All notable public changes to Team First Development are documented here.
- Add opt-in, session-only
AUTO_REVIEWwith one confirmed Autonomy Envelope, Orchestrator approval for in-envelope gates, bounded repair and evidence recovery, and no repeated user reply between approved steps. - Keep independent review as risk-scaled evidence, preserve exact external targets, and leave out-of-envelope, production, destructive, privileged, messaging, security, and structural Wiki changes human-gated.
- Remove all Superpowers Skill bindings from TFD documentation and example
profiles; allow an explicit empty
skillslist when a member needs no extra working-method Skill.
- Make the Coordinator decompose a
TEAMoutcome into the minimum useful workstreams and map each one to exactly one accountable selected member. - Include the session-only workstream map, write scopes, dependencies, handoffs, and parallel or serial order in the exact confirmation proposal.
- Allow only the Coordinator to activate members; prohibit member re-delegation and unconfirmed helper Agents.
- Run only dependency-free, non-overlapping workstreams in parallel, stop
dependent work after a
BLOCKER, and integrate accepted outputs into one immutable candidate before review.
- Add one progressively loaded engineering contract for every source-code or
architecture change, including
SOLOwork. - Require one concern owner, inward dependencies, fake or in-memory unit-test seams, one authoritative capability implementation, add/remove feature units, one canonical paradigm, current callers, and current-need minimalism.
- Scale evidence depth with risk while retaining
PASS,BLOCKER, andUNVERIFIEDas the exact review verdicts.
- Add an exact per-member Runtime binding with
codex_spawn,codex_thread, andcodex_execexecution surfaces. - Require new or edited member profiles to declare
runtime, while resolving legacy v3.1 profiles without it tocodex_spawnwithout rewriting them. - Keep
agency_roleas optional frozen agency-agents provenance, independent from Runtime and model selection. - Use
~/.codex/models_cache.jsononly for account candidate discovery and require surface-specific eligibility evidence before activation. - Include exact Runtime, model, reasoning effort, evidence source, and user-visible behavior in the confirmation proposal.
- Start the confirmed binding once, verify trusted Runtime metadata, preserve
missing proof as
UNVERIFIED, and prohibit automatic retry or fallback.
- Add a Git-native Markdown Team Wiki under each configured team, with immutable digest-addressed sources, maintained pages, exact proposal-confirm/apply knowledge writes, and no RAG or task control plane.
- Add the standard-library Wiki Guard CLI for initialization, proposal validation/application, query records, bounded work activity, and strictly read-only integrity lint.
- Record explicit user and team-member Wiki questions without a second
confirmation; keep answers up to 1,000 Unicode code points in
log.mdand route longer answers to linked query detail files. - Merge bounded
work_started,handoff,review, anddeliveryaudit into the Wiki event chain while keeping knowledge promotion separately confirmed and retaining legacy receipts only before Wiki initialization. - Package the Team Wiki protocol under the
using-tfdSkill so its on-demand relative reference resolves directly in a fresh Codex task. - Require one explicit confirmation of the exact team proposal before writing profiles or creating Agents; a generic team request or delegated choice does not confirm an unseen roster.
- Allow one unchanged proposal to cover profile writes and immediate activation, while requiring renewed confirmation after any material proposal field changes.
- Breaking: replace the four-Skill v2 control plane
with the suitability-first
tfd:using-tfdand project-local YAML team profiles. - Configure reusable teams and named members without creating Agents; select at most one team and its minimum useful member subset for each requirement.
- Require exact
spawn_agentmodel choices and exact locally installed Skill names; stop on missing dependencies or initialization failure without substitution or fallback. - Remove persistent task state, state lifecycle, recovery, and management commands; retain only an optional final delivery receipt as a human-readable trace.
- Preserve separate approval for installation, merge, push, tag, release, publication, and external actions.
- Derive aligned Task participants from the sealed TaskDocument, assign all and only that exact set through a prospective roster validation, and keep legacy Tasks owner-only.
- Release exact participants atomically when a Task reaches
DONEorCANCELLED, with an idempotentcoordinator-release-taskrepair command for pre-v2.1.3 terminal Tasks. - Render current execution bindings from the authoritative roster while preserving Task ownership as separate history, and retain runtime preparation as a fail-closed dispatch prerequisite.
