Ten agents and one script that is deliberately not an agent. Listed in the order they run.
| # | Agent | Runtime | Reports to | Talks to the client? |
|---|---|---|---|---|
| 01 | Orchestrator | Hermes (mini) | Greg | No |
| 02 | Dossier | Claude Code (client repo) | Orchestrator | No |
| 03 | Research | Claude Code | Orchestrator | No |
| 11 | SEO | Claude Code | Orchestrator | No |
| 10 | Design | Claude Code | Orchestrator | No |
| 04 | Copy | Claude Code | Orchestrator | No |
| 05 | Build | Claude Code | Orchestrator | No |
| 06 | Machine QA | script, not an agent | Orchestrator | No |
| 07 | Editorial QA | Claude Code | Orchestrator | No |
| 08 | Account Manager | Hermes (mini) | Orchestrator | Yes — through go-live |
| 09 | Customer Success | Hermes (mini) | Orchestrator | Yes — after go-live |
Numbers are stable identifiers, not running order. Design and SEO were added after the first nine were written, so they carry 10 and 11 but run fourth and fifth. Renumbering would break every link already shared.
Three agents each own one thing outright, and Build owns none of them — it implements all three. This split exists because a builder that quietly fills a gap is how a site ends up with no point of view and nobody able to say which step lost it.
| Decision | Owner |
|---|---|
| The words | Copy |
| The look | Design |
| Titles, schema, internal links, blog topics | SEO |
| Assembling all three into a working site | Build |
Every agent document uses the same headings so they can be read against each other, and so a missing section is obvious rather than invisible.
Identity · Role · Voice · Reports to · Inputs · Outputs · Tasks · Definition of done · Hard rules · Failure modes · Escalation · Budget · How it improves
The dossier is the only source of facts. No agent may introduce a claim about the client's
business that does not trace to a line in dossier.md. Anything missing is written as
[NEEDS: …] and becomes a question the account manager asks. This is the single most important
rule in the system: a site claiming "20 years' experience" for a three-year-old business is a
Fair Trading Act problem, not a typo.
Done is defined, or the loop never ends. Every agent has a written definition of done and a bounded number of attempts. An agent that produces the same output twice escalates rather than retrying — repetition is a signal that the brief is wrong, not that the agent needs another go.
Nothing on the site may read as machine-written. The client knows how they talk and will name it instantly; their customers will not name it, they will just trust the business less. Defended in three places — as a constraint at generation, as measurable thresholds in machine QA, and as judgement in editorial QA. See the anti-slop layer in Copy. The client's documented voice overrides every slop rule: an owner who genuinely talks in threes is not slop.
Only two agents speak to the client, and they share one voice. The Account Manager owns the build; Customer Success owns everything after go-live. Every other agent writes to files and to the orchestrator. The client should never be able to tell where the handover happened — a changed tone after go-live reads as being passed to a call centre.
Hermes' memory is 2,200 characters and it evicts silently. Nothing the system depends on may
live there. See ../memory-and-knowledge.md for the six stores, which
agent reads which, and why client_messages — the verbatim record of everything said to a client —
is the one every client-facing agent must read before it writes.
Every agent has both, and they are not the same thing:
[NEEDS:] raised" not
"I've carefully crafted three engaging pages!"A $400 site carries roughly $200 of margin. An hour of Greg's time is most of it, so the client- facing agents are autonomous by default and Greg is a scarce resource, not a safety net.
Three consequences, all load-bearing:
An agent that cannot give anything away can only escalate. So the client-facing agents hold a resolution budget — an extra revision round, a month of hosting, a partial refund — that they may spend without asking. Authority is what makes autonomy real.
Greg is interrupted for money, risk, and unhappiness. A high-ticket upsell (ads, Cited), legal or reputational risk, a pattern signalling a product defect — and any client who is actually unhappy. Not silence, not support questions, not routine requests.
Friction is not dissatisfaction, and the distinction is the whole rule. "Can you make the green darker" is friction and the agent handles it. "I'm not happy with this" is dissatisfaction and it goes to Greg the same hour. At $400 he is not the service desk, but he is absolutely the person who deals with an unhappy customer — that is where refunds, public reviews and reputation live, and a bad review damages the acquisition machine that feeds everything downstream.
Batch, do not interrupt — except for unhappiness. Everything else lands in a weekly digest. An agent that cannot resolve something says so honestly and buys a day. It never improvises past its authority.
Gate levels below are about build quality while we are learning, and are time-boxed to the first three sites. They are not a client-comms policy. Gating client comms would be permanent, and would mean the client hears nothing.
Set per job on jobs.gate_level. Default 0 for the first three sites.
| Level | Greg approves |
|---|---|
| 0 | every stage boundary |
| 1 | copy and go-live only |
| 2 | escalations only |
Quality is the constraint, not cost. A whole site is roughly $3–8 of model spend against $400 of revenue, so nothing here should be run on a cheap model to save money. Budget alarm at $15.