Strategy
Defines why.
Control plane · Workflow, authority & attention
The control plane that reads authoritative state, determines the next valid action, dispatches bounded work, gathers evidence, and pauses precisely when human intent, judgment, authority, or lived experience is required.
Defines why.
Defines what is known.
Delivers and proves.
Preserves reuse.
Controls authority.
Changes future behavior.
Coordinates next action.
The Orchestrator reads the six systems, applies governance, assembles task-specific context, coordinates execution, and preserves state in Git.
It determines what may happen next—not what the product should mean, which architecture is desirable, or which risk a human should accept.
Human inputs are versioned operating inputs, not interruptions. They contribute what AI cannot legitimately invent.
Strategy defines intent.
Governance defines authority.
Orchestrator determines the next valid action.
Humans supply intent, judgment, authority, and experience.
Agents execute inside bounded scope.
Git preserves authoritative state.
Every transition is based on current artifacts, explicit authority, dependencies, qualified actors, and required evidence.
Which versions and approvals are authoritative?
What change is currently authorized?
Is work sufficiently defined to begin?
Which entry criteria must be satisfied?
What exactly may change?
Who can and may perform the work?
What is the smallest sufficient package?
Which packages are safely independent?
What will prove completion?
What requires pause or escalation?
Has new information invalidated authority?
Which intent or judgment is missing?
Which role has authority?
What can proceed while input is pending?
What state and evidence must be preserved?
The Orchestrator earns leverage by reducing ambiguity, preserving traceability, and using human attention only where it adds legitimate authority or judgment.
Conversation initiates; versioned repository records control.
Silence and ambiguous assent are not authorization.
Agents proceed independently until a defined stop condition.
Actors receive only sufficient authoritative information.
Dependencies and public boundaries determine concurrency.
Completion claims never satisfy a gate by themselves.
Dependent work is re-evaluated when sources change.
Failures retain intent, evidence, and progress.
Human requests are decision-ready and role-specific.
Agents generate leverage within approved constraints.
The Orchestrator connects intent to evidence while enforcing policy at every transition.
| Capability | Orchestrator responsibility |
|---|---|
| State reconstruction | Read specifications, approvals, commits, packages, risks, and evidence. |
| Readiness evaluation | Confirm entry criteria for the next stage. |
| Planning | Convert approved changes into dependency-aware packages. |
| Assignment | Select qualified agents or route decisions to named human roles. |
| Context assembly | Supply current requirements, boundaries, interfaces, policies, and evidence. |
| Parallel execution | Start independent packages and manage integration order. |
| Progress + recovery | Track blockers, retry safely, narrow scope, reassign, or resume. |
| Gate preparation | Assemble decision-ready evidence for the authorized approver. |
| Policy enforcement | Prevent unauthorized actions, paths, or stage transitions. |
| Traceability | Link intent → specification → approval → package → commit → evidence. |
| Learning triggers | Create structured signals from meaningful outcomes and failures. |
| Repository update | Preserve current state, evidence, decisions, and completed work. |
A change may traverse this loop several times as OpenSpec progresses through Explore, Propose, Refine, Approve, and Apply.
The view is derived from authoritative records and never competes with the specification.
Every update identifies the responsible actor and timestamp.
orchestration:
id: ORCH-GAME-LIFECYCLE-001
status: executing
change:
id: CHANGE-GAME-LIFECYCLE-001
version: 0.4
commit: 8f31c2a
current_stage: openspec-apply
authorized_by: APR-GAME-LIFECYCLE-004
active_packages:
- WP-LIFECYCLE-CORE-003
- WP-LIFECYCLE-UI-002
waiting_packages: [WP-LIFECYCLE-AUDIO-002]
blocked_packages: []
next_gate: integration
risks: [RISK-AUDIO-004]
stop_conditions:
- lifecycle-public-api-change
- memory-budget-exceeded
- target-hardware-input-conflictEach package carries its source authority, permitted paths, required evidence, executor role, and explicit stop conditions.
