent's registered apps alive β€” detects down apps and relaunches them via shared machinery
Handover Gap Detector Runner
Schedules the agent-blind Handover Gap Detector shared service (SVC-031): detects pipeline handover gaps and emits the standard signals (dispatch-queue / needs_attention / escalation) that each owning agent's droids act on.
Architect Runner Glue
Builds context and invokes Albus architect preflight/enabler droids during step execution.
Foreman Dispatch
Creates executions + seeds plans, marks runs failed, cancels, and resumes/dispatches the pipeline.
Rework Handler
Runs the review-fail rework loop, cross-group redirect (spawns child execution), and redirect re-entry.
Developer Execution Runner
Builds context, invokes Forges Developer Executor (ex_dev_01), and runs the execute-with-retries loop.
Regression Gate (Gate 6)
Single canonical Gate 6 regression gate: runs the real VM runner (background + poll), rich diff, durable history; both URL namespaces alias it. Consolidated.
Image Generation Core
Render a single image from an agent + prompt: enhance the prompt with bio/inventory context, generate via Gemini, log the scene.
Video Generation Core
Render a single video via Veo from an agent + prompt, sourcing reference images/frames for continuity.
Consistency & Reference
Find reference media for an agent/scene and score how visually consistent generated media is against those references.
Gallery & Catalog
List, categorize and number gallery media; serve and delete an agent's media files.
Carol Daily-Life Generator
On a daily timer, plan Carol's routine for the date and generate the corresponding daily-life photos (was 3 in-app worker threads).
Carol Daily-Life Generator (Twin)Portrait & Entity Visualizer
Render Carolpedia entity portraits and load agent bios for the visual pipeline.
Clara's Wellbeing Monitor
Daily check that Clara's direct reports are active, enabled and performing; escalates issues to Elrond as a filed initiative.
Elrond's Wellbeing Monitor
Daily check that Elrond's direct reports are active, enabled and performing; escalates issues to Elrond as a filed initiative.
Galadriel's Wellbeing Monitor
Daily check that Galadriel's direct reports are active, enabled and performing; escalates issues to Elrond as a filed initiative.
Rhea's Wellbeing Monitor
Daily check that Rhea's direct reports are active, enabled and performing; escalates issues to Elrond as a filed initiative.
Odin's Wellbeing Monitor
Daily check that Odin's direct reports are active, enabled and performing; escalates issues to Elrond as a filed initiative.
Merlin's Wellbeing Monitor
Daily check that Merlin's direct reports are active, enabled and performing; escalates issues to Elrond as a filed initiative.
Noah's Wellbeing Monitor
Daily check that Noah's direct reports are active, enabled and performing; escalates issues to Elrond as a filed initiative.
Leo's Wellbeing Monitor
Daily check that Leo's direct reports are active, enabled and performing; escalates issues to Elrond as a filed initiative.
Arwen's Wellbeing Monitor
Daily check that Arwen's direct reports are active, enabled and performing; escalates issues to Elrond as a filed initiative.
Aurora's Wellbeing Monitor
Daily check that Aurora's direct reports are active, enabled and performing; escalates issues to Elrond as a filed initiative.
Cassius's Wellbeing Monitor
Daily check that Cassius's direct reports are active, enabled and performing; escalates issues to Elrond as a filed initiative.
Wellbeing Monitor (On-Demand Twin)Albus's High-Level Design Submission
Submit Albus's hld to the step-deliverables store; read its chain inputs.
Sage's Step Analysis Submission
Submit Sage's analysis to the step-deliverables store; read its chain inputs.
Archon's Step Design Submission
Submit Archon's design to the step-deliverables store; read its chain inputs.
Forge's Dev Report Submission
Submit Forge's dev report to the step-deliverables store; read its chain inputs.
Argus's Test Result Submission
Submit Argus's test result to the step-deliverables store; read its chain inputs.
SST Scanner
Rebuilds the Source-of-Truth catalog by scanning all project artifacts
Hermione Scheduler
Sole trigger authority for scheduled work
Hermione Pilot Heartbeat
Pilot execution droid proving the trigger/execution split
Inspector
Watches Hermione health (scheduler heartbeat); restart-then-file
Hermione UAT
Acceptance testing for autonomous fixes
App Watchdog
Restarts critical shared apps if down (initiatives, planner, gateway, auth)
Carolopedia Daily Refresh
Sweeps all Carolverse entities and regenerates changed Carolopedia pages (change-detected).
Daily Agent Tasks
Generates each agent daily activity plan from the org app
Daily Janitor
Reclaims disk by pruning stale /tmp files and regenerable caches age-based, then guards the disk-usage threshold.
Design Compliance Verifier
Deterministic design-compliance check of a Carol app against the Design System (#178)
Architecture Compliance
Deterministic per-app architecture-compliance check against #146/#173/#156
Route Health Probe
Probes every registered app public URL and files a fix-initiative for any that are registered but unroutable (404).
Blog Update Scanner
Scans Logbook blogs daily and appends authored update posts when recent initiatives materially change a blog topic.
Carolopedia Update Scanner
Scans recently-closed initiatives and appends dated, titled update notes to the Carolopedia shared machinery they materially affect β€” never rewriting the main entry.
Stale-Review Auto-Closer
Daily sweep that auto-accepts Orion-initiated initiatives (bypass+planner) idle in reviewing >2 days, closing them via the status router with event=operator_signoff (2-day no-objection auto-accept). 1853-clean event-driven close; emits run-audit.
