clembot

the harness

Built for one agent system. Some of it travels.

Everything else on this site argues from this install's own record. This page looks sideways at the agent harness underneath it: what got built to make one agent system worth trusting, what was learned doing it, and which pieces are any use to somebody who does not have this vault.

Behind the headline: the diagram further down this page, seen edge on. 7 layers holding 31 components, with 10 of the 37 connections running back up into an earlier layer.

Statuses come from the project index on wanessalabs.com. They are not restated or reconciled here, because the projects pagealready audits the portfolio against the build and reports where the two disagree. A second hand-kept copy of that judgement would be one more thing to drift.

How it fits together

The lists further down say what exists. This says how a piece of work gets through it: seven layers, and the three paths that run. Every box cites a real file, and the export refuses to write when one of those paths stops existing. That catches a rename or a deletion. It does not catch a box whose description quietly stopped being true.

The dotted boxes are the ones that do not run. Four are a product document and no code, and the routines are written, registered and deliberately not started. They are in the diagram because leaving them out would draw a system more finished than the one that exists.

31 components, 37 connections

  • work moving
  • context loading in
  • can stop the work
  • the loop back
  • a model answering
Clemens: Types, or holds a key and talks.ClemensClembot-dictate: Voice to text at the cursor, local Whisper, nothing uploaded.Clembot-dictateDesire Queue: Raw ideas compiled into runnable prompts before anything executes.Desire QueueUnified Reader: Would tag RSS, mail and Slack into the inbox.Unified ReaderThe router: One file that says which project owns what, and which rules apply.The routerRules: Standing constraints. Some always load, some only when the work touches matching files.RulesHANDOFF.md: Where the last session stood, capped at 120 lines and verified before it is trusted.HANDOFF.mdMemory: Who the user is, how they work, what is already decided, who the people are.MemoryThe vault: A plain Obsidian directory, so a record is a file both sides can edit. This is one of its wikis.The vaultSubagents: Isolated context, restricted tools, enforced at runtime rather than by instruction.SubagentsSkills: Packaged procedures. An agent may only invoke the ones its row in the registry lists.SkillsCommands: Named entry points for the workflows that repeat.CommandsWorktrees: One feature, one branch, one isolated copy of the repo.WorktreesRoutines: Written, registered, and deliberately not running: automation waits on a delivery surface.RoutinesHooks: Run on save and on tool use. They report and refuse; they never quietly rewrite a draft.HooksSkill registry: A skill is Approved, Pending or Deprecated, and Pending means no agent may invoke it.Skill registryDoorman: The gate on outside tools: an allowlist that fails closed, and a grade from driving a server.DoormanThe human gate: Anything that leaves the system, or that is hard to undo, stops for a person first. Small scoped edits do not.The human gateHosted Claude: Architecture, judgement, anything with a client in it.Hosted ClaudeLocal lane, via Token Thrift: Mechanical drafting delegated to a local model that sends nothing off this machine. Anything touching a client is kept out of it by rule, and the rule is the only thing enforcing that.Local lane, viaToken ThriftLocal LLM adapter: Would point the whole harness at a local model, not just one lane.Local LLM adapterGit and Pages: Branch, commit, review, deploy. The deploy is a separate decision from the merge.Git and PagesThe platform: The multi-client marketing system: agents, approvals, publishing.The platformEvidence chain: Every action the platform's agents take, hash-chained into an append-only log, each record naming its parent.Evidence chainSlack: The pulse: what the agents are doing, as they do it.SlackNotion: The memory: structured records that outlive the channel they were announced in.NotionThis site: A read-only export, scanned three ways before it is written. No runtime, no API, no fetch.This site/session-end: Rewrites the handoff and the memory files, so the next session starts where this one stopped./session-endMemory with events: Would write memory when something happens, rather than at a manual close.Memory witheventsSelf-improvement: Would rank what is missing each week, before something gets built wrong.Self-improvementDoorman dashboard: A weekly letter grade for the harness itself, with the week-over-week difference.Doorman dashboard
01

Where work comes from

Three routes that work today: a person typing, the same person talking, and a queue that person filled earlier. The fourth is written up and carries nothing.

Clemens

Types, or holds a key and talks.

in usevault/CLAUDE.md

Clembot-dictate

Voice to text at the cursor, local Whisper, nothing uploaded.

in usevault/voice-transcriber

Desire Queue

Raw ideas compiled into runnable prompts before anything executes.

in usevault/queue/desires.md

Unified Reader

Would tag RSS, mail and Slack into the inbox.

A product document and no code. Nothing feeds the inbox this way yet.

not builtvault/rss-reader/prd.md

02

What loads before any work starts

The reason a session does not begin from nothing. All of it is markdown a person can read and edit.

