Issue #50 · Static architecture specimen
Foreman owns the work.
The Fabric grants the route.
The host runs the sandbox.
One product surface spans ChatGPT, the browser companion, the Greenways Fabric, and an enrolled execution host without passing credentials through or turning Foreman into a shell.
01 · Client capability
Observed tools, not assumed authority.
A subscription label or successful login never determines what the client can do. Foreman shows the actual advertised tool class and then applies Greenways authority independently.
- Observed
- read/fetch
- Tool classes
- observe
- Action state
- unavailable
The client may inspect Foreman but cannot be presented as having durable action authority.
- Observed
- read and action
- Tool classes
- observe · act · external-effect
- Action state
- gated
Client support does not bypass Greenways grants, human approval, or external read-back.
- Observed
- application operations
- Tool classes
- observe · act · external-effect
- Action state
- gated
The directly enrolled surface uses the same Foreman operations through the selected Fabric authority.
Current reference specimen: ChatGPT Pro custom MCP is presented as an Observe-only connection. The design does not disguise a durable action as fetch.
02 · Foreman tool surface
One application catalogue across every delivery surface.
The installed Foreman package owns these names and schemas. Desktop, CLI, browser companion, and MCP clients consume the same application operations through different capability profiles.
Observe
Read current Foreman projections and exact evidence without creating durable work or an external effect.
- List projectsprojection freshness and project identity
foreman.projects.list - Inspect projectproject revision and canonical external references
foreman.project.get - List buildoutsprojection freshness and evidence summary
foreman.buildouts.list - Inspect buildoutbuildout revision and causal evidence
foreman.buildout.get - Inspect work itemwork revision and run references
foreman.work.get - List sessionslast observation and native reference
foreman.sessions.list - Inspect sessionlast heartbeat and provider evidence
foreman.session.get - List approvalsscope, expiry, decision, and authority evidence
foreman.approvals.list - Inspect approvaldecision record and affected transition
foreman.approval.get - List execution choiceshost generation and advertised capability manifest
foreman.execution.hosts.list - Inspect execution runrun generation, checkpoint chain, and cleanup evidence
foreman.execution.run.get - Read activityevent identity, actor, source, and observation time
foreman.activity.list - Read artifactdigest, producer run, availability, and retention state
foreman.artifact.get
Act
Request one bounded Foreman transition through the current Fabric authority.
- Create buildoutcreated buildout identity and accepted revision
foreman.buildout.create - Submit workaccepted request, run identity, and durable activity
foreman.work.submit - Cancel workcancellation owner, time, and downstream state
foreman.work.cancel - Attach sessionsession/run binding and lease expiry
foreman.session.attach - Request sandbox leaselease identity, grant intersection, host generation, and expiry
foreman.execution.lease.request - Revoke sandbox leaserevocation actor, time, and affected run state
foreman.execution.lease.revoke - Cancel execution runcancel result, retained checkpoints, and cleanup status
foreman.execution.run.cancel - Decide approvaldecision record, actor, exact scope, and expiry
foreman.approval.decide - Capture selected outputartifact identity, digest, and source completeness
foreman.output.capture
External effect
Request one separately authorised mutation in GitHub or another external authority.
- Request external effectsubmitted or uncertain state plus eventual canonical read-back
foreman.external-effect.request - Inspect external effectexternal identity, last read-back, and verification state
foreman.external-effect.get
04 · Browser consent
Approve the exact sandbox, not a machine.
Scope, shared data, host, network, expiry, and excluded authority remain adjacent to the human decision.
Cross-runtime conformance
- Origin context
- Attached ChatGPT Pro session
- Requested by
- Chris through Foreman companion
- Project / buildout
- Hara · #838 · direct callable catalogue
- Host
- Mac Studio
- Capabilities
- exact checkout · apply candidate patch in sandbox · run bounded tests · return logs and artifacts · clean workspace
- Network
- GitHub and locked package mirrors
- Expiry
- 45 minutes
- Not included
- host home directory · browser cookies · provider credentials · SSH agent · GitHub push · merge · deployment · publication
05 · Execution choices and run
The host is selected; the Work run remains canonical.
Foreman presents user choices and evidence. Provider implementation stays expanded or diagnostic, and no host receives independent GitHub authority.
Mac Studio
Isolated project sandbox
- Capabilities
- exact repository checkout · bounded candidate evaluation · Hara/Rust/JVM/Node tests · artifact return · cleanup
- Bounds
- 8 vCPU · 12 GiB memory · 45 minute lease
- Network
- GitHub and locked package mirrors
- Observed
Expanded implementation
container provider. This is not the normal product label.
Cloud worker
Ephemeral clean-room runner
- Capabilities
- exact repository checkout · bounded candidate evaluation · test execution · artifact return
- Bounds
- 4 vCPU · 8 GiB memory · 30 minute lease
- Network
- No network after setup
- Observed
Expanded implementation
remote sandbox provider. This is not the normal product label.
MacBook
Local development host
- Capabilities
- repository inspection · bounded test execution
- Bounds
- battery policy active · no new long runs
- Network
- GitHub only
- Observed
Expanded implementation
local process provider. This is not the normal product label.
Exact revision → tests → artifact → cleanup
- Requested
Foreman recorded the exact work, host profile, inputs, limits, and idempotency key.
- Approval required
The browser companion shows shared data, capability scope, network policy, exclusions, and expiry.
- Lease granted
The Fabric recorded the authority intersection and one request-bound host generation.
- Allocating
The host is materialising an exact repository revision into an isolated workspace.
- Running
Canonical Work is executing through the selected host/store/executor path.
- Checkpointed
Bounded progress, logs, and artifact references are durable without claiming completion.
- Completed
The declared sandbox outcome has exact result evidence; no external GitHub effect is implied.
- Cleaned
The host returned attributable cleanup evidence for the leased workspace.
Difficult outcomes remain first-class.
- Host unavailable
Keep the selected host and last observation visible; do not silently reroute.
- Partial result
Retain completed checkpoints and name missing output.
- Run failed
Show failure stage, retained evidence, and whether cleanup is complete.
- Cancelled
Show actor, cancellation time, retained output, and cleanup state.
- Cleanup uncertain
The host disappeared before cleanup evidence; keep recovery action explicit.
06 · Product laws
The interface makes the architecture enforceable.
- 01
The installed Foreman package owns tool names and schemas; MCP only transports and advertises them.
- 02
Tool availability comes from actual client and Fabric grants, never a subscription label, provider login, or online route.
- 03
MCP, browser, provider, and execution-host credentials terminate at their own boundaries and are never passed through.
- 04
Foreman requests semantic work operations and never exposes an unrestricted shell, Docker API, filesystem root, database, or native handle.
- 05
The browser companion is the consent and revocation control plane; the Fabric may establish a direct bounded data plane to the host.
- 06
A sandbox lease is bound to one actor, app, project, buildout, work item, run, capability set, host generation, and expiry.
- 07
Sandboxes start without unrelated host files, browser cookies, provider credentials, keychains, SSH agents, or ambient cloud credentials.
- 08
A completed sandbox run or local commit does not prove a GitHub or deployment effect; authoritative read-back remains required.
- 09
Desktop, CLI, browser, and local sandbox operation remain useful when hosted MCP is unavailable.