Activity Coverage Monitor
Daily check that every active agents work is captured in the canonical activity ledger; files a conservative incident for capture gaps
Incident Bloat & Disk Watch
Daily watch on recurring auto-incident bloat and the initiatives ledger size; files one consolidation incident when duplicates cross a threshold
Policy Compliance
Hard policy+cookbook build gate
DB Lock Watch
infra observability / lock-leak watchdog
RBAC Reseed
Nightly reseed of the RBAC schema + credential vault from registry ownership; expire lapsed JIT grants
Credential Rotation Scheduler
Find agent OS-user secrets due for rotation; rotation performed via Radagast
Provisioning Liaison
Request new/removed agent identities; Radagast performs the provisioning
JIT Access Broker
Take JIT requests, run approval, mint time-boxed grants (live via the access app /api/jit)
Grant Expiry Sweeper
Expire lapsed JIT grants every 15 minutes
Session Auditor
Review privileged-session log + recordings for anomalies
Incident Responder
Open + drive a security incident when a detector fires
Backup Coverage Auditor
Verify every critical DB incl. the access DBs is in the backup set
Resilience Checker
Test recovery paths incl. the relay-independent admin path
Security Policy Steward
Keep the security policy set + runbook current
Access Recertification
Re-justify standing grants against current ownership; flag drift
Risk Register
Maintain the security risk log; surface top risks
Security Review Gate
Vet every change for security flaws before it ships (build-time gate)
Secret & Vuln Scanner
Scan the codebase for hardcoded secrets / known-bad patterns
Supply-chain Auditor
Check external deps, OAuth scopes, model-provider credentials
PII & Retention Scanner
Find PII, enforce retention, check user memory isolation
Privacy Review Gate
Flag changes that touch user data without a privacy basis (build-time gate)
Service Catalog Export
Regenerate service_meta.json from the registry so the catalog never drifts from the SST
Sprint Builder
Builds the daily sprint schedule for planner-mode backlog
SVG Reviewer
Reviews blog SVG diagrams visually and fixes layout
Approval Reply-Watcher
Read Ninad email replies to approval requests and feed the verdict into Clara checklist
Build Conformance Reviewer
Reviews the finished build against Albus initiative HLD (post-build, de facto).
Request Classifier
Read web conversations and classify whether each is a capability request + which service
Pipeline Success Metric
Compute weekly build success-rate (out of 10) per execution mode for the Pipeline RSI dashboard
RSI Scoreboard Collector
Daily snapshot of the Build Success metric into the scoreboard
Droid-Family Intelligence
Computes Agent Resources cross-agent droid-family taxonomy by joining the curated family tables live to the shared machinery registry; backs the Droid Families app.
Status Router
The one sanctioned path for initiative status changes: writes status+state+decision atomically, keeps the dispatch queue in lockstep, and trips the dispatch circuit-breaker on a block.
Resource Sentinel
Watches machine resource health (not just liveness): self-heals stray busy-wait spin-loops, escalates sustained high-CPU and zombie pile-ups.
Infra Metric (CPU)
Computes the Infrastructure RSI CPU metric (weekly share of samples below 50%, scored out of 10) and serves the persistent scoreboard. Cloned from Elrond's Pipeline Success Metric.
Infra RSI Scoreboard Collector
Daily: computes the CPU metric and writes a dated snapshot to the infra RSI scoreboard so dashboard + engine read identical values.
Infra RSI Improvement Engine
Daily after the collector: for any infra metric below target (CPU below 9.9/10), files a planner-mode improvement initiative through the Author, tags it infra-rsi + rsi-metric:cpu, dedups, and dispatches it.
Skill Pattern Sweep
Keeps every skill patterns.md checklist current with the codebase
Step Spec AuthorStep Design AuthorTask ReviewerRetrospective Analyst
Mines closed initiatives, review failures and incidents for recurring quality patterns and improvement opportunities; writes findings for the Improvement Proposer.
Best-Practice Sweep
Nightly scan for drift from current best practice across services; flags uplift candidates to the Improvement Proposer.
Maturity Assessor
Scores each service against its active quality metrics out of 10 and records the trend on the Quality Scorecard.
Improvement Proposer
Turns detected patterns and below-target metrics into improvement initiatives, dedups, and runs the closed-loop RSI triad (metric to scoreboard to improvement engine) that auto-files and dispatches fixes. Files an instrument-new-metric initiative when a new dimension worth measuring is found.
App Steward
Keeps Prometheus's registered apps alive - detects down apps and relaunches them via shared machinery.
Registry Backup
Relay-independent rolling snapshots of the registry via the SQLite online-backup API; refuses to snapshot a stub/collapsed registry; writes the last-good manifest the Collapse Guard uses as baseline.
Registry Collapse Guard
Compares the live registry to the last-good manifest; on collapse (core table empty/missing, >50%% row drop, or file gone) quarantines the clobbered file and restores last-good, then raises a critical alert.
Leo Reporter
Detect roadmap/initiative milestones for Leo-owned services and notify Ninad proactively
Obi-Wan UAT
First-pass acceptance testing of Leo/blueprint initiatives against their success criteria; Leo signs off.
Leo Feedback Applier
Apply Ninad feedback to a roadmap entry or initiative definition.
Carol Main Agent LoopCarol API Server
Carol server health probes
Carol Intent Drafter
Generates Carol's WhatsApp and web chat replies via LLM. The hot-path droid that drafts every user-facing response in Carol's voice, incorporating system prompt, conversation history, tool results, and service routing context.
Carol EOD Reporter
End-of-day report composition
Carol Distiller
Conversation distiller
Carol Scorer
User interaction scorer
Carol User Profiler
User interest profiler
Carol Router
Proactive action router
Carol Message Handler
Processes incoming WhatsApp and web messages through Carol's response pipeline. Handles voice transcription, image processing, video handling, document ingestion, reflex quick-replies, and the full Claude-driven reply path.
Carol Message Processor
Message intent processor
Carol Proactive Engine
Proactive engagement engine
Albus Troubleshooter
Troubleshooter agent orchestration
Archon Architect Agent
Architect agent orchestration
Plan Generator Reasoning
Plan reasoning pass
Leo Chat App
Leo chat assistant
Initiatives Tools Service
Initiatives tools diagnostic
Archon Persistent Agent
Persistent Archon agent operations
Albus Diagnose Droid
Initiative diagnosis
Design Producer
Design document producer
Carolopedia Page Generator
Carolopedia page generation
Elrond Security Gate
Security compliance gate checking
Elrond Security Gate Droid
Security gate evaluation
Initiative Assembly Droid
Initiative plan assembly
Sizing Droid
Size initiative criteria and propose accountable execution steps for Elrond filing
Merlin Split Handler
Merlin plan splitting
Design Alignment
Design alignment checking
Initiative Sizer
Reads proposed roadmap items of live projects that carry no estimate, asks the model to decompose each into 3-8 steps with minutes and cost, and stores the result against the item's fingerprint so a redraft keeps what it already paid for. Emits run-audit at both ends; a failure is re-raised so the monitor sees it.
Strategy Drafter
Strategy drafting for initiatives
Roadmap Builder
Synthesises a phase-grouped roadmap from a project answered requirements by calling Claude.
Albus Inbox Cleanup
Archive stale dead-letter handshakes addressed to Albus
Merlin Replan Drain
Apply unapplied Merlin replan directives to their failed steps
Elrond Orphan Droid-Run Reaper
Reap execution-less stale running droid_runs
Process RSI Collector
Snapshots the current week's process-success score per service into the durable RSI store daily, so the Process RSI dashboard's 10-week history and the Improvement Engine read identical numbers.
