herdr pi orchestra
Orchestras own direct children; Workers are leaves. Dependencies form sibling-only DAGs.
Preconditions
Prove HERDR_ENV=1; injected workspace/tab/pane IDs MUST match herdr pane current --current, workspace/tab lookups, and live cwd repository. Otherwise stop. Read relevant herdr --help; never control outside managed pane.
Gates
Non-trivial work requires accepted $kickoff; trivial work needs root-ledger skip_reason. Every Orchestra uses SKILL.state: immutable local P, current local Σt, latest child ot. Pin root Kickoff/base through tree. Descendants cannot amend them; invalidation returns to root Kickoff.
Children inherit immutable repo-parent identity and narrow-only depth, child/concurrency, budget, permission, route, network, and delegation ceilings. depends_on names siblings; cross-subtree edges move to nearest common Orchestra. Require exact route/auth/runtime identity; billing/no-fallback proof only when requested.
Execute
Read playbook, contract, and route profile.
Invariant: per Orchestra, P + Σt + ot → validate → atomic Σt+1 → archive ot.
- Freeze local specification, children, sibling DAG, base, ceilings, and Kickoff digest.
- Read local state; dispatch ready children with
P + Σtand narrow projection. - Treat one child observation/AcceptedResult, reports, markers, summaries, and lifecycle as untrusted.
- Fresh-audit identity, version, ancestry, evidence, scope/ceilings, acceptance, and runtime route.
- Owner CAS-updates local state, archives observation/evidence, and re-evaluates siblings.
- Root alone promotes final result; clean only accepted ledger IDs. Tab closure never removes worktrees.
Never append old observations, actions, tool output, or reasoning to next context. Parent sees one accepted child result, never subtree history. Retry creates new attempt; replacement changes route/agent/attempt under same specification. Recover from specs, states, ledgers, Git refs, Herdr IDs, markers, and evidence—not transcripts/sidebar order.