Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
20 changes: 20 additions & 0 deletions docs/architecture/rfcs/app-conversation-and-async-inbox-v0.md
Original file line number Diff line number Diff line change
Expand Up @@ -28,6 +28,26 @@ Five questions organize the experience: is my request still here; who is actuall
working; did my correction or stop take effect; where is the checked result; and
how do I come back after failure without starting the work again?

### Realtime Bot entry and recipient purpose

A native Bot replacement is another entry to this conversation lifecycle. Its
realtime connection is independent of periodic Goal work. Entry and recipient
purpose are separate: ordinary project chat, direct conversation with an existing
Agent, and the persistent steward share mechanics but have different objectives
and grants. The [steward operational contract](capable-manager-semantic-handoff-v0.md#10-operational-contract)
orders transport isolation, ordinary DM/role choice, progress/media/permissions
and installed replacement qualification under S5.

Ordinary project chat needs a shared Core conversation context whose workspace,
executor and audience are explicitly authorized, without a user-created Goal or
an automatic global-steward objective. This is a remaining entry requirement,
not a new shipped Session schema. Lark must not implement it by creating hidden
Goals, copying another host's sessions, or introducing an independent executor.
Explicit recipient selection uses permitted stable references; labels do not
confer grants. Switching the selected recipient affects future input, while
accepted work and returns retain their original Session, source and audience.
Stop targets the exact current request rather than every Agent behind a Bot.

### Managed and attached are different execution relationships

| Relationship | App promise | Required evidence and limit |
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,20 @@ Goal/Todo、lease、quota、验收和 effect 各自保留原有权限归属。
体验围绕五个问题组织:请求还在吗;谁确实在工作;纠偏或停止生效了吗;
核验过的结果在哪里;失败后如何回来且不重新启动工作?

### 实时 Bot 入口与接收者职责

原生 Bot 替换是这套对话生命周期的另一个入口,实时连接独立于 Goal 周期工作。
入口与接收者职责分开:普通项目对话、与既有 Agent 直接交流、持久管家共享机制,
但目标与授权不同。[管家运行契约](capable-manager-semantic-handoff-v0.zh-CN.md#10-运行契约)
在 S5 下排列传输隔离、普通私聊/角色选择、进度/媒体/权限及安装态替换验收。

普通项目对话需要共享 Core 会话上下文,明确授权工作区、executor 和受众,
无需用户创建 Goal,也不自动赋予全局管家目标。这是尚待实现的入口要求,
不是新增已发布 Session schema。Lark 不能通过创建隐藏 Goal、复制其它 host session
或另建 executor 来实现。显式接收者选择使用权限范围内的稳定引用,标签不授予权限。
切换接收者影响未来输入;已受理工作和回报保留原 Session、来源和受众。
停止针对当前精确请求,不停止 Bot 后面的全部 Agent。

### Managed 与 attached 是不同的执行关系

| 关系 | App 承诺 | 必需证据与限制 |
Expand Down
36 changes: 36 additions & 0 deletions docs/architecture/rfcs/capable-manager-semantic-handoff-v0.md
Original file line number Diff line number Diff line change
Expand Up @@ -752,6 +752,42 @@ Target an ingress receipt within two seconds on a healthy local service, indepen

Use existing service recovery and receipt pumps. No manager-specific business automation for each kind of request. Expose configuration and failures through the existing CLI, capability settings and manager conversation. Troubleshooting distinguishes model failure, tool/policy denial, state conflict, unreachable receiver and transport formatting/delivery failure.

**Realtime IM entry (S1/S5/S10):** qualify long-connection reception, durable
admission, host execution and visible return separately. While one answer is
blocked, another request or correction must receive bounded, truthful admission
feedback; Core queue/steering support alone does not qualify the Lark consumer.
Retain persistent Sessions, provisional progress, exact permission decisions
and explicit media availability through existing Chat/Turn/operation owners.
No parallel bridge ledger or scheduler is required. The bundled provider's
[readiness guide](../../../loopx/extensions/lark/docs/realtime-conversation-readiness.md)
records bounded cross-conversation dispatch and remaining replacement qualification;
private DM onboarding, ordinary non-Goal chat, streaming and media remain
unqualified until the pinned installed journey passes.

**Product boundary:** the Bot is a realtime conversation entry, not another
steward. Ordinary project chat and direct conversation with a selected existing
Agent must remain useful without team decomposition or a new Goal/Todo. The
steward is an explicit recipient when the user needs persistent commitments,
coordination and acceptance. Share authenticated ingress, Session/Turn,
execution/progress/attachments, operation decisions and recovery; keep recipient
purpose, audience, transcript and workspace grants distinct. A channel must not
inherit the global steward objective or portfolio visibility just to obtain a
working executor. Shared changes belong to the
[conversation-entry RFC](app-conversation-and-async-inbox-v0.md), not a second Bot
execution or approval authority. Replacing a tenant-controlled App on another
machine requires a freshly authorized App; credentials, source transcripts and
permission bindings do not travel as a workstation backup.