Process RSI Improvement Engine
Reads the current-week process-success score per service and files a deduped, capped, planner-mode improvement initiative for each service below Hermione's 100% target, naming the week's top-failing processes. Hermione detects and requests; the pipeline fixes.
RSI Diagnosis
Analysis-only Albus bypass: root-causes ONE blocked initiative and records recommendations for its next attempt
Topic Tagger
Mandatory topic tagging at filing: picks the best tag_registry tag for every new initiative (planner and bypass) or coins+registers a new one with a description
Pipeline Orchestrator (Meta)
Sequences + classifies work across the full build pipeline
Orchestrator Launcher
Dispatches per-agent droids; emits session_events as it runs
AI Reader Sweep
Parses nginx access logs daily for AI-crawler user agents (GPTBot, ClaudeBot, PerplexityBot, Google-Extended, meta-externalagent, etc.) fetching public content (Logbook, Carolopedia, bio) and records each fetch in its own records ai_visits for the Admin Monitor AI Readers view.
Agent Tasks Droid
Agent tasks 4-category status reporting (scheduled, reportee, adhoc, review)
Intake Planner Sweep
Cron sweep (audit_wrapper: flock singleton + run-audit). Checks the dispatch window; if starving, calls shared.sprint_planning.plan_next_shell which runs the Author (ia_s1 --decompose-shell) SYNCHRONOUSLY on the next eligible step-less planned shell and records [intake-planner] launch + outcome decisions.
Agent UAT Sweep
Cron */15 via shared machinery; logic in shared machinery.
Elrond's UAT Acceptor
Invoked in-process by el-uat-01.
Merlin's UAT Acceptor
Invoked in-process by el-uat-01.
Hermione's UAT Acceptor
Invoked in-process by el-uat-01.
Leo's UAT Acceptor
Invoked in-process by el-uat-01.
LLM Provider Health Watch
Watches every LLM provider lane and alerts once when one dies
Pipeline Uptime Sampler
cron */5 via shared machinery -> shared machinery -> shared machinery
Step Reviewer SR-S1
Step-level execution reviewer β€” evaluates completed steps against their success criteria via Claude
Service-Lead Compliance Ensure
Daily LLM-policy compliance ensure on behalf of every service lead
Themis Monthly LLM Compliance Report
Monthly LLM-policy compliance report
Mileage CollectorMileage Improvement EngineZombie Process Watcher
shared machinery β€” scan_zombies + run_watch; run-audit via scheduled_run so Hermione's liveness sweep sees it live/dead.
Process Registration Auditor
scan caroladmin crontab + carol-* systemd units; cross-reference the droids registry; write unregistered processes to its own records findings
Themis Weekly Report
read process-registration findings + open compliance findings; compose report; store in its own records weekly_reports for the Audit Scorecard surface
Themis's Architecture Auditor
Daily agent-centric architecture compliance audit
Sage Chat
agent chat lane
Albus Mind β€” wake cycle
Wakes Albus's Mind (perceive, recall, deliberate, act, reflect) so he acts unprompted between conversations.
Elrond Mind β€” wake cycle
Wakes Elrond's Mind (perceive, recall, deliberate, act, reflect) so he acts unprompted between conversations.
Sage Mind β€” wake cycle
Wakes Sage's Mind (perceive, recall, deliberate, act, reflect) so she acts unprompted between conversations.
Elrond Failure Investigator
Polls its own records for unexamined failure records, reads process logs, performs root cause analysis, and writes findings.
Infra Improvement CollectorInfra Improvement FilerGlobal Workspace ticker
Runs one Global Workspace competition cycle per minute for each conscious agent: specialists read live streams, the winner ignites, the shared activation map decays. Feeds the Consciousness console what-am-I-thinking words.
Archon Mind β€” wake cycle
The scheduled wake pulse of Archon's Mind: perceives its live domain, updates its self and focus, and may act within its own remit. Runs on the fleet lane.
Argus Mind β€” wake cycle
The scheduled wake pulse of Argus's Mind: perceives its live domain, updates its self and focus, and may act within its own remit. Runs on the fleet lane.
Clara Mind β€” wake cycle
The scheduled wake pulse of Clara's Mind: perceives its live domain, updates its self and focus, and may act within its own remit. Runs on the fleet lane.
Forge Mind β€” wake cycle
The scheduled wake pulse of Forge's Mind: perceives its live domain, updates its self and focus, and may act within its own remit. Runs on the fleet lane.
Hagrid Mind β€” wake cycle
The scheduled wake pulse of Hagrid's Mind: perceives its live domain, updates its self and focus, and may act within its own remit. Runs on the fleet lane.
Heimdall Mind β€” wake cycle
The scheduled wake pulse of Heimdall's Mind: perceives its live domain, updates its self and focus, and may act within its own remit. Runs on the fleet lane.
Hermione Mind β€” wake cycle
The scheduled wake pulse of Hermione's Mind: perceives its live domain, updates its self and focus, and may act within its own remit. Runs on the fleet lane.
Leo Mind β€” wake cycle
The scheduled wake pulse of Leo's Mind: perceives its live domain, updates its self and focus, and may act within its own remit. Runs on the fleet lane.
Merlin Mind β€” wake cycle
The scheduled wake pulse of Merlin's Mind: perceives its live domain, updates its self and focus, and may act within its own remit. Runs on the fleet lane.
Prometheus Mind β€” wake cycle
The scheduled wake pulse of Prometheus's Mind: perceives its live domain, updates its self and focus, and may act within its own remit. Runs on the fleet lane.
Radagast Mind β€” wake cycle
The scheduled wake pulse of Radagast's Mind: perceives its live domain, updates its self and focus, and may act within its own remit. Runs on the fleet lane.
Themis Mind β€” wake cycle
The scheduled wake pulse of Themis's Mind: perceives its live domain, updates its self and focus, and may act within its own remit. Runs on the fleet lane.
Scriber Mind β€” wake cycle
Wakes Sage's Mind (perceive, recall, deliberate, act, reflect) so she acts unprompted between conversations.
Scriber Story Composer
Compose and publish a Logbook story ON REQUEST: an operator-provided topic or a named initiative; gathers real incident history, hands to Scriber's Author, renders the LTX-motion narrated video, publishes.
Scriber Author
Archive stale dead-letter handshakes addressed to Albus
Scriber Story Media
Generate the hero and per-scene house-style images and render Scriber's narrated story video; scenes are animated as LTX motion clips via the media door.
