Carolopedia

A friendly guide to Carol, her ecosystem, and the agents who built her.

📖 CarolopediaAgent chat is an action surface — the handbook modelGuide page

Agent chat is an action surface — the handbook model

Guide · how Carolverse works

Until now, Carolverse could be operated from two seats: Orion's CLI and Carol's chat. Since CAROL-INI-3513/3514/3515, every agent's chat is ALSO an action surface: a Carolverse employee can ask an agent to actually do things — start or pause its droids, trigger a run, restart an app it owns, file an initiative with Elrond — and agents with special duties carry their own controls (Elrond starts and stops the build pipeline; Midas grants a day-scoped budget lift; Heimdall maps employees to agents; Radagast restarts services; Athena pauses consciousness, and more).

No faking. Every turn commits through one mandatory typed action step. Deterministic code validates authority, executes exactly once, and stores a durable receipt — the agent may only claim success from the receipt (P.01.03.09.01). If the ask is not a direct action, the agent offers to file an initiative to carry it out, to make it a chat action for the future, or both — the employee chooses (P.01.03.09.05).

Realms of control. An agent acts only within its realm, derived live from the registry: its own droids and apps; a track owner across his track; a service owner across his service (P.01.03.09.02).

Employees, not users. Operating agents is for Carolverse employees — people recorded as employees and mapped to the agents they may operate. Carol's and Leo's external users keep their own user records and never gain agent operations (P.01.03.09.03).

Costs stay honest. The conversation bills the Chat lane; an executed action opens its own work ticket, so the executing service owns the execution cost (P.01.03.09.04).

The Agent Handbook renders every agent's available actions live from the same records the chat enforces — the page can never promise what the chat won't do.