From 3eb3bc3052be2b25de8fe2320231bab00b0a4261 Mon Sep 17 00:00:00 2001 From: Jer Miller Date: Sun, 26 Jul 2026 10:52:20 -0600 Subject: [PATCH] fix(cogitate): apply approved journal families to every sol-enabled tier The access-tier table attached approved direct `journal` families to `synthesis` only, while policy and the shared runtime preamble apply them to every sol-enabled cogitate run. Restate the surface uniformly for `normal`, `system-read`, and `outbound` (`diagnostic` has no `sol` tool and is unchanged), and correct the now-inaccurate `cogitate_sol_tool_hint` docstring. --- docs/COGITATE.md | 6 +++--- solstone/think/providers/cli.py | 2 +- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/docs/COGITATE.md b/docs/COGITATE.md index 41abf1084..a51ca1105 100644 --- a/docs/COGITATE.md +++ b/docs/COGITATE.md @@ -127,9 +127,9 @@ enforcement are layered on top of it. | Tier | Purpose | Surface | |---|---|---| -| `normal` | default cogitate talents | the `sol` tool (`sol` / `sol call`), the bounded raw-read tier, a finalization tool | -| `system-read` | diagnostics boundary for scoped operational evidence | no cogitate talent claims it today (steward was demoted to a deterministic renderer + `lite` generate); the tier remains the declared diagnostics boundary and extension point, with scoped evidence arriving through a talent pre-hook rather than an extra model read tool | -| `outbound` | comms-like talents that may submit something that leaves the machine (e.g. `support`) | the `sol` tool (`sol` / `sol call`) and a finalization tool, plus submit-capable support commands gated on per-send owner approval supplied only by a human-initiated chat launch; no raw-read tier — drafts and evidence go through `sol` domain commands | +| `normal` | default cogitate talents | the `sol` tool (`sol` / `sol call`, plus approved direct `journal` families when a prompt names one), the bounded raw-read tier, a finalization tool | +| `system-read` | diagnostics boundary for scoped operational evidence | no cogitate talent claims it today (steward was demoted to a deterministic renderer + `lite` generate); when used, the declared surface is the `sol` tool (`sol` / `sol call`, plus approved direct `journal` families when a prompt names one), the bounded raw-read tier, and a finalization tool, with scoped evidence arriving through a talent pre-hook rather than an extra model read tool | +| `outbound` | comms-like talents that may submit something that leaves the machine (e.g. `support`) | the `sol` tool (`sol` / `sol call`, plus approved direct `journal` families when a prompt names one) and a finalization tool, plus submit-capable support commands gated on per-send owner approval supplied only by a human-initiated chat launch; no raw-read tier — drafts and evidence go through `sol` domain commands | | `synthesis` | pure command-surface synthesis talents (e.g. `weekly_reflection`, `partner`) whose source of record is a documented command form, not the raw journal tree | the `sol` tool (`sol` / `sol call`, plus approved direct `journal` families when a prompt names one) and a finalization tool; **no raw-read tier and no submit** — same as `outbound` minus the outbound submit capability. Removing the raw-read tools keeps a synthesis talent from spelunking `chronicle/` / `talents/` / `facets/` and burning its budget instead of using documented commands | Policy denies support send verbs (`create`, `reply`, `attach`, `feedback`) for diff --git a/solstone/think/providers/cli.py b/solstone/think/providers/cli.py index ef4217c60..0d3d86599 100644 --- a/solstone/think/providers/cli.py +++ b/solstone/think/providers/cli.py @@ -87,7 +87,7 @@ async def _drain_line(stream: asyncio.StreamReader) -> None: def cogitate_sol_tool_hint(tool_name: str) -> str: - """Return the shell-tool hint for non-write cogitate runs.""" + """Return the model-visible command-routing hint for the provider tool.""" return ( "When the instructions tell you to run `sol ...` or approved " f"`journal ...` commands, invoke them through the `{tool_name}` tool. " -- 2.51.2