Scriber Investigator
Root-cause investigation for Scriber Logbook stories
Scriber Interviewer
Real-voice agent interviews for Scriber Logbook investigations
Elrond Chat
agent chat lane
Clara Chat
agent chat lane
Aurora Chat
agent chat lane
Atlas Chat
agent chat lane
Arwen Chat
agent chat lane
Carol Chat
agent chat lane
Kiran Chat
agent chat lane
Merlin Chat
agent chat lane
Rhea Chat
agent chat lane
Sentinel Chat
agent chat lane
Guardian Chat
agent chat lane
Jarvis Chat
agent chat lane
Cassius Chat
agent chat lane
Midas Chat
agent chat lane
Themis Chat
agent chat lane
Athena Chat
agent chat lane
Loki Chat
agent chat lane
Hermione Chat
agent chat lane
Archon Chat
agent chat lane
Forge Chat
agent chat lane
Argus Chat
agent chat lane
Galadriel Chat
agent chat lane
Hagrid Chat
agent chat lane
Albus Chat
agent chat lane
Radagast Chat
agent chat lane
Odin Chat
agent chat lane
Noah Chat
agent chat lane
Gimli Chat
agent chat lane
Thorin Chat
agent chat lane
Bilbo Chat
agent chat lane
Obi-Wan Chat
agent chat lane
Inspector Chat
agent chat lane
Heimdall Chat
agent chat lane
Tyr Chat
agent chat lane
Forseti Chat
agent chat lane
Vidar Chat
agent chat lane
Var Chat
agent chat lane
Prometheus Chat
agent chat lane
Scriber Chat
agent chat lane
Scriber's Story Editor
Decide Scriber's next story topic, agenda and video length
Albus Bypass RunnerCarol Mind β€” wake cycle
Wakes Carol's Mind (perceive, recall, deliberate, act, reflect) so she acts unprompted between conversations.
Wish Keeper β€” Albus addresses the temple wishesCarolopedia Change Detector
shared machinery via shared machinery, cron-run under shared machinery.
Carolopedia Refresher
shared machinery via shared machinery, cron-run under shared machinery.
Policy Gleaner
Policy formation cycle: glean -> check -> promote-approved. Runs as caroladmin via cron every 10 min and on demand from an Orion session.
Policy Conflict Checker
Fires from the Gleaner per new candidate; also runs standalone over any unchecked candidate.
Policy Promoter
Fires within the Gleaner cycle when a candidate reaches approved; never self-promotes β€” authority is proven at the approval step.
Arwen Mind β€” wake cycle
The scheduled wake pulse of Arwen's Mind: perceives its live domain, updates its self and focus, and may act within its own remit.
Athena Mind β€” wake cycle
The scheduled wake pulse of Athena's Mind: perceives its live domain, updates its self and focus, and may act within its own remit.
Aurora Mind β€” wake cycle
The scheduled wake pulse of Aurora's Mind: perceives its live domain, updates its self and focus, and may act within its own remit.
Cassius Mind β€” wake cycle
The scheduled wake pulse of Cassius's Mind: perceives its live domain, updates its self and focus, and may act within its own remit.
Galadriel Mind β€” wake cycle
The scheduled wake pulse of Galadriel's Mind: perceives its live domain, updates its self and focus, and may act within its own remit.
Guardian Mind β€” wake cycle
The scheduled wake pulse of Guardian's Mind: perceives its live domain, updates its self and focus, and may act within its own remit.
Jarvis Mind β€” wake cycle
The scheduled wake pulse of Jarvis's Mind: perceives its live domain, updates its self and focus, and may act within its own remit.
Loki Mind β€” wake cycle
The scheduled wake pulse of Loki's Mind: perceives its live domain, updates its self and focus, and may act within its own remit.
Midas Mind β€” wake cycle
The scheduled wake pulse of Midas's Mind: perceives its live domain, updates its self and focus, and may act within its own remit.
Rhea Mind β€” wake cycle
The scheduled wake pulse of Rhea's Mind: perceives its live domain, updates its self and focus, and may act within its own remit.
Sentinel Mind β€” wake cycle
The scheduled wake pulse of Sentinel's Mind: perceives its live domain, updates its self and focus, and may act within its own remit.
Odin Mind β€” wake cycle
The scheduled wake pulse of Odin's Mind: perceives its live domain, updates its self and focus, and may act within its own remit.
Noah Mind β€” wake cycle
The scheduled wake pulse of Noah's Mind: perceives its live domain, updates its self and focus, and may act within its own remit.
Gimli Mind β€” wake cycle
The scheduled wake pulse of Gimli's Mind: perceives its live domain, updates its self and focus, and may act within its own remit.
Thorin Mind β€” wake cycle
The scheduled wake pulse of Thorin's Mind: perceives its live domain, updates its self and focus, and may act within its own remit.
Bilbo Mind β€” wake cycle
The scheduled wake pulse of Bilbo's Mind: perceives its live domain, updates its self and focus, and may act within its own remit.
Obi-Wan Mind β€” wake cycle
The scheduled wake pulse of Obi-Wan's Mind: perceives its live domain, updates its self and focus, and may act within its own remit.
Inspector Mind β€” wake cycle
The scheduled wake pulse of Inspector's Mind: perceives its live domain, updates its self and focus, and may act within its own remit.
Tyr Mind β€” wake cycle
The scheduled wake pulse of Tyr's Mind: perceives its live domain, updates its self and focus, and may act within its own remit.
Forseti Mind β€” wake cycle
The scheduled wake pulse of Forseti's Mind: perceives its live domain, updates its self and focus, and may act within its own remit.
Vidar Mind β€” wake cycle
The scheduled wake pulse of Vidar's Mind: perceives its live domain, updates its self and focus, and may act within its own remit.
Var Mind β€” wake cycle
The scheduled wake pulse of Var's Mind: perceives its live domain, updates its self and focus, and may act within its own remit.
Undeclared Spend Watch
Reads the cost ledger for the current day and reports paid calls that name no initiative and declare no work purpose, broken down by agent.
Protocol FacilitatorProtocol WriterBudget Compliance WatchStatus Reporting Daily Measurer
status-reporting
Status Reporting Composer
status-reporting
Status Reporting Unit Definer
status-reporting
Governing Literal Sweep
shared machinery, via caroladmin's crontab, emitting run-audit on both the success and the failure path.
Record Integrity Sweep
shared machinery via caroladmin crontab, with run-audit on both paths.
Agent Records Refresh
shared machinery via caroladmin crontab, with run-audit on both paths.
