Direction agreed before the separation spike
The initial recommendation has been refined: runtime isolation stays, but the personal runtime may carry a deliberately small shared foundation until provider coordination is extracted into services.
Recorded decisions
Shared patches are allowed temporarily
Personal Hermes should stay upstream-oriented, but Featherless and other truly cross-runtime essentials may remain shared until their generic replacement exists. Nagato-only Runs, trace, artifact, and bridge behavior stays in the product runtime.
Every runtime and candidate gets isolated memory
Personal Hermes may inspect, develop, and operate Nagato through authenticated interfaces because it lives on the same desktop. It does not mount or silently retrieve from Nagato’s structured memory database. A trimmed Nagato Hermes remains an option after the first separation spike.
Featherless becomes shared infrastructure
The long-term target is one local scheduling service that owns reservations, capacity, fairness, retries, and provider observability. Hermes runtimes and future harnesses become clients, allowing duplicated scheduler patches to be retired.
Plans become ephemeral capability sites
The current public directory is only a bootstrap. The desired service creates high-entropy temporary links, supports expiry/deletion and explicit save-to-directory, and later accepts authenticated replies/revisions. Capability URLs reduce accidental discovery but do not replace access control.
Checkpoints align with subwaves and risk events
Publish at each subwave boundary, on material blockers, before and after cutover, and at final acceptance. This creates a readable operational history without noisy clock-only updates.
Resulting access boundary
Personal Hermes
- Works directly in the Nagato repository
- Calls Nagato development and inspection APIs
- Own sessions and structured memory
- Shared Featherless client contract
Nagato runtime
- Bridge-facing product service
- Trimmed to required agent behavior
- Game/profile-isolated memory
- Recall remains bridge-governed evidence
Important qualification
“UUID-style temporary link” is a usability and discovery property, not complete authentication. The first plan-service slice should combine at least 128 bits of randomness with TTL, explicit deletion, no directory listing, noindex, strict file/type limits, and safe response handling. Private replies or operational logs require authenticated ownership.
Checkpoint 002 scope
Produce the exact separation-spike blueprint: installations and service identities, the shared-vs-product patch ledger, Featherless scheduler interface boundary, memory namespaces, personal-to-Nagato development API, migration and rollback sequence, contract tests, and the first ephemeral-plan-service slice. This remains a plan until explicitly approved for implementation.