The router

One file that says which project owns what, and which rules apply.

in usevault/CLAUDE.md

Rules

Standing constraints. Some always load, some only when the work touches matching files.

in use19vault/.claude/rules

HANDOFF.md

Where the last session stood, capped at 120 lines and verified before it is trusted.

in usevault/HANDOFF.md

Memory

Who the user is, how they work, what is already decided, who the people are.

in use5vault/memory

The vault

A plain Obsidian directory, so a record is a file both sides can edit. This is one of its wikis.

in usevault/meta-wiki

03

The session

One orchestrator thread that mostly delegates. Each subagent gets its own context and only the tools its definition lists.

Subagents

Isolated context, restricted tools, enforced at runtime rather than by instruction.

in use36vault/.claude/agents

Skills

Packaged procedures. An agent may only invoke the ones its row in the registry lists.

in use62vault/.claude/skills

Commands

Named entry points for the workflows that repeat.

in use51vault/.claude/commands

Worktrees

One feature, one branch, one isolated copy of the repo.

in usevault/.claude/rules/worktrees.md

Routines

Written, registered, and deliberately not running: automation waits on a delivery surface.

The registry says it plainly: live 0, scaffolded 36. The platform posts to Slack already; these are waiting on a surface of their own.

scaffolded36vault/routines/_pending

04

What stands in the way

The layer the rest of the site argues about. Each of these can stop work, and one of them stops it so a person can decide.

Hooks

Run on save and on tool use. They report and refuse; they never quietly rewrite a draft.

in use15vault/.claude/hooks

Skill registry

A skill is Approved, Pending or Deprecated, and Pending means no agent may invoke it.

in usevault/.claude/rules/security.md

Doorman

The gate on outside tools: an allowlist that fails closed, and a grade from driving a server.

in usevault/clembot-doorman

The human gate

Anything that leaves the system, or that is hard to undo, stops for a person first. Small scoped edits do not.

in usevault/.claude/rules/security.md

05

Which model runs it

Not everything needs the expensive model. Mechanical work goes to a local one that sends nothing off this machine, and judgment, including anything touching a client, stays with the hosted model.

Hosted Claude

Architecture, judgement, anything with a client in it.

in usevault/.claude/rules/stack-standards.md

Local lane, via Token Thrift

Mechanical drafting delegated to a local model that sends nothing off this machine. Anything touching a client is kept out of it by rule, and the rule is the only thing enforcing that.

alphavault/.claude/skills/token-thrift/SKILL.md

Local LLM adapter

Would point the whole harness at a local model, not just one lane.

This page lists it as production further down. It is a product document and no code. The local lane beside it is real, and is a skill rather than this project.

not builtvault/local-clembot-llm/prd.md

06

Where the work lands

Two destinations, plus this page. Code goes to a repository and a deploy; content goes through the platform, and is recorded on the way.

Git and Pages

Branch, commit, review, deploy. The deploy is a separate decision from the merge.

in usevault/.claude/rules/git-workflow.md

The platform

The multi-client marketing system: agents, approvals, publishing.

in useplatform/server

Evidence chain

Every action the platform's agents take, hash-chained into an append-only log, each record naming its parent.

in use38platform/outputs/evidence

Slack

The pulse: what the agents are doing, as they do it.

in useplatform/server/lib/messenger-slack.js

Notion

The memory: structured records that outlive the channel they were announced in.

alphaplatform/server/lib/notionClient.js

This site

A read-only export, scanned three ways before it is written. No runtime, no API, no fetch.

in usesite/scripts/site-feed.js

07

What comes back

The part a component list cannot show. Two of these run today, and both feed the next session rather than a report nobody reads.

/session-end

Rewrites the handoff and the memory files, so the next session starts where this one stopped.

in usevault/.claude/commands/session-end.md

Memory with events

Would write memory when something happens, rather than at a manual close.

A product document and no code. Today the close is manual, and that is the loop above.

not builtvault/memory-events/prd.md

Self-improvement

Would rank what is missing each week, before something gets built wrong.

A product document and no code.

not builtvault/self-improvement-module/prd.md

Doorman dashboard

A weekly letter grade for the harness itself, with the week-over-week difference.

in usevault/clembot-doorman/doorman/cli/dashboard.mjs

The three paths

A session

Work starts by loading what the last session wrote, and ends by writing for the next one.

  1. ClemensA request arrives, typed or spoken.
  2. HANDOFF.mdThe handoff and the memory files load first, then get verified against the repo.
  3. RulesRules load: the always-on ones, plus any matching the files being touched.
  4. SubagentsThe orchestrator delegates rather than doing the work itself.
  5. HooksHooks run on save, and report rather than rewrite.
  6. Git and PagesThe change lands on a branch, in its own worktree.
  7. /session-endThe close rewrites the handoff and memory.
  8. MemoryWhich is what the next session loads. This is the loop.

A post

The path content takes, and the two places it stops.