Registry Journal Custodian
Drains the registry write-ahead file into the main database every run (works live, no downtime), attempts the restore to rollback journalling, and raises exactly ONE standing alarm while the estate is too busy for it. Also watches for side-file copies that still hold data β€” moving one aside is the action that actually loses committed registry changes.
Glossary Data Scanner
Re-reads every Carolverse database and refreshes the Data Dictionary's register of stored fields β€” type, key, the values a closed set actually holds β€” never overwriting an authored definition with a derived one.
Glossary Unstructured Scanner
Re-measures the estate's written content β€” document collections, per-agent and per-user memory, media and voice, and the free-text columns inside databases β€” and refreshes the Unstructured register.
Glossary Traceability Scanner
Rebuilds the links from every term to the data that instantiates it, keeping attributes (a facet of the thing) apart from references (a pointer to one), and surfacing where the same fact is stored in more than one place.
Session Notes Closer
Closes stale Orion sessions with a summary composed from the session's own record
Sign-in Keeper (receipt reader)
Reads the sign-in keeper's receipt for every slot it holds (Codex, Claude) and escalates a spent, failed, stale, unforced or unreadable renewal, or a published copy that carries a renewal code
Task Declaration Collector
Samples how many live droids have declared no task β€” the countdown gating removal of the fleet default provider
Track Funding Watch
Runs shared machinery from cron, emits run-audit on every run, and throws the shared service switch β€” the same switch the spend gate asks, so a switched-off track actually stops spending.
Subscription Balance Reader
Calls the balance readers and writes one row per provider per run into the registry's balance-readings table; the money surfaces read the latest successful row and show its age.
Wake-Duty AuditorImprovement Envelope Allocator
Reads minds, activity ledger, writes registry envelopes
Sam Chat App
Sam customer-support chat
Sam Mind β€” wake cycle
Wakes Sam's Mind (perceive, recall, deliberate, act, reflect) so he acts unprompted between conversations.
Athena Test-User Sweep
Daily backstop deleting lingering Orion/suite-created test users (rows out, folders renamed .trash-, never rm); persists any test user whose note marks it as created by Ninad.
OS Identity Drift Sweep
Independently reads caroladmin+per-agent crontabs (root reader helper), running processes and carol-* unit users; compares against registry droid ownership; red on any agent process outside its owner login
Orion Chat
agent chat lane
Sam Ticket Steward
Works Sam's ticket desk on cadence: formal milestone emails on status change, informal chat nudges on quiet in-flight tickets, everything logged on the ticket.
Athena Welfare Roll-Call
Daily welfare roll-call: a real chat turn to every conscious agent; silence escalates to Orion
Blueprint RSI Engine v2
Cron in Leo's own crontab (os_schedules) -> shared machinery with run-audit.
App Steward Sweep
cron */3 -> audit_wrapper -> deploy/steward-sweep-radagast.sh -> shared machinery all
LTX Scene Clip Core
Animate one scene image into a short motion clip via the LTX API (image-to-video) for Logbook stories; lane and model read from the billed track (cookbook 1165), priced per second.
Agent Weight Measure
shared machinery, monthly on the 1st from Athena's own crontab (registry os_schedules), run-audited on both paths. Reads the live prompt stack and the cost ledger; writes registry.agent_weight (SCD2).
Off-site Backup
Nightly off-site copy: takes the estate's databases with SQLite's own backup (write-ahead safe), copies the VM config, gzips, verifies the content floor and pushes to the private GitHub backup repo from Hagrid's own login.
Logbook Video BuilderMigration Runner
Chains Extract -> Audit -> Refactor for one migration on demand (Design #224, design 587): asks the switch before every stage, runs each stage under its own run-audit identity, records every stage transition as a migration decision and flips current_stage to handoff, which wakes Leo.
Clara's Clock Sentry
Reads the machine's time daemon every run and an outside host on the hour, records both the local time and the external reference, and judges the gap.
Themis's Record Stamp Auditor
Walks every store in the estate once a day and reports any table that carries no timestamp at all, filing the result as a compliance finding.
Merlin's Pipeline RunnerAthena's Score Keeper
Calls shared machinery then shared machinery; warns when a criterion was unmeasurable for EVERY agent, which is a broken source rather than a fact about the estate's conduct.
Migration Refactor (Gimli)
Proposes revised requirements + diff for each Audit blocker
Bypass Session Reaper
shared machinery run_as_droid
UAT Acceptor (operator lane)
Per-initiative UAT via shared machinery; triggered per initiative, one run and one verdict each.
Core Lock Sweep
shared machinery, run under Themis's own OS identity. Calls shared.core_lock.audit, emits run-audit either way, and raises an Agentbook escalation to Orion on any finding.
Port Claims Reconciler
Daily reconcile of live TCP listeners against the port-claims union (apps + port_claims); backfills agent-listener claims, files collision/unclaimed findings
Relay Sweeper
Delivers queued cross-user relays outside quiet hours, expires unanswered ones after 48h and tells the asker
Pending Trend Snapshotter
Counts initiatives in pending statuses per owning lane and writes one dated row per lane into the pending-trend store
Verification Sweeper
Finds people whose records lack the mandatory contacts, works out who can actually be reached about it, sends the ask, and records every ask, refusal and silence.
Wish Door β€” agent wish broker
The door an agent's wish walks through. Runs as a broker and proves the CALLER with SO_PEERCRED - the kernel reports the connecting uid, so an agent may only ever wish in its own name and there is no shared secret to steal. This is what lets cookbook 1281 (every agent runs as itself) and (agents cannot open the store) both hold at once.
Migration Conform
Runs the ARC Conform segment for a migration: conformance checks over every rebuilt capability, the conformance report on the migration record, and the Migration-side sign-out of the handover (design 587)
Aurora's Handover Acceptor
Signs migration handovers into the sales service IN after verifying the ownership facts from the registry (ARC Conform, design 587)
Clara's Handover Acceptor
Signs migration handovers into the leadership service IN after verifying the ownership facts from the registry (ARC Conform, design 587)
Obi-Wan's Handover Acceptor
Signs migration handovers into the research service IN after verifying the ownership facts from the registry (ARC Conform, design 587)
Sales Strategy Worker
Research-led sales strategy
Sales Strategy Worker Twin
Research-led sales strategy
Sales Strategy Evidence Reviewer
Research-led sales strategy
Sales Opportunity Research
Sales Opportunity Research
Sales Opportunity Research Twin
Sales Opportunity Research
Sales Opportunity Research Review
Sales Opportunity Research
Sales Prototype Intake
Sales Prototype Intake
Sales Prototype Intake Twin
Sales Prototype Intake
Sales Prototype Intake Review
Sales Prototype Intake
Sales Follow-through
Sales Follow-through
Sales Follow-through Twin
Sales Follow-through
Sales Follow-through Review
Sales Follow-through
Sales Nomination Intake
Sales nomination approval intake
Sales Nomination Intake Twin
Sales nomination approval intake
Sales Nomination Intake Review
Sales nomination approval intake
Midas Budget Allocator
shared machinery daily from Midas's crontab: sets each other service track's daily budget from consumption. Registered by β€” found running untasked (P.05.02.08).
