Splinter port — completed and superseded
The original Splinter/Rig port plans are retained in Git history. They are not implementation instructions for the managed Hermes runtime.
The useful substrate outcomes remain in code and current ADRs: signed runtime authority, tenant scoping, idempotent execution, explicit product-owned input, and isolated server-owned write-action approval where configured.
The original plans' default HITL, high-risk-reply approval, auto-reply policy, Humanwork-owned tool-manifest gating, synthetic event transcript, prompt snapshot, and universal tool-call audit instructions are obsolete. Normal tools are primary, MCP fills only missing capabilities, Hermes/ACP owns native tool evidence, and every successful canonical reply is delivered exactly once.
Current sources: