Safety

The owner

The owner is a terminal outside herdr with no agent process above it: a seat, or a script a seat runs, cannot approve a file or start a team. With no --file, the file is .agents/team.yaml of the repository's main checkout, found through git's common directory. A folder that is not a git repository is read from .agents/team.yaml in that folder only, not from a parent, and a link at .agents or at the file is not followed. Every command that reads the file also takes --file <path> for a file other than .agents/team.yaml.

The owner, from a terminal outside herdr — or without one: a run whose stdin is not a terminal launches seats like any other, but never reads stdin and never prompts, so every dialog is left for the owner (below). --dry-run is open to anyone: it reaches nothing and changes nothing, prints the refusals it would hit as ! up would refuse: … above the plan, and exits 0.

The approved copy

team init keeps .agents/team.yaml out of git through .git/info/exclude, never by editing .gitignore: a public repository shouldn't carry its roster. A fresh clone therefore has no team file. Run team init to write one, or team init --restore to bring back the copy you last approved on this machine. A file you receive from someone else runs nothing until you approve it yourself.

What an approval covers

What needs a new approval is a change to an owner section (trust, limits, machine, rules, identity, workspace, coordinator, operator, session, visibility, tools, budgets, watch — its timings included, down to watch.checks, whose turn-offs are their own line) or to a seat's own fields.

Until an edit is approved its section changes nothing: the watch, the budget reports, the check cadence, up's and add's launch gate and status's table run with the approved values, or with the defaults when nothing was approved.

Trust is left to the owner

The lobby is a folder no CLI has seen before, and up reads a trust question and never answers one: a seat that stops there waits for its owner — at a terminal up keeps the seat's workspace, records it waiting and asks with one prompt (below); a run without a terminal closes the workspace without an answer and records <seat>: left out: trust (no terminal for owner). Nothing is run until the owner trusts the lobby once in that CLI. Then it starts.

What team never does

  • Nothing writes a lab's config or an AGENTS.md.
  • It never answers prompts and performs no sign-in action.
  • A file you receive from someone else runs nothing until you approve it yourself.
  • up, down and add take --dry-run to print every command they would run, and every refusal, and change nothing.

Launching a Cursor seat, like launching cursor-agent by hand, creates Cursor's own project record under ~/.cursor/projects for that folder; team writes no trust (.workspace-trusted) and no Cursor config.

team's screen hatch is a code module a CLI profile may name — inside the package's own profiles folder, nowhere else. A screen hatch is an escape hatch for a CLI whose screens the data primitives cannot express. A hatch can only add caution, never remove it, and no shipped profile uses one. The guarantees cover what a hatch returns and what load accepts; a hatch is trusted package code, not a sandbox.

Who may run what

Who may run each command
CommandWho may run it
team initthe owner
team approvethe owner (--show: anyone)
team checkanyone; read only
team doctoranyone; read only
team statusanyone; read only
team upthe owner
team downthe owner, the coordinator or the operator seat
team watchanyone, one per session; it types only its fixed nudge, into an empty idle prompt
team addthe owner, the coordinator or the operator
team answerthe owner, or the coordinator from its own seat
team releaseanyone; read only
team removethe owner, the coordinator or the operator; only the owner removes the coordinator or the operator
team worktreethe owner, the coordinator or the operator

What this version builds

Status: early, herdr only. This build parses and validates the file, checks who is calling, and holds add, answer, approve, check, doctor, down, init, release, remove, status, up, watch and worktree.

team up, team down, team add, team remove, team worktree new and team worktree remove run live. up, down and add take --dry-run to print every command they would run, and every refusal, and change nothing.