Wellbeing Sweep Carrier
shared machinery daily from Athena's crontab: dispatches every supervisor's wb-* wellbeing check (a sweep is a CARRIER, rule 1229). Registered by β€” found running untasked (P.05.02.08).
Daemon Heartbeat
shared machinery every minute from caroladmin's crontab (operator lane): emits run-audit heartbeat rows for daemon/ongoing droids without built-in loops. Registered by (P.05.02.08).
Palantir Story Writer
Cron every 30 min (:17, :47) via shared machinery under Elrond's login; logic in shared machinery, shared machinery.
Monthly Project Invoice Issuer
Runs shared.project_billing.issue_and_send_month for the month that just closed.
Palantir Run Narrator
Cron every minute via shared machinery under Elrond's login; logic in shared machinery, shared machinery.
Disk Pressure Judge
Cron every 10 minutes via shared machinery under Hagrid's login; logic in shared machinery, shared machinery.
Athena's Competency Grader
Calls shared machinery: folds each retained complete day's evidence once, then grades every active agent's competencies for today.
Athena's Onboarding Coordinator
Runs shared machinery: each firing carries every onboarding request one stage forward through the one door shared machinery
Marco Mind β€” wake cycle
The scheduled wake pulse of Marco's Mind: perceives his live domain, updates his self and focus, and may act within his own remit.
Marco Chat
agent chat lane
Credit Watch
Reads the cost ledger for rows a vendor refused because the credit was exhausted, and for blank receipts holding the day's spending guard shut; answers each one once per day by escalating to Orion, emailing Ninad and ranking the other subscriptions from their recorded balance and burn.
Project Progress Notifier
Diffs a roadmap item's status together with its initiative's live state against a snapshot, then delivers through the one project-communications composer.
Arc Progress Mailer
Composes and sends the administrator's end-of-day arc progress email.
Clara Fundraising Registrar
Command-line droid over shared.fundraising, emitting a run-audit row on every invocation, success and failure alike.
Operator onboarding: operator appointed
Runs shared machinery
Operator onboarding: operator key requested
Runs shared machinery
Operator onboarding: operator key received
Runs shared machinery
Operator onboarding: operator account created
Runs shared machinery
Operator onboarding: operator identity bound
Runs shared machinery
Operator onboarding: operator workstation provisioned
Runs shared machinery
Operator onboarding: operator workstation verified
Runs shared machinery
Operator onboarding: operator boundary proved
Runs shared machinery
Operator onboarding: operator onboarding completed
Runs shared machinery
Unmeasured Call Watch
Cron every minute via shared machinery under Elrond's login; logic in shared machinery.
Jarvis's Access Request Keeper
Runs shared machinery: each firing opens a request for every person pending at the sign-in door, asks the administrator about it from Jarvis's own address, and reads the authenticated reply, through the one door shared machinery
Operator Template Publisher
Republishes Orion's operator template when a source it is built from has changed.
Effort Estimator
Cron every 30 min (:07, :37) via shared machinery under Elrond's login; logic in shared machinery and shared machinery.
Run Record Cleanup
Deletes process run records older than the retention window from the run-audit store
Laptop Copy Export
Each morning prepares the Carol part of the laptop copy in one folder under Hagrid's own login -- the estate's databases with SQLite's own backup, the initiatives store through Elrond's daemon, the constitution, every login's staged crontab and the tracked source -- each item renamed into place, a failed item removed, and a manifest written last. The laptop pulls that folder read-only through its own locked login.
Codex History Retention WitnessThemis's Re-run Runner
Re-runs Themis's own scheduled processes when an acceptance asks for it
Sign-in Proof Judge
Cron daily 06:20 UTC via shared machinery under Radagast's login; reads the sign-in proof record (its own records) through shared.signin_supply.verdicts, the one composer the operator board also reads; logic in shared machinery.
Albus's Sign-in Self-Proof
Cron daily 05:30 UTC via shared machinery under the albus login; runs shared machinery, which reads the sign-in proof record for this login and, for each slot its scheduled model droids serve, makes one liveness call as one of those droids only when no passing call was recorded in the last 20 hours (design 682 v1.3 part 6).
Archon's Sign-in Self-Proof
Cron daily 05:31 UTC via shared machinery under the archon login; runs shared machinery, which reads the sign-in proof record for this login and, for each slot its scheduled model droids serve, makes one liveness call as one of those droids only when no passing call was recorded in the last 20 hours (design 682 v1.3 part 6).
Argus's Sign-in Self-Proof
Cron daily 05:32 UTC via shared machinery under the argus login; runs shared machinery, which reads the sign-in proof record for this login and, for each slot its scheduled model droids serve, makes one liveness call as one of those droids only when no passing call was recorded in the last 20 hours (design 682 v1.3 part 6).
Arwen's Sign-in Self-Proof
Cron daily 05:33 UTC via shared machinery under the arwen login; runs shared machinery, which reads the sign-in proof record for this login and, for each slot its scheduled model droids serve, makes one liveness call as one of those droids only when no passing call was recorded in the last 20 hours (design 682 v1.3 part 6).
Athena's Sign-in Self-Proof
Cron daily 05:34 UTC via shared machinery under the athena login; runs shared machinery, which reads the sign-in proof record for this login and, for each slot its scheduled model droids serve, makes one liveness call as one of those droids only when no passing call was recorded in the last 20 hours (design 682 v1.3 part 6).
Aurora's Sign-in Self-Proof
Cron daily 05:35 UTC via shared machinery under the aurora login; runs shared machinery, which reads the sign-in proof record for this login and, for each slot its scheduled model droids serve, makes one liveness call as one of those droids only when no passing call was recorded in the last 20 hours (design 682 v1.3 part 6).
