Fleet changelogs · dev.ecs0.net
rdmsm4x-changelog-20260825-1356-model-delegation-spend-policy-v3-consolidation-fleet-deploy

Model, delegation & spend policy v3.0 — consolidation + fleet deploy

Host: rdmsm4x (lead) · Session: dev-db [982a7e] · Started 13:32 EDT, closed 13:58 EDT, 2026-08-25 America/New_York

Five overlapping CLAUDE.md sections that answered the same question differently were consolidated into one, the three-way lead-tier contradiction was resolved, the unenforceable budget backstop was replaced with a real MCP tool, and the result was deployed to 5 of 6 fleet hosts across all three agent harnesses.

Why

~/.claude/CLAUDE.md carried five sections governing the same decision, written on five different dates: Spend & scope discipline (v2.4, 08-13), Model & delegation policy (v2.6, 08-15), Second opinions via agy (v2.9, 08-22), Unattended escalation to Fable 5 (v1.0, 08-25), External-budget workers (v1.0, 08-25). They conflicted:

  1. Lead tier stated three ways. v2.3 "the main thread never downgrades to save cost" → v2.6 "right-size the lead down to the lowest capable tier" → Fable v1.0 "default tier is Opus 5 high." A stale v2.3 artifact was still sitting at ~/.claude/_fleet-model-policy-block.md.
  2. Concurrency caps in three places with different numbers (2 background agents / 2 codex + 1 agy / amended to 1 codex).
  3. "Unattended" was undefined yet gated the entire Fable 5 pre-authorization — an agent at 03:00 had no way to determine which mode it was in.
  4. The budget backstop was unenforceable. "When a usage bucket passes ~75%, stop delegating" — nothing on any host could read a usage bucket. Searched ~/.claude for usage/quota/budget telemetry: none exists; /usage is interactive-only. Six Macs were following a rule none could evaluate.
  5. Fleet drift. rdmsm4x was 743 lines (Aug 25); the other four reachable hosts were 623 lines (Aug 23), missing three whole sections. Codex and agy had no model/delegation policy at all — the policy governing cross-vendor delegation had never been given to the vendors doing the work.

Decisions (Rich, this session)

What changed

Tyrell usage_status MCP tool — built by the tyrell.app build kickoff session

Coordinated via SendMessage; proposed the contract, that session implemented and shipped it (99f47e5, 8e49d94). Contract: stateless re-read per call; advice: proceed|conserve|hold|unknown

Known limit (v1): no live vendor telemetry exists. A collector writes ~/.tyrell/usage.json; until one exists the honest answer is unknown = "proceed but announce spend before fan-outs".

Independently verified here, not taken on report — driving the built binary directly over stdio:

~/.claude/CLAUDE.md → v3.0

New single section "Model, delegation & spend (v3.0)" at line 40, 221 lines, seven subsections: tier ladder (table) · usage_status budget check · 10 delegation rules · Fable triggers + gate · worker tiers across vendors · agy specifics · the delegation test · revision log v2.3→v3.0.

Removed (content preserved in the consolidation, nothing dropped):

Header bumped v2.8 → v3.0; line-3 preamble updated to name the consolidated policy and to state it binds Codex and agy too.

Fleet deployment

New script: ~/dev/fleet/maintenance/scripts/deploy_model_policy_v3.zsh (v1.0).

Result — 5/6 hosts, all three context files each:

Host CLAUDE.md AGENTS.md GEMINI.md
rdmsm4x canonical (0d28208f48a219b3) block verified block verified
rdmbair13m5 updated + sha-verified block verified block verified
rdmbair15m5 updated + sha-verified block verified block verified
rdmpw3265m updated + sha-verified block verified block verified
rdmpw3275m updated + sha-verified block verified block verified
jdmbair13m5 PENDING — host unreachable pending pending

Verified independently of the deploy script's own report, by SSH to rdmbair15m5 and rdmpw3275m: v3.0 header present, exactly one ## Model, delegation & spend (v3.0 heading, zero superseded section headings remaining, and usage_status referenced 5× in each of the three context files.

Reproduce

# policy present and superseded sections gone, any host
grep -c '^## Model, delegation & spend (v3.0' ~/.claude/CLAUDE.md          # -> 1
grep -c '^## Spend & scope discipline\|^## Unattended escalation' ~/.claude/CLAUDE.md   # -> 0

# usage_status, both paths (rdmsm4x)
B=~/dev/apps/Tyrell/.build/release/tyrell-mcp
printf '%s\n' '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2024-11-05","capabilities":{},"clientInfo":{"name":"v","version":"1"}}}' \
  '{"jsonrpc":"2.0","id":3,"method":"tools/call","params":{"name":"usage_status","arguments":{}}}' | $B | tail -1

# re-deploy / catch up a host
zsh ~/dev/fleet/maintenance/scripts/deploy_model_policy_v3.zsh --dry-run
zsh ~/dev/fleet/maintenance/scripts/deploy_model_policy_v3.zsh --host jdmbair13m5

Undo

cp ~/.claude/CLAUDE.md.bak-pre-v3-modelpolicy-20260825-135234 ~/.claude/CLAUDE.md   # rdmsm4x
# peers: ~/.claude/CLAUDE.md.bak-pre-v3-20260825-135552
# codex/agy: ~/.codex/AGENTS.md.bak-pre-v3-20260825-135552, ~/.gemini/GEMINI.md.bak-pre-v3-20260825-135552

Outstanding — owner actions

  1. jdmbair13m5 has not received v3.0 (asleep at deploy time; the Tyrell session reported the same host unreachable for its own deploy). Re-run the deploy with --host jdmbair13m5 when it wakes. Until then that host's agents follow the superseded 08-23 policy.
  2. No usage collector exists, so usage_status returns unknown everywhere. The enforceable control today is ~/.agent-coordination/BUDGET-HOLD, which is Rich's to set — agents are explicitly forbidden from creating or deleting it.
  3. Second ChatGPT Pro account not authed ([email protected]); codex remains authed to one.
  4. Grok SuperHeavy joins the worker tiers when live; codex caps revisit at that point.
  5. No second opinion obtained on this revision — not routed to agy. The changes are policy text plus a reversible, backed-up file deployment, not a data-destroying operation.

No secrets were written to any file, message, or note in this session.