- Show users only a short human fingerprint for conversational approval while retaining the complete canonical digest internally for the exact machine/operator
init-apply --approval-digestboundary; changed, stale, expired, mismatched, or ambiguous proposals require renewed confirmation. - Validate the user's outcome, shared success criteria, complete current phase, and each participant contribution when proposing task alignment before approval.
- Disclose generated views as rebuildable rather than authoritative, and disclose nested Git repositories or worktrees while failing closed instead of treating them as ordinary candidate content.
- Add live
create_threadmodel-allowlist evidence to TEAM scanning: pass observed exact IDs with repeated--create-thread-modelflags, omit that input rather than reuse cached identifiers when metadata is unavailable, and prefercreate_thread_eligible_modelsbefore the legacyeligible_modelsspawn_agentfallback.
- Assess every non-hidden live account model with sourced pros/cons and role-fit-first scoring, while keeping the optional Spark preference bonus bounded below role fit and execution hard gates.
- Separate recommendations from execution: prefer verified
create_threadcapability, retain the exact-IDspawn_agentintersection as fallback, preserve unavailable backends asUNVERIFIED, and keep session evidence out of.tfd. - Preserve the complete recommendation catalog when the verified execution intersection is empty, and report execution separately as
BLOCKER/no_verified_execution_backend. - Make the three product principles explicit: vision alignment, model-role fit, and context isolation. Persistent v1 records authoritative alignment, recipient TaskPackets are derived least-privilege projections, and a complete-participant gate blocks work until every required current-phase projection is valid.
- Keep persistent new-v1, legacy compatibility, and session-only alignment routes separate: legacy records remain readable but
UNVERIFIED, while session-only keeps alignment in active context, writes no.tfd/path, and has no cross-session recovery. - Tighten reviewer and Coordinator authority boundaries: only Coordinator-owned, revision-safe state transitions can move authoritative task state; required reviewer/user
PASSattestations bind the active reviewer or named user to the exact task revision and candidate digest. - Add an offline release preflight that rejects unsafe fixed release inputs, plus a cachebuster update flow that verifies the configured local marketplace source before a fresh task loads the rebuilt plugin cache.
- Breaking packaging change: replace the source standalone Skill with the installable
tfdplugin. There is no compatibility shim; install the plugin from the repository marketplace and usetfd:using-tfd. - Split the workflow into a four-Skill architecture: the normal
tfd:using-tfdentry coordinates the internaltfd:team,tfd:deliver, andtfd:workspacestages. - Keep the current primary Codex as the visible, non-roster Coordinator rather than a persistent Agent or task-team member.
- Offer project-local
.tfd/persistence while preserving a complete session-only fallback when Workspace creation is declined. - Add authoritative Coordinator state, immutable Workspace events, and the deterministic, rebuildable
.tfd/LOG.mdtimeline. - Preserve the local-only v1 boundary and separate approval for publishing, deployment, deletion, external messages, privileged commands, and external-system writes.
- Add the local-only TFD Workspace v1 CLI with proposal-first initialization and stable JSON envelopes.
- Document authoritative versus generated state, Agent identity snapshots, capability-driven Skill review, default-deny whitelists, permission enforcement, immutable worklogs, archive/reactivation, and context-free recovery.
- Document reviewed
project_custom,BIND,INSTALL, and commit-pinned local Git checkout behavior. - Keep strict host invisibility honestly
UNVERIFIEDwithout concrete host evidence. - Verify one deterministic three-core-Agent/five-task local closed loop and 496 passing tests; named-user acceptance and out-of-scope deployment remain
UNVERIFIED. - Retain digest-bound role sources separately from generated identity Markdown so initialized temporary experts can archive and reactivate safely.
- Run every contract, catalog, and Workspace test through unittest discovery in CI.
- Require immutable revision- and candidate-bound reviewer/named-user attestations for required team or user
PASS, exposed through the localtask-attestCLI. - Publish exclusive records from a fully flushed same-directory temporary file with atomic no-replace linking, directory fsync, and deterministic stale claim reconciliation.
Initial public release.
- Dynamically search and select local Agency Agents roles.
- Support optional private custom-role catalogs.
- Establish authority envelopes and team charters before execution.
- Require progressive contract, vertical-slice, and frozen-candidate gates.
- Bind review evidence to a reproducible Candidate manifest.
- Normalize review and closeout to
PASS,BLOCKER, andUNVERIFIED. - Keep automated, team, human/device, user, and deployment evidence independent.
- Preserve upstream role sources as read-only during normal operation and tests.