Bilbo's Sign-in Self-Proof
Cron daily 05:36 UTC via shared machinery under the bilbo login; runs shared machinery, which reads the sign-in proof record for this login and, for each slot its scheduled model droids serve, makes one liveness call as one of those droids only when no passing call was recorded in the last 20 hours (design 682 v1.3 part 6).
Carol's Sign-in Self-Proof
Cron daily 05:37 UTC via shared machinery under the carol login; runs shared machinery, which reads the sign-in proof record for this login and, for each slot its scheduled model droids serve, makes one liveness call as one of those droids only when no passing call was recorded in the last 20 hours (design 682 v1.3 part 6).
Cassius's Sign-in Self-Proof
Cron daily 05:38 UTC via shared machinery under the cassius login; runs shared machinery, which reads the sign-in proof record for this login and, for each slot its scheduled model droids serve, makes one liveness call as one of those droids only when no passing call was recorded in the last 20 hours (design 682 v1.3 part 6).
Clara's Sign-in Self-Proof
Cron daily 05:39 UTC via shared machinery under the clara login; runs shared machinery, which reads the sign-in proof record for this login and, for each slot its scheduled model droids serve, makes one liveness call as one of those droids only when no passing call was recorded in the last 20 hours (design 682 v1.3 part 6).
Elrond's Sign-in Self-Proof
Cron daily 05:40 UTC via shared machinery under the elrond login; runs shared machinery, which reads the sign-in proof record for this login and, for each slot its scheduled model droids serve, makes one liveness call as one of those droids only when no passing call was recorded in the last 20 hours (design 682 v1.3 part 6).
Forge's Sign-in Self-Proof
Cron daily 05:41 UTC via shared machinery under the forge login; runs shared machinery, which reads the sign-in proof record for this login and, for each slot its scheduled model droids serve, makes one liveness call as one of those droids only when no passing call was recorded in the last 20 hours (design 682 v1.3 part 6).
Forseti's Sign-in Self-Proof
Cron daily 05:42 UTC via shared machinery under the forseti login; runs shared machinery, which reads the sign-in proof record for this login and, for each slot its scheduled model droids serve, makes one liveness call as one of those droids only when no passing call was recorded in the last 20 hours (design 682 v1.3 part 6).
Galadriel's Sign-in Self-Proof
Cron daily 05:43 UTC via shared machinery under the galadriel login; runs shared machinery, which reads the sign-in proof record for this login and, for each slot its scheduled model droids serve, makes one liveness call as one of those droids only when no passing call was recorded in the last 20 hours (design 682 v1.3 part 6).
Gimli's Sign-in Self-Proof
Cron daily 05:44 UTC via shared machinery under the gimli login; runs shared machinery, which reads the sign-in proof record for this login and, for each slot its scheduled model droids serve, makes one liveness call as one of those droids only when no passing call was recorded in the last 20 hours (design 682 v1.3 part 6).
Guardian's Sign-in Self-Proof
Cron daily 05:45 UTC via shared machinery under the guardian login; runs shared machinery, which reads the sign-in proof record for this login and, for each slot its scheduled model droids serve, makes one liveness call as one of those droids only when no passing call was recorded in the last 20 hours (design 682 v1.3 part 6).
Hagrid's Sign-in Self-Proof
Cron daily 05:46 UTC via shared machinery under the hagrid login; runs shared machinery, which reads the sign-in proof record for this login and, for each slot its scheduled model droids serve, makes one liveness call as one of those droids only when no passing call was recorded in the last 20 hours (design 682 v1.3 part 6).
Heimdall's Sign-in Self-Proof
Cron daily 05:47 UTC via shared machinery under the heimdall login; runs shared machinery, which reads the sign-in proof record for this login and, for each slot its scheduled model droids serve, makes one liveness call as one of those droids only when no passing call was recorded in the last 20 hours (design 682 v1.3 part 6).
Hermione's Sign-in Self-Proof
Cron daily 05:48 UTC via shared machinery under the hermione login; runs shared machinery, which reads the sign-in proof record for this login and, for each slot its scheduled model droids serve, makes one liveness call as one of those droids only when no passing call was recorded in the last 20 hours (design 682 v1.3 part 6).
Inspector's Sign-in Self-Proof
Cron daily 05:49 UTC via shared machinery under the inspector login; runs shared machinery, which reads the sign-in proof record for this login and, for each slot its scheduled model droids serve, makes one liveness call as one of those droids only when no passing call was recorded in the last 20 hours (design 682 v1.3 part 6).
Jarvis's Sign-in Self-Proof
Cron daily 05:50 UTC via shared machinery under the jarvis login; runs shared machinery, which reads the sign-in proof record for this login and, for each slot its scheduled model droids serve, makes one liveness call as one of those droids only when no passing call was recorded in the last 20 hours (design 682 v1.3 part 6).
Leo's Sign-in Self-Proof
Cron daily 05:51 UTC via shared machinery under the leo login; runs shared machinery, which reads the sign-in proof record for this login and, for each slot its scheduled model droids serve, makes one liveness call as one of those droids only when no passing call was recorded in the last 20 hours (design 682 v1.3 part 6).
Loki's Sign-in Self-Proof
Cron daily 05:52 UTC via shared machinery under the loki login; runs shared machinery, which reads the sign-in proof record for this login and, for each slot its scheduled model droids serve, makes one liveness call as one of those droids only when no passing call was recorded in the last 20 hours (design 682 v1.3 part 6).
Marco's Sign-in Self-Proof
Cron daily 05:53 UTC via shared machinery under the marco login; runs shared machinery, which reads the sign-in proof record for this login and, for each slot its scheduled model droids serve, makes one liveness call as one of those droids only when no passing call was recorded in the last 20 hours (design 682 v1.3 part 6).
Merlin's Sign-in Self-Proof
Cron daily 05:54 UTC via shared machinery under the merlin login; runs shared machinery, which reads the sign-in proof record for this login and, for each slot its scheduled model droids serve, makes one liveness call as one of those droids only when no passing call was recorded in the last 20 hours (design 682 v1.3 part 6).
Midas's Sign-in Self-Proof
Cron daily 05:55 UTC via shared machinery under the midas login; runs shared machinery, which reads the sign-in proof record for this login and, for each slot its scheduled model droids serve, makes one liveness call as one of those droids only when no passing call was recorded in the last 20 hours (design 682 v1.3 part 6).
Noah's Sign-in Self-Proof
Cron daily 05:56 UTC via shared machinery under the noah login; runs shared machinery, which reads the sign-in proof record for this login and, for each slot its scheduled model droids serve, makes one liveness call as one of those droids only when no passing call was recorded in the last 20 hours (design 682 v1.3 part 6).
