The instruction ranking already exists in crates/tui/src/prompts/text.rs ("Whose word wins", 5cf9db3). This issue adds the three pieces the prompt text can't enforce by itself. Founder-approved direction, 2026-09-25 (from codewhale-app #90).
Why
Instruction files and memory are snapshots of someone's past intent. Often a past agent session wrote them, not the owner, and people change. Today agent-written text ranks the same as owner-written text, and nothing in code keeps a live request from switching off the agent's honesty.
Scope
- Provenance as data. Every instruction layer and memory entry the Engine loads carries its author (owner, or agent session) and a date, as real fields rather than prose. Repo files get this from git; Engine memory needs it natively. A deletion leaves a trace.
- Agent-written text is a claim, not a rule. Prompt assembly marks agent-authored instruction or memory content as notes. It needs owner confirmation before it acts as a rule. Anything the owner wrote or approved outranks it.
- Name conflicts, don't resolve them silently. When the live request contradicts a file, follow the request, then offer to update the file ("AGENTS.md says X, you said Y; update it?").
- Honesty can't be overridden. A live request ("always agree with me") cannot remove honesty or the agent's values. Today the user's turn ranks above the constitution, and only facts are explicitly protected ("no one may invent one"). Add a regression test next to
only_the_constitution_states_precedence.
Acceptance
- Provenance fields are served for instruction layers and memory entries, and are visible in the prompt projection.
- A test shows agent-authored memory is rendered as a claim, not a rule.
- A test shows a user turn cannot drop the honesty clause from the assembled prompt.
- The precedence statement still lives only in
BASE_PROMPT.
Not in scope
- UI. The desktop app will show provenance once the Engine serves it.
- Any second prompt authority, and any TypeScript or Effect port. Rust types and tests carry the enforcement.
The instruction ranking already exists in
crates/tui/src/prompts/text.rs("Whose word wins", 5cf9db3). This issue adds the three pieces the prompt text can't enforce by itself. Founder-approved direction, 2026-09-25 (from codewhale-app #90).Why
Instruction files and memory are snapshots of someone's past intent. Often a past agent session wrote them, not the owner, and people change. Today agent-written text ranks the same as owner-written text, and nothing in code keeps a live request from switching off the agent's honesty.
Scope
only_the_constitution_states_precedence.Acceptance
BASE_PROMPT.Not in scope