A two-agent Codex loop with a hard boundary.
This is the safe version of multi-agent orchestration:
- a planner proposes steps
- a policy file checks every step
- an executor runs only allowlisted work
- every action writes a receipt
- the loop continues from receipts, not vibes
No hidden routing. No renamed agents. No silent sensitive work. If a step is not allowed, the loop stops and asks you.
- clone this repo
- give
workflow.pngto your agent - copy
loop.md,planner.md,executor.md, andpolicy.yamlinto the conversation - create
task.mdwith the job you want done, then say:
run this as a /loop automation
task.md
-> planner proposes one step
-> policy checks the step
-> if allowed: executor runs it
-> receipt goes into receipts/
-> log.md updates
-> planner re-plans from receipts
-> stop when done or blocked
loop.md- the loop driverplanner.md- planner role (no execution)executor.md- executor role (allowlist only)policy.yaml- hard rulesreceipt.schema.json- receipt shapetask.md.example- starter taskexamples/allowed-step.json- example allowed stepexamples/blocked-step.json- example blocked stepworkflow.png- give this to your agentworkflow.excalidraw- source diagram
- Planner never executes.
- Executor never invents steps.
- Policy is fail-closed.
- Publish, delete, spend, credentials, prod, messages, and external posts need human approval.
- Every action must leave a receipt.
- If anything is unclear, stop and ask.
- Open a Codex thread in the repo.
- Attach
workflow.png. - Paste
loop.mdas the system driver. - Keep
planner.md,executor.md, andpolicy.yamlin context. - Write your goal into
task.md. - Say:
run this as a /loop automation.
The agent should:
- read
task.md - write a proposed step
- check it against
policy.yaml - either run it or stop for approval
- append a receipt
- update
log.md - continue until done
Edit policy.yaml first. That is the product.
- add only the paths you want touched
- add only the commands you want allowed
- put irreversible actions under human approval
- keep the forbidden list boring and strict
If the loop feels slow, your policy is doing its job.