Proposal · for review AINA · Paperclip team · AIOPS-266 2026-07-01

AINA Minas Tirith OS

The White City as the control plane. You're the marketing-bound King; Donna is Steward — the team ships itself, and you review outcomes on a surface you pull, never pings that interrupt you.

Verdict direction right · repair → verify → flip Origin calibration w26wlq0qs · 9 agents · 1.23M tok Next Step 1: repair manifests (reversible)
The Verdict

Direction confirmed — but do NOT rename + flip in one pass. The council was unanimous: sequence it repair → verify → flip, or we repeat three "never again" mistakes (false-done, drift, detection-without-action). The calibration's real value: it caught four live landmines before we touched anything.

Section 01

The 4 landmines calibration caught

  1. 63 of 64 agents' manifests are corrupted — a secret-scrubber overwrote real authority_order values with the literal string [REDACTED]. Routines read these at wake; repair is a blocking prerequisite.
  2. Donna doesn't exist as a Paperclip agent yet — only a thin 11-line bridge stub. "Donna is CEO" is false until a real record exists.
  3. COO is a LIVE 10th agent dispatching build lanes, wired as Jessica's deputy. Paperclip allows exactly one CEO — retiring Jessica must dispose of COO explicitly.
  4. 0 of 7 routines actually fire (all paused), and COO's health-marker file is the external scaffolding we're removing → replace with a native task-watchdog.
Locked with you
COO folds into Donna for now (re-design the COO responsibility later; no Slack pings to you — digests & escalations go to a pull surface you check). Donna = a new clean Paperclip record. Jessica retired. reportsTo slugs stay stable.
Section 02

The White City — seven levels

7 · Donna — Steward 6 · Council of Lords (heads · Hermes) 5 · Archives — Finch · Gandalf 4 · Citadel Guard (review · Claude) 3 · Armoury / Q-Branch (Codex) 2 · Guildhalls — ~35 artisans (Codex) 1 · Pelennor — retired / legacy
A Steward who administers in the King's absence, a Council of Lords each sovereign over a district, a Guard that watches but never builds, an Archive that remembers so the city doesn't repeat its mistakes.
LevelWhoAdapter
7 CitadelDonna — Steward-CEO (absorbs Jessica + COO)hermes_local
6 LordsBoromir · Fury · Galadriel · Arwen · Círdan · Théoden · Éomer · Faramirhermes_local
5 ArchivesFinch (Loremaster) · Gandalfhermes_local
4 GuardGimli · Éowyn · Silva · Vision · Argus (review ≠ producer)claude_local
3 ArmouryQ · Root · Rambo · Moneypenny · Jarvis · Stark · Fridaycodex_local
2 Guildhalls~35 artisans (Thorin, Balin, Celebrimbor, Bilbo, Samwise, Radagast…)codex_local
Section 03

Four skill layers per role

So the agent playing a role actually has the skill for it:

LayerWhat
1 · Hermes-native29 skills auto-loaded on hermes_local (software-dev, devops, github, research, mlops, red-teaming, delegate-to-specialist…) — Donna + heads + Finch
2 · Paperclipcompany (decision-contract, handoff, code-reviewer, pr-writer, grill-me) + dept + per-agent via skills:sync
3 · Ruflo powersrag-memory/agentdb (memory) · intelligence/SONA (self-learning) · aidefence [req. at launch]/security-audit (Silva/Théoden) · testgen/jujutsu (Gimli/Éowyn) · cost-tracker/observability (Fury). Plugin-only — NEVER the swarm layer (it caused the April failure; Paperclip orchestrates).
4 · Memory loopthe heads' compounding intelligence (below) — a real build item

Frodo's release skills (parked earlier, folded back): github-pr-workflow, cloudflare-preview-proof, merge-gate, release-announcement — Keeper of the Gate of Release.

The heads' memory & learning loops — a real build (their memory is empty today)
Each Hermes head gets a per-head Tier-1 MEMORY.md + USER.md, a self-evolving loop (on wake read memory; after each task log what worked/failed → weekly distill to fewer, sharper rules), Tier-2 FTS5 session search (automatic), and the LLM Wiki for the domain heads (Galadriel/data, Círdan/research, Arwen/curriculum) — a separate world-knowledge layer that compounds and cuts hallucination. This is what makes them get smarter every week.
Section 04

Self-running, natively — no scaffolding, no pings

Company goal → Donna's strategy (you approve once) → she delegates → the citadel ships → she escalates only genuine irreversibles, to the surface you pull.
Section 05

Execution — repair → verify → flip

ACT reversible (Donna/Finch) · Ali your gate

  1. ACT Repair the ~63 [REDACTED] manifests (pointers to source, never inlined). Blocking prerequisite.
  2. Ali Create Donna's new clean record + fold COO's loop into her; retire COO + marker.
  3. ACT Global 64-file re-point Jessica/mission_control → Donna's UUID (grep to zero).
  4. ACT Minas Tirith rename pass — display names + titles only; slugs stay.
  5. ACT Workspace hygiene — split Growth/Media cwds, give AgentOps its own, fix stale adapter text.
  6. Ali Canary ONE head on hermes_local end-to-end (memory + FTS5 + delegation) before flipping the other 7.
  7. Ali Finalize Finch's PKM-Steward-Charter.
  8. Ali Bind + test-fire 2–3 routines (digest → pull surface).
  9. ACT Attach native task-watchdogs → Guard-tier reviewers.
  10. ACT Heartbeat-off / wake-on-demand audit across all 62.
  11. Ali Verify no agent flipped paused → live; founder sign-off before "landed."
Section 06

Still needs you