Boundaries protect reusable platform code from product-local behavior.
work_package:
id: WP-LIFECYCLE-CORE-003
risk_tier: 2
source:
change_id: CHANGE-GAME-LIFECYCLE-001
specification_version: 0.4
approval_id: APR-GAME-LIFECYCLE-004
objective: implement start, pause, resume
boundaries:
may_modify: [platform/lifecycle/**, tests/platform/lifecycle/**]
must_not_modify:
- games/sock-rescue/scoring/**
- platform/audio/public/**
outputs: [implementation, tests, conformance, notes]
executor: gameplay-platform-engineer
verification:
- all transitions pass
- no mutation while paused
- deterministic resume
- memory budget satisfied
stop_conditions:
- public interface must change
- unspecified state required
- target behavior not reproducibleFourteen input classes make human involvement specific, routable, and traceable.
Desired outcome or priority.
Choice among valid alternatives.
Qualitative or domain assessment.
Formal authorization to progress.
Ownership of residual exposure.
Qualified knowledge unavailable to agents.
Direct human response to the product.
Data produced through human activity.
A non-negotiable boundary.
Relative sequence or investment.
Temporary authorized deviation.
Verification that a condition is true.
Decision when authorities conflict.
Approval to change future standards.
Human participation ranges from originating the work to resolving only exceptional conditions.
The human should not reconstruct the project to understand the choice. Consequential conversational assent is converted into a structured record.
human_input_request:
id: HIR-LIFECYCLE-AUDIO-003
input_type: risk-acceptance
required_role: product-owner
subject:
change_id: CHANGE-GAME-LIFECYCLE-001
version: 0.4
build: platform-0.5.0
question: Proceed at 27 ms
against the 20 ms target?
evidence:
- target-board-latency-006
- pause-playtest-003
options:
A: delay and correct
B: approve MVP exception
C: remove pause audio
recommendation: B
blocked: [audio, release]
may_continue: [docs, harness]human_input_response:
request_id: HIR-LIFECYCLE-AUDIO-003
decision: approve-with-conditions
selected_option: B
conditions:
- record release exception
- remeasure in release 0.6.0
- do not promote 27 ms as platform target
approved_subject:
change_id: CHANGE-GAME-LIFECYCLE-001
version: 0.4
build: platform-0.5.0
responder:
role: product-owner
identity: human-product-owner
invalidated_by:
- audio architecture change
- latency above 27 ms
- lifecycle interface changeAI prepares evidence and options; humans supply the specific contribution needed to produce an authorized result.
| Stage | Human input | AI preparation | Result |
|---|---|---|---|
| Strategy | Outcome, priority, investment boundary | Options, evidence, dependencies | Authorized strategic intent |
| Explore | Questions, expertise, experience | Research and ambiguity map | Qualified problem |
| Propose + Refine | Tradeoff judgment and clarification | Draft spec, alternatives, contradiction checks | Approval-ready specification |
| Approve | Authority and risk ownership | Gate package and recommendation | Exact authorization |
| Plan + Apply | Exceptional sequencing and escalation resolution | Package graph and bounded execution | Implemented change |
| Integrate + Verify | Cross-system judgment and experience review | Compatibility, tests, measurements | Complete evidence |
| Accept + Release | Product acceptance and residual-risk decision | Evidence map, manifest, rollback plan | Authorized distribution |
| Promote | Support commitment | Reuse and consumer evidence | Platform capability |
| Learn | Meaning and generalization judgment | Pattern and causal analysis | Adopted improvement |
Governance resolves the authorized individual and delegation path.
Outcome, investment, continuation, cancellation.
Behavior, priority, acceptance, tradeoffs.
Visual, animation, audio, delight, coherence.
Boundaries, interfaces, technical direction.
Reuse, promotion, compatibility, deprecation.
Board behavior, peripherals, target evidence.
Evidence sufficiency, severity, release quality.
Qualified interpretation and residual exposure.
Sequence, dependencies, human availability.
Assets, interaction behavior, visual specs.
Direct experiential evidence.
Distribution authority and rollback readiness.
Bundle related questions, show meaningful deltas, distinguish required decisions from optional feedback, and never infer approval from delay.
Decision needed · What must be decided
Why now · Which transition depends on it
Recommendation · Preferred option and rationale
Evidence · Facts and uncertainty
Consequences · Tradeoffs by option
Authority + deadline · Who must decide and when delay matters
Local questions pause a package; shared contracts pause producers and consumers; strategic, safety, or release risk may stop the change.
| Waiting state | Orchestrator behavior |
|---|---|
| Local decision | Pause only the affected package. |
| Interface decision | Pause producers and consumers of the interface. |
| Platform-boundary decision | Pause proposed shared-code changes. |
| Evidence request | Continue evidence collection where safe. |
| Experience review | Prepare a playable build and review protocol. |
| Risk acceptance | Stop the affected release or exposure. |
| Strategic conflict | Stop downstream execution. |
| Human unavailable | Preserve state and use the defined delegation path. |
Every event triggers impact analysis, policy evaluation, context assembly, dispatch, verification, and state preservation.
