Autonomous shipping: the flywheel factory

Status: protocol v1, draft · 2026-09-12 · phase 1 workers are OpenCode only

Goal: ship features with flywheel and cheap OpenCode worker agents at a fraction of frontier cost, with no human in the loop. That is only safe if every step is recorded, validation is done by the machine, independent auditors check the checkers, and the rules are enforced where an agent cannot skip them.

Flywheel plays the part of a factory’s execution system: the control plane dispatches work and enforces policy; the data plane keeps traceability, telemetry and accountability for every agent session. Leads use it to communicate, understand the situation and trace any result back to the sessions that produced it.

0. Design priorities

In order: efficiency and consistency, then speed, reliability and recoverability. Every feature in this document is held to them:

1. The factory model

Factory role Flywheel persona Does Never Skill
Plant manager lead (frontier) sets goals, capacity and policy; handles escalations; signs off on sensitive work implements flywheel
Production planner planner writes work orders (briefs): owns:/needs:/exclusive:, gates, acceptance criteria dispatches or inspects flywheel-planner
Line supervisor foreman runs a line: dispatches, watches, retries by policy, pulls the cord on trouble plans or implements flywheel-foreman
Line worker worker (OpenCode) builds one work order at its own station (worktree) and reports plans, inspects, commits flywheel-worker
Machine gauges supervisor (the CLI, no model) measures every unit: runs the gates in the unit’s worktree, checks owns: judges intent built into flywheel supervise
QC inspector (internal) inspector inspects each unit against its work order, using the gauge readings; pass, rework, scrap or escalate runs gauges or fixes units flywheel-inspector
External auditor auditor (independent agent + CI) audits samples and the process: re-measures, re-inspects, checks the records and whether QC catches defects; files nonconformances works on the line or talks to it before reporting flywheel-auditor
Continuous improvement steward turns stopped lines and nonconformances into corrective actions (learnings) changes units flywheel-steward
Owner operator (human or agent) installs, assigns roles to agents, sets merge and publish policy — flywheel-operator

One agent may hold several internal roles at small scale, but independence rules are hard: the auditor is never the same session as the lead, planner or inspector, and should be a different model or vendor; the inspector never inspects work from its own session; a worker never records gauge readings, inspections or audits.

Factory mechanics, as enforced features:

2. Required entries

Every event records who wrote it: by: {persona, agent, model, session}.

Stage Event Required fields Written by
Plan planned brief path, brief SHA-256, owns, needs, gates, acceptance criteria planner or lead (flywheel plan add)
Dispatch dispatched adapter, model, session, attempt, run file CLI (flywheel run)
Work worker_plan the worker’s plan message (required before step 20) CLI, from the run
Work finished rc, finish reason, tokens, cost, run-file SHA-256 CLI
Work report final report, “Findings outside owns:” CLI, from the run
Gauges validated gate, command, git tree hash, exit code, duration, output SHA-256, evidence path, environment supervisor only
Gauges owns_checked changed paths, paths outside owns:, grants applied supervisor only
Inspection inspected verdict (pass, rework, scrap, escalate), tree hash, checklist items, note inspector or lead
Audit audited scope (unit, sample, wave), tree hashes, re-measurements, re-inspection result, record check, verdict (conforms, nonconformance) auditor only
Landing landed commit, tree hash, the gauge and inspection events it relies on landing queue (flywheel land)
Andon signal, dismissed kind, task, evidence CLI; steward or lead triage
Improvement learning severity, observed, evidence, ask, linked signals or nonconformances steward

3. Poka-yoke: transition rules

flywheel verify fails, and the enforcing commands refuse, when any of these is broken:

4. Enforcement layers

Layer Mechanism Stops Bypass
CLI commands refuse illegal transitions a persona recording a result it has not earned editing the log by hand, which T10 detects
Supervisor flywheel supervise measures every finished unit itself “tests pass” claims; skipped measurement not running it, which T3 then fails at inspection
Git hooks commit-msg requires Flywheel-Task:; pre-push runs flywheel verify untracked or unverified commits leaving the machine --no-verify, which CI catches
Agent hooks a Claude Code Stop hook and an OpenCode plugin run flywheel gate before a session ends a lead or foreman ending with uninspected units, missing readings or untriaged signals agents without hooks, which CI catches
External audit the auditor persona plus the CI flywheel-audit check (required status) internal QC passing defects; a broken chain reaching main a repository admin override, visible on the PR

5. Telemetry: every session is captured

6. Evidence

7. Cost

The lead spends tokens on planning, escalations and sign-offs; workers do the reading and writing; gauges cost no tokens; auditors spend on samples, not on every unit. flywheel stats reports cost per landed unit by persona against a frontier-only baseline (the same tokens priced at the lead’s model), so the “fraction of frontier cost” claim is measured per wave.

8. A wave, end to end

  1. The planner records work orders (planned).
  2. The foreman runs the line: flywheel run dispatches OpenCode workers (dispatched), captures their plans (worker_plan), or pulls the cord (signal).
  3. A unit finishes (finished, report); the supervisor measures it (validated, owns_checked). A failed gauge gets a templated rework delta up to a retry limit, then escalates.
  4. The inspector inspects (inspected). First articles and sensitive units go to the auditor (audited) and, for sensitive domains, the lead.
  5. The landing queue re-measures if rebased and lands (landed); the PR’s flywheel-audit check verifies the chain; release-please prepares the release.
  6. The steward closes the wave: every signal and nonconformance has a learning or a dismissal.

9. Open questions