Deliver these through M1/M3 and the existing S5 journey, without adding a parallel
milestone or treating a periodic heartbeat as realtime transport:

| Order | User-visible exit | Existing owner and qualification |
| --- | --- | --- |
| First | A slow role does not hold every other conversation on the same Bot; follow-ups remain ordered | Lark transport has bounded workers/buffering, fresh binding checks, reply/ACK readback and stop/drain evidence; Core retains Session admission and budgets |
| Next | A first DM and explicit role choice continue the intended conversation; busy work promptly reports durable admission or rejection | Chat Session/Turn and typed ingress own continuity, audience and queue/steering; ordinary chat must not require users to manufacture a Goal Topic, and role names alone grant no authority |
| Then | Progress, images/files and permission answers work for each advertised host | Existing event/attachment/operation owners; bounded provisional cards, explicit unsupported media, authenticated exact-operation callbacks and delivery-only recovery |
| Switch gate | The installed provider/host journey survives reconnect, duplicates, cancellation and unavailable delivery | Pin versions and run the actual entry/readback; retire an old bridge only after qualification, with one consumer owner per App and no copied credentials or sessions |

**Accepted queue preparation failures (S1/S10, A12/A22/A23):** an accepted
request owns a terminal outcome even before an adapter starts. A missing runtime
asset, invalid workspace or failed session restoration must settle the affected
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -632,6 +632,31 @@ M0 盘点真实字段和 producer;以下是迁移验收底线,不代表已

使用现有服务恢复和 receipt pump,不为每类请求创建管家业务 automation。配置/故障通过已有 CLI、capability settings、管家对话展示。诊断区分模型失败、工具/策略拒绝、状态冲突、接收方不可达、格式/传输失败。

**实时 IM 入口(S1/S5/S10):** 分开验收长连接收信、持久准入、host 执行和可见回报。
一个回答阻塞时,另一个请求或纠正仍须得到有界、真实的准入反馈;Core 已支持 queue/steering
不能替代 Lark consumer 的验证。持续 Session、临时进度、精确权限决策和明确的媒体可用性
复用已有 Chat/Turn/operation owner,不另建 bridge 账本或 scheduler。
bundled provider 的[就绪指南](../../../loopx/extensions/lark/docs/realtime-conversation-readiness.md)
记录有界跨会话处理和仍待完成的替代验收;私聊开通、普通非 Goal 对话、流式回显与媒体输入,
须等固定版本的已安装旅程通过后才能宣称就绪。

**产品边界:** Bot 是实时会话入口,不是另一个管家。普通项目对话和与选定既有 Agent
直接交流,无需团队拆解或新增 Goal/Todo;需要长期承诺、协调和验收时,管家是显式接收者。
共享认证入口、Session/Turn、执行/进度/附件、operation 决策与恢复;接收者职责、受众、
会话记录和工作区授权保持独立。不能为了获得可用 executor,就让渠道继承全局管家目标或
portfolio 可见性。共享改动归[对话入口 RFC](app-conversation-and-async-inbox-v0.zh-CN.md),
不另建 Bot 执行或审批权威。跨主机替换受租户控制的 App 时,使用重新授权的新 App;
凭据、来源会话和权限绑定不作为装机备份迁移。

按 M1/M3 和已有 S5 旅程交付,不新增平行里程碑,不把周期 heartbeat 当实时传输:

| 次序 | 用户可感知出口 | 既有 owner 与验收 |
| --- | --- | --- |
| 先做 | 同一 Bot 的慢角色不拖住其它会话,同会话追问保持顺序 | Lark 传输有界 worker/缓冲、执行前绑定复核、reply/ACK 回读和停止/drain 证据;Core 保留 Session 准入与预算 |
| 接着 | 首次私聊与显式角色选择接续正确会话,忙碌工作及时报告持久准入或拒绝 | Chat Session/Turn 与 typed ingress 拥有连续性、受众及 queue/steering;普通对话无需用户先造 Goal Topic,角色名本身不授予权限 |
| 再做 | 每个宣称支持的 host 都能显示进度、接收图/文件和处理权限答复 | 既有 event/attachment/operation owner;有界临时卡片、明确不支持的媒体、认证后的精确 operation 回调,以及只重试投递的恢复 |
| 切换门槛 | 安装态 provider/host 旅程经得住重连、重复事件、取消和投递不可用 | 固定版本,跑实际入口和回读;验收后才退役旧 bridge,每个 App 保持唯一 consumer,不复制凭据或 session |

## 11. 规范性里程碑

以完整用户旅程交付,不按零散字段拆 PR。管家工程负责人维护 canonical Todo 和私有 incident→验收映射;PR 引用本 RFC 的里程碑及验收 ID。公开进度只含可公开结果。完成需要当前部署证据,不是合并 PR 数。
Expand Down
Loading
Loading