Context is role-specific, versioned, and labeled as authoritative or informative.
Approved requirements, paths, interfaces, tests, stop conditions.
Criteria, risk tier, commit, and evidence policy.
Board revision, pins, timing, memory, measurement procedure.
Asset contract, display, palette, frame and memory budgets.
Impact, alternatives, dependencies, platform implications.
Decision, evidence, recommendation, risk, exact version.
Scenario, tasks, build configuration, observation protocol.
Reuse evidence, consumer needs, compatibility, maintenance.
Failures become structured state changes, not reasons to silently improvise.
| Failure | Response |
|---|---|
| Incomplete agent output | Return the package with specific unmet criteria. |
| File-boundary violation | Reject the change and record the policy violation. |
| Repeated agent failure | Re-decompose, improve context, or reassign. |
| Requirement ambiguity | Stop affected work and request clarification. |
| Public interface must change | Return to the Knowledge Gate. |
| Hardware contradicts simulation | Preserve measurement and route to the embedded owner. |
| Incompatible agent changes | Pause integration and resolve contract ownership. |
| Human decision conflicts with strategy | Escalate to the strategy owner. |
| Approval references old version | Invalidate it and request reauthorization. |
| Experience fails despite technical success | Route through Knowledge and Learning. |
Parallel packages accelerate delivery while explicit human touchpoints protect lifecycle meaning, creative quality, target behavior, and platform commitments.
| Package | Executor | Dependency | Human input |
|---|---|---|---|
| Lifecycle state machine | Gameplay/platform agent | Approved state model | Architect if model changes |
| Input mapping | Embedded agent | Controller contract | Embedded owner for hardware conflict |
| Pause overlay | Graphics/gameplay agent | Creative specification | Creative approval |
| Audio pause behavior | Audio agent | Audio policy | Product judgment on perceived response |
| State preservation tests | QA agent | Lifecycle contract | QA evidence acceptance |
| Target-board validation | Embedded + QA | Integrated build | Human hardware observation |
| Experience review | Human playtest lead | Playable build | Player feedback and product acceptance |
| Platform promotion | Engine Steward review | Consumer or harness evidence | Human support commitment |
Success is faster flow with fewer avoidable escalations, complete evidence, correct gates, and lower human reconstruction effort.
Authorized change to accepted execution.
Packages started with sufficient knowledge.
Eligible packages completed independently.
Review time by decision class.
Requests resolved without missing context.
Duration blocked on required input.
Independent packages executed concurrently.
Unauthorized paths or capabilities changed.
Invalid transitions prevented.
Packages with all required proof.
Work resumed without rebuilding context.
Failures converted into verified improvement.
Current knowledge, governance permission, approved scope, qualified assignment, and objective verification are all required.
Plans, packages, dependencies, events, escalations, approvals, experience evidence, and delegation policies live beside the work they govern.
The Orchestrator coordinates the system without bypassing any source of truth. Human input remains specific, versioned, attributable, conditional, and invalidatable.
orchestration/
├── charter/orchestrator-charter.md
├── state/
│ ├── active-changes.yaml
│ ├── active-work.yaml
│ └── current-system-state.yaml
├── plans/{active,completed,templates}/
├── work-packages/
│ ├── ready/ ├── active/
│ ├── blocked/ ├── review/
│ └── completed/
├── dependencies/
│ ├── change-graph.yaml
│ └── package-graph.yaml
├── assignments/
├── context/{assembly-rules.yaml,packages}/
├── events/{pending,processed}/
├── escalations/{active,resolved}/
├── recovery/ ├── metrics/
└── templates/
human-inputs/
├── policy/
│ ├── human-input-policy.md
│ ├── attention-policy.md
│ └── delegation-policy.md
├── requests/{pending,answered,expired,withdrawn}/
├── responses/
├── experience/{playtests,creative-reviews,usability}/
├── approvals/ ├── risk-acceptance/
├── expertise/ ├── decisions/
└── templates/
├── input-request.yaml
├── input-response.yaml
├── experience-review.yaml
└── risk-acceptance.yaml