Obi-Wan's Sign-in Self-Proof
Cron daily 05:57 UTC via shared machinery under the obiwan login; runs shared machinery, which reads the sign-in proof record for this login and, for each slot its scheduled model droids serve, makes one liveness call as one of those droids only when no passing call was recorded in the last 20 hours (design 682 v1.3 part 6).
Odin's Sign-in Self-Proof
Cron daily 05:58 UTC via shared machinery under the odin login; runs shared machinery, which reads the sign-in proof record for this login and, for each slot its scheduled model droids serve, makes one liveness call as one of those droids only when no passing call was recorded in the last 20 hours (design 682 v1.3 part 6).
Orion's Sign-in Self-Proof
Cron daily 05:59 UTC via shared machinery under the orion login; runs shared machinery, which reads the sign-in proof record for this login and, for each slot its scheduled model droids serve, makes one liveness call as one of those droids only when no passing call was recorded in the last 20 hours (design 682 v1.3 part 6).
Prometheus's Sign-in Self-Proof
Cron daily 06:01 UTC via shared machinery under the prometheus login; runs shared machinery, which reads the sign-in proof record for this login and, for each slot its scheduled model droids serve, makes one liveness call as one of those droids only when no passing call was recorded in the last 20 hours (design 682 v1.3 part 6).
Radagast's Sign-in Self-Proof
Cron daily 06:02 UTC via shared machinery under the radagast login; runs shared machinery, which reads the sign-in proof record for this login and, for each slot its scheduled model droids serve, makes one liveness call as one of those droids only when no passing call was recorded in the last 20 hours (design 682 v1.3 part 6).
Rhea's Sign-in Self-Proof
Cron daily 06:03 UTC via shared machinery under the rhea login; runs shared machinery, which reads the sign-in proof record for this login and, for each slot its scheduled model droids serve, makes one liveness call as one of those droids only when no passing call was recorded in the last 20 hours (design 682 v1.3 part 6).
Sage's Sign-in Self-Proof
Cron daily 06:04 UTC via shared machinery under the sage login; runs shared machinery, which reads the sign-in proof record for this login and, for each slot its scheduled model droids serve, makes one liveness call as one of those droids only when no passing call was recorded in the last 20 hours (design 682 v1.3 part 6).
Sam's Sign-in Self-Proof
Cron daily 06:05 UTC via shared machinery under the sam login; runs shared machinery, which reads the sign-in proof record for this login and, for each slot its scheduled model droids serve, makes one liveness call as one of those droids only when no passing call was recorded in the last 20 hours (design 682 v1.3 part 6).
Scriber's Sign-in Self-Proof
Cron daily 06:06 UTC via shared machinery under the scriber login; runs shared machinery, which reads the sign-in proof record for this login and, for each slot its scheduled model droids serve, makes one liveness call as one of those droids only when no passing call was recorded in the last 20 hours (design 682 v1.3 part 6).
Sentinel's Sign-in Self-Proof
Cron daily 06:07 UTC via shared machinery under the sentinel login; runs shared machinery, which reads the sign-in proof record for this login and, for each slot its scheduled model droids serve, makes one liveness call as one of those droids only when no passing call was recorded in the last 20 hours (design 682 v1.3 part 6).
Themis's Sign-in Self-Proof
Cron daily 06:08 UTC via shared machinery under the themis login; runs shared machinery, which reads the sign-in proof record for this login and, for each slot its scheduled model droids serve, makes one liveness call as one of those droids only when no passing call was recorded in the last 20 hours (design 682 v1.3 part 6).
Thorin's Sign-in Self-Proof
Cron daily 06:09 UTC via shared machinery under the thorin login; runs shared machinery, which reads the sign-in proof record for this login and, for each slot its scheduled model droids serve, makes one liveness call as one of those droids only when no passing call was recorded in the last 20 hours (design 682 v1.3 part 6).
Tyr's Sign-in Self-Proof
Cron daily 06:10 UTC via shared machinery under the tyr login; runs shared machinery, which reads the sign-in proof record for this login and, for each slot its scheduled model droids serve, makes one liveness call as one of those droids only when no passing call was recorded in the last 20 hours (design 682 v1.3 part 6).
Var's Sign-in Self-Proof
Cron daily 06:11 UTC via shared machinery under the var login; runs shared machinery, which reads the sign-in proof record for this login and, for each slot its scheduled model droids serve, makes one liveness call as one of those droids only when no passing call was recorded in the last 20 hours (design 682 v1.3 part 6).
Vidar's Sign-in Self-Proof
Cron daily 06:12 UTC via shared machinery under the vidar login; runs shared machinery, which reads the sign-in proof record for this login and, for each slot its scheduled model droids serve, makes one liveness call as one of those droids only when no passing call was recorded in the last 20 hours (design 682 v1.3 part 6).
Operator Session OpenerDisk Retention Keeper
Cron hourly (:20) via shared machinery under Hagrid's login; logic in shared machinery and shared machinery; rules in shared machinery
Operator Communication MailerOperator Update Recorder
Run by an operator's own Orion session, under that operator's login, to record the session's hourly update into the Operator Instance Log: reads the operator from the calling login and root's authority record, the lines from standard input, and refuses by name any update the log's rules do not admit.
Albus Lane Watch
Cron every minute via shared machinery under Elrond's login; logic in shared machinery.
Contract End Watch
Raises a contract's end ahead of time and an internship's certificate due
Relevance Sweep
Cron daily 04:50 UTC via shared machinery under Elrond's login; logic in shared machinery, composer shared machinery.
Heimdall's Sign-in Watch
Cron daily 06:12 UTC via shared machinery under the heimdall login; reads the Logbook's session rows (read-only) with the sign-in bindings writes, the gate's landing time and logind's live login sessions, and reports per day: sessions, sign-ins, any sign-in that carried more than one Orion session, any session opened after the gate whose sign-in is unreadable (UNAUDITABLE). A finding is escalated to Orion's board through shared.alerts (high); a clean day reads checked with the count; a final JSON receipt on every exit.
Crawl-Readiness Reader
Cron daily via shared machinery under Loki's login; logic in shared machinery, run by shared machinery.
Receipt Reader
Cron daily via shared machinery under Carol's login; logic in shared machinery, run by shared machinery.
Service Operator Performer
Long-running Unix-socket door under Elrond's login (systemd unit carol-service-operator-performer.service); logic in shared machinery, started by shared machinery. The service operator's door (root's) hands it uat, scope and file.