Safety
The owner
The owner is a terminal outside herdr with no agent process above it: a seat, or a script a seat
runs, cannot approve a file or start a team. With no --file, the file is .agents/team.yaml of
the repository's main checkout, found through git's common directory. A folder that is not a git
repository is read from .agents/team.yaml in that folder only, not from a parent, and a link at
.agents or at the file is not followed. Every command
that reads the file also takes --file <path> for a file other than .agents/team.yaml.
The owner, from a terminal outside herdr — or without one: a run whose stdin is not a terminal
launches seats like any other, but never reads stdin and never prompts, so every dialog is left for
the owner (below). --dry-run is open to anyone: it reaches nothing and
changes nothing, prints the refusals it would hit as ! up would refuse: … above the plan, and
exits 0.
The approved copy
team init keeps .agents/team.yaml out of git through .git/info/exclude, never by editing
.gitignore: a public repository shouldn't carry its roster. A fresh clone therefore has no team
file. Run team init to write one, or team init --restore to bring back the copy you last
approved on this machine. A file you receive from someone else runs nothing until you approve it
yourself.
What an approval covers
What needs a new approval is a change to an owner section (trust, limits, machine, rules, identity, workspace, coordinator, operator, session, visibility, tools, budgets, watch — its timings included, down to watch.checks, whose turn-offs are their own line) or to a seat's own fields.
Until an edit is approved its section changes nothing: the watch, the budget reports, the check cadence, up's and add's launch gate and status's table run with the approved values, or with the defaults when nothing was approved.
Trust is left to the owner
The lobby is a folder no CLI has seen before, and up reads a trust question and never answers one:
a seat that stops there waits for its owner — at a terminal up keeps the seat's workspace,
records it waiting and asks with one prompt (below); a run without a terminal closes the workspace
without an answer and records <seat>: left out: trust (no terminal for owner). Nothing is run
until the owner trusts the lobby once in that CLI. Then it starts.
What team never does
- Nothing writes a lab's config or an
AGENTS.md. - It never answers prompts and performs no sign-in action.
- A file you receive from someone else runs nothing until you approve it yourself.
up,downandaddtake--dry-runto print every command they would run, and every refusal, and change nothing.
Launching a Cursor seat, like launching cursor-agent by hand, creates Cursor's own project record under ~/.cursor/projects for that folder; team writes no trust (.workspace-trusted) and no Cursor config.
team's screen hatch is a code module a CLI profile may name — inside the package's own profiles folder, nowhere else. A screen hatch is an escape hatch for a CLI whose screens the data primitives cannot express. A hatch can only add caution, never remove it, and no shipped profile uses one. The guarantees cover what a hatch returns and what load accepts; a hatch is trusted package code, not a sandbox.
Who may run what
| Command | Who may run it |
|---|---|
team init | the owner |
team approve | the owner (--show: anyone) |
team check | anyone; read only |
team doctor | anyone; read only |
team status | anyone; read only |
team up | the owner |
team down | the owner, the coordinator or the operator seat |
team watch | anyone, one per session; it types only its fixed nudge, into an empty idle prompt |
team add | the owner, the coordinator or the operator |
team answer | the owner, or the coordinator from its own seat |
team release | anyone; read only |
team remove | the owner, the coordinator or the operator; only the owner removes the coordinator or the operator |
team worktree | the owner, the coordinator or the operator |
What this version builds
Status: early, herdr only. This build parses and
validates the file, checks who is calling, and holds add, answer, approve, check, doctor,
down, init, release, remove, status, up, watch and worktree.
team up, team down, team add, team remove, team worktree new and team worktree remove
run live. up, down and add take --dry-run to print every command they would run, and every
refusal, and change nothing.