  1. Desire QueueA brief, compiled into a runnable prompt before anything executes.
  2. SubagentsResearch, then drafting, each in its own context.
  3. HooksNo draft leaves a writing agent without a voice pass.
  4. The human gateA person approves. Nothing reaches an outside surface before this.
  5. SlackPublished, and announced in the channel.
  6. Evidence chainAnd appended to the chain, which is what the proof page lets you recompute.
  7. This siteWhich is what this site exports, redacted, at build time.

A new tool

How something outside gets permission to run inside. This is the path Doorman exists for.

  1. Skill registryA candidate arrives, usually because Clemens saw it somewhere, and enters the registry as Pending. Pending means no agent may invoke it.
  2. DoormanDoorman measures it by driving it, rather than by reading what it claims about itself.
  3. The human gateA person decides on the verdict. Undeclared network access is an automatic decline, though nothing watches egress yet, so a person has to notice it first.
  4. SkillsOnly then is it Approved, and only for the agents whose row lists it.

the one built to leave

Doorman is a product, not a vault feature

Every tool below was built for this harness. Doorman is the one with a problem that is not ours: an agent loads anMCP server, the server describes itself, and the model reads that description as an instruction. Nothing in the protocol distinguishes a capability from a command. A server can ship an advertisement, a steering nudge, or an injection in the same field that tells your agent what it does, and your agent has no way to tell those apart.

That hole is in every harness, not this one. So doorman was built to be installed by someone else: a zero-dependency gate that fails closed, a trust list the tool's own updates cannot overwrite, and a grade produced by driving a server rather than by reading what it claims. Documentation describes what authors wish were true.

It caught a live server shipping a 6,290-character in-context advertisement. That is the whole argument for the category in one finding.

Open the doorman siteProject notes

portable

Useful without this vault

Clembot Doorman shipped

A gate on what an agent is allowed to reach, plus a trust grade for MCP servers that is measured by driving them rather than by reading their docs.

Every agent harness has this hole. A server describes its own tools to your model, and your model reads those descriptions as instructions.

Clembot-dictate shipped

Hold a key, speak, release, and the text lands at the cursor. Local Whisper, no subscription, nothing uploaded.

Input speed is the quiet tax on agent work. This one needs no vault at all.

Local LLM adapter production

One file that points the harness at a local Ollama instance instead of a hosted API.

Mechanical drafting runs free and offline. Client work is deliberately kept out of that lane and stays with the hosted model.

Token Thrift alpha

Measured 111 agent sessions to find where the tokens actually went, then built the layer the data justified.

The measurement is the transferable part. Most token advice is folklore with no denominator.

Gauntlet Loop shipped

Paired worker and critic agents polish a finished build against its own written brief. Bounded rounds, a human gate between each, isolated writers.

Critics with no brief optimise toward their own taste, so it refuses to run without one.

vault-bound

Only make sense with a vault underneath

These are the ones worth reading for the pattern rather than installing. Each solves a problem that only exists once an agent system has its own memory, its own project records and its own review loop.

Obsidian as the substrate in use

The vault is a plain Obsidian directory, so every project record, decision log and wiki page is a markdown file an agent can read and a human can edit in the same place. Five skills teach the agent that dialect: wikilinks, callouts, bases, canvases and diagrams.

The memory layer in use

Four durable files plus an index the agent loads every session: who the user is, how they work, what has already been decided, and who the people are. A consolidation pass prunes it, because memory that only grows stops being memory and becomes a transcript.

Design Hub production

A design reference library where every entry carries a rule an agent can follow, and becomes a prompt that applies it.

Vault Kanban production

A board that scans the vault itself and renders every project as a lifecycle card, reading each project’s own frontmatter rather than a second list to keep in sync.

Slack and Notion alpha

Three agents publish activity to three Slack channels and write structured records to three Notion databases. Slack is the pulse, Notion is the memory.

Memory with Events alpha

Memory that writes itself when something happens, rather than waiting for a manual session close.

Self-Improvement Module alpha

A weekly pass that scans for coverage gaps and surfaces ranked improvement candidates before something gets built wrong.

Unified Reader alpha

RSS, mail and Slack in one place, tagged and written straight into the inbox.

what it cost to learn

Four things that were not obvious

A control that is inert looks exactly like one that works

Both are quiet. A gate installed and not wired, a routinescheduled and never firing, a redaction rule that travelled without the code it guards: none of them announce anything. Every check here reportswired separately from installed for that reason.

Never grade documentation as proof

Docs describe what authors wish were true. The only claim worth acting on is one produced by running the thing, which is why doorman's grade comes from driving a server and why an unmeasured layer here reports as unmeasured rather than as zero.

Measure before building the fashionable layer

Token Thrift started as a plan to compress tool output. Measuring 111 sessions showed that was 2.8% of the spend. The layer that got built is the one the data justified, and the measurement is the part worth copying.

A number with no denominator is decoration

Every figure on this site names the file it came from and the date it was exported. Sections that could not be measured say so rather than rendering a confident zero, which is the failure mode this whole system was built to avoid.