Codex Accountable Agent Workflow

This Codex-only convention defines a risk-based accountability lifecycle for planning, implementation, independent review, and delivery. It supplements the shared quality gate without changing Claude workflows.

Roles and lifecycle

The order is: Sol plan → optional Luna assignments → Sol inspection and integration → integrated verification → fresh Terra audit → Sol disposition and remediation → required focused Terra re-audit → final Sol acceptance → shipping.

Trivial typo, formatting-only, narrow text, and task-checkbox changes stay on the existing single-owner path. A workflow-policy or executable-contract change is non-trivial even when it is text in a skill or convention.

Model routing truthfulness

Sol records requested model and resolved model for Sol, every Luna assignment, and Terra. Model names request role separation; they do not prove runtime routing. If the runtime cannot select or report an exact model, record resolved model: unavailable, preserve the role's ownership and independence constraints, and disclose the fallback in the final report. Never claim an unverified model identity.

Accountability topology

Planning records an Accountability topology independently of the execution profile:

The topology does not replace serial, research-only, review-only, implementation-safe, or agent-team. implementation-safe Luna lanes share a worktree only with disjoint paths. agent-team Luna lanes use isolated non-primary branches and consolidation/PR review. Reject, merge, or serialize any overlapping write ownership before dispatch.

Luna assignment contract

Every Luna lane must be decision-complete before dispatch:

Task docs, shared manifests, lockfiles, migrations, generated artifacts, integration, conflict resolution, commits, pushes, and deployment remain Sol-owned unless the plan explicitly grants one lane exclusive ownership of a normally shared artifact. Sol must not assign overlapping paths to multiple write lanes.

Each Luna return report includes: lane identifier, status, changed paths, diff/commit evidence, acceptance-criteria mapping, verification commands and results, assumptions or deviations, unresolved risks, and requested/resolved model identity. A return is evidence, not acceptance: Sol reads the actual diff and surrounding code before integrating it.

Terra audit contract

Terra starts only after integrated verification and receives the final integrated diff plus relevant surrounding code, plans, specifications, and verification evidence. Terra must be a fresh review context that did not implement or integrate the reviewed change.

In delegated mode, invoke $expert-review --adversarial-diff --read-only. Before launch, Sol captures any prompt-history or delegation record required by the repository. Terra must not modify repository files, task documents, prompt history, alignment pages, indexes, branches, commits, refs, or external state; read-only mode overrides all write-producing skill and repository conventions for the delegated invocation.

Every non-stylistic finding has a stable identifier and these fields:

Terra reports no findings explicitly when appropriate. Style-only observations may be omitted and cannot block shipping.

Sol disposition and remediation

Sol records exactly one disposition for every Terra finding:

After remediation, Sol reruns relevant integrated verification. A fresh focused Terra re-audit is mandatory when the remediation affects security, authentication, billing, persistence, migrations, concurrency, privacy, data loss, or broad cross-package contracts. The focused audit is also read-only and must verify the finding, fix, and adjacent regression risk.

Shipping gate

Sol refuses shipping when any of these is true:

Issue-backed non-primary delivery and branch-isolated agent-team rules remain governed by the repository's shipping contract. Sol is always the final integration and delivery owner.

Final accountability report

The ship manifest and terminal report include: