Safety
The owner
The owner is a terminal outside herdr with no agent process above it: a seat, or a script a seat
runs, cannot approve a file or start a team. Every command that reads the file also takes
--file <path> for a file other than .agents/team.yaml.
The owner, from a terminal outside herdr. --dry-run is open to anyone: it reaches nothing and
changes nothing, prints the refusals it would hit as ! up would refuse: … above the plan, and
exits 0.
The approved copy
team init keeps .agents/team.yaml out of git through .git/info/exclude, never by editing
.gitignore: a public repository shouldn't carry its roster. A fresh clone therefore has no team
file. Run team init to write one, or team init --restore to bring back the copy you last
approved on this machine. A file you receive from someone else runs nothing until you approve it
yourself.
What an approval covers
What needs a new approval is a change to an owner section (trust, limits, machine, rules, identity, workspace, coordinator, operator, session, visibility, tools, budgets, watch — its timings included, down to watch.checks, whose turn-offs are their own line) or to a seat's own fields.
Until an edit is approved its section changes nothing: the watch, the budget reports, the check cadence, up's and add's launch gate and status's table run with the approved values, or with the defaults when nothing was approved.
Trust is left to the owner
The lobby is a folder no CLI has seen before, and up reads a trust question and never answers one:
the first up in worktree mode leaves each implementer out with <seat>: left out: trust question —
its workspace closed without input, nothing run — until the owner trusts the lobby once in that CLI,
as they trusted the worktrees. Then it starts.
What team never does
- Nothing writes a vendor config or an
AGENTS.md. - It never answers prompts and performs no sign-in action.
- A file you receive from someone else runs nothing until you approve it yourself.
upanddowntake--dry-runto print every command they would run, and every refusal, and change nothing.
Launching a Cursor seat, like launching cursor-agent by hand, creates Cursor's own project record under ~/.cursor/projects for that folder; team writes no trust (.workspace-trusted) and no Cursor config.
team's screen hatch is a code module a CLI profile may name — inside the package's own profiles folder, nowhere else. A screen hatch is an escape hatch for a CLI whose screens the data primitives cannot express. A hatch can only add caution, never remove it, and no shipped profile uses one. The guarantees cover what a hatch returns and what load accepts; a hatch is trusted package code, not a sandbox.
Who may run what
| Command | Who may run it |
|---|---|
team init | the owner |
team approve | the owner (--show: anyone) |
team check | anyone; read only |
team doctor | anyone; read only |
team status | anyone; read only |
team up | the owner |
team down | the owner, the coordinator or the operator seat |
team watch | anyone, one per session; it types only its fixed nudge, into an empty idle prompt |
team add | the owner, the coordinator or the operator |
team remove | the owner, the coordinator or the operator; only the owner removes the coordinator or the operator |
team worktree | the owner, the coordinator or the operator |
What this version builds
Status: 0.1, early: herdr only; trust is specified, not built yet. This build parses and
validates the file, checks who is calling, and holds add, approve, check, doctor, down,
init, remove, status, up, watch and worktree.
team up, team down, team add, team remove, team worktree new and team worktree remove
run live. up and down take --dry-run to print every command they would run, and every
refusal, and change nothing. trust is specified but not built yet.