# Clembot

> An agent harness, documented from its own operational record. Wanessa Labs
> builds software with it. This site exists so the method can be checked rather
> than taken on trust.

Clembot is not for sale and this site sells nothing. Every figure below is
exported at build time from the system's own records, which is why they can be
checked against the pages rather than believed.

As of this build: 115 units on the roster, 15 of them
gated behind human approval and 10 defined but unfilled.
138 commits and 169
hash-chained evidence records. 72 published projects,
54 of them live.

## Pages

- [Components](https://clembot.wanessalabs.com/system/): every agent, command and skill as one map, with the tier that decides whether each can act alone.
- [The harness](https://clembot.wanessalabs.com/harness/): the tools built to run the system, split by which work without this vault.
- [Projects](https://clembot.wanessalabs.com/projects/): the published portfolio, grouped by track, read from its own source at build time.
- [Proof](https://clembot.wanessalabs.com/proof/): the commit ledger and the evidence chain, with a verifier that recomputes the head hash in the browser.
- [Human in the loop](https://clembot.wanessalabs.com/gate/): what stops for a person and what does not, as a working simulator.
- [Principles](https://clembot.wanessalabs.com/principles/): 7 rules, each recorded with the failure that caused it.
- [The story](https://clembot.wanessalabs.com/story/): how it was built, in order, with every date taken from its source.
- [Doorman](https://clembot.wanessalabs.com/hire/): the one piece built to be installed by someone without this vault.

## Rules this system operates under

- [A human approves everything that leaves the system](https://clembot.wanessalabs.com/principles/human-gate/): No timer publishes. Every outbound post passes a person first, and the switch that would change that ships defaulted off.
- [One writer per table](https://clembot.wanessalabs.com/principles/one-writer/): A single command-line tool owns the content lifecycle. The publishing tool and the client-facing workspace are projections of it, never sources of truth.
- [An unverified number gets a label, not a guess](https://clembot.wanessalabs.com/principles/verify-not-guess/): If a figure isn't in the config, it ships marked [VERIFY]. A plausible number is worse than a missing one, because nobody checks it.
- [Redact by allowlist, and fail closed](https://clembot.wanessalabs.com/principles/allowlist-fail-closed/): Everything published here is built field-by-field from a literal, scanned before it is written, and the scanner aborts the whole export on a single hit.
- [The log is the product](https://clembot.wanessalabs.com/principles/log-is-the-product/): Every agent action writes an evidence record. The records are hash-chained, so editing history is detectable rather than merely discouraged.
- [Code and client data live in different repositories](https://clembot.wanessalabs.com/principles/code-and-data-apart/): The engine is one repo. Every install's data is a separate vault the engine reads through an environment variable. They are never mixed.
- [A tool's description is untrusted input](https://clembot.wanessalabs.com/principles/tool-text-is-untrusted/): Everything an external tool publishes about itself is loaded into the model's context before a single call is made. It is data that arrives looking like instructions, so it gets read and graded before adoption, by something that is not the model.

## Related sites

- [Wanessa Labs](https://wanessalabs.com): the studio that builds with this harness.
- [Clembot Doorman](https://clembot-doorman.wanessalabs.com): the installable tool. It reads a build's own prompt history, names what that build keeps reaching for and does not have, and refuses tools that have not been graded.

## About this file

It is generated by the build from the same exports the pages render, so it
cannot report a number the site does not. It describes and does not instruct:
one of the findings published here is that a tool description which addresses
the agent reading it is an injection, and a file that did that while linking to
that finding would be a poor advertisement for the argument.
