Factory docs, home
Page navigation

What it does for you: It keeps a durable record of who owns each Run and Attempt, and how each Attempt ended. A retry, a crash or a late report cannot create two owners or override a cancellation. Like a relay, the baton passes only when the last runner reports in, or a trusted supervisor confirms that leg ended or was fenced off.

Module studies, plate 1: six Plumb studies for the records-and-runs modules, each labelled with its module's name.

Plate 1, position 3, Plumb with the baton: a relay baton. The plate is shown whole.

How it links: Takes Run submissions, claims, reports and cancellations from Guarded verification / recovery · Records every step in the Command journal · Names the Run and Attempt that the Attempt fence / workspace and Evidence / Assurance pin to.

Honest limits:

  • A completed Run means the Recipe ran to its end, not that the Candidate passed. Only Assurance gives a Verdict.
  • It starts, stops and times nothing. A cancel request does not stop work: a stuck Attempt stays running until a trusted supervisor confirms its work ended or was fenced off, which is not proof that its process exited. A Run may use at most 20 Attempts.
  • Callers are trusted local code. Crash tests killed processes; survival after power loss is not tested.

Status: Accepted for trusted local supervision (local review, 28 September 2026). Local development only, not a release; all 27 epics remain open.

Agent reference →

Source: docs/guide/execution.md