Coordinator Planning and Native ROOT Execution
Fresh sessions default to legacy; opt in with --native-root. Saved sessions retain their recorded mode, for both explicit-ID and interactive-picker resume. --no-native-root explicitly selects legacy Fleet execution. Both retain MCP, acknowledged YOLO, custom roles/skills and Claude worker behavior under existing permission policies. Native mode is not a trust grant. AGENTS_FLEET_NATIVE_ROOT remains unsupported and ignored. This source policy does not migrate existing tasks or adopt live sessions. The implementation and local production fixtures establish the contracts below, not live-model quality or universal SDK reliability. The remainder of this guide describes that native mode, including eligible workflow children. It is not a /wf mode. Ordinary chat requires no task DAG. With native mode enabled, the coordinator plans; the native runtime schedules:
draft -> explicit commit -> execution -> validated evidence
-> declared independent verifier -> decision -> eligible downstream workExecution finished != accepted != merged. A report, an idle worker, task_update verification/status fields, a DoD checkbox, or a verifier merely finishing cannot supply acceptance. Native bookkeeping, evidence delivery and reconciliation do not wait for a model response or successful notification outbox delivery. Provider output and SDK-internal behavior remain nondeterministic.
Planning and commit
Ordinary workflow commands
An authenticated workflow command such as /code-review (also /review or /cr) starts an owned workflow execution in one submission. The command host prepares the invocation, derives its execution criteria and DoD mapping from the declared workflow, arguments and required artifacts, then durably proposes and commits that draft. You do not need to repeat the command with root IDs or type root_plan_commit. Coordinator-prompt workflows run in their own coordinator-capable session, not in the main coordinator's response queue. Dry runs do not allocate a root or start workers.
This authorizes execution, not acceptance or Git integration. Required reports and descendant completion still undergo native structural validation; human or independent acceptance remains separate. Existing explicit --root-id / --root-operation-id planning calls and the low-level tools below retain their preparation/commit barrier. Legacy mode keeps its existing route. Single-shot CLI execution waits for its exact native run's validated output, not a different run's completion event or an idle-worker heuristic. Missing artifacts, failed/unknown execution and timeouts produce a nonzero exit.
The CLI and REPL issue a new host identity per submission. Authenticated socket clients may supply prompt.requestId and retain it on transport retries; Telegram retains the authenticated update identity. A retry of the same identity and input returns the original result without repeating execution. Two intentional submissions of identical command text are separate runs. Interrupted or conflicting submissions are held, not silently restarted.
Registry/session reads such as describe_feature and list_features do not create action roots. Task reads of an allocated-but-uncommitted preparation return an honest empty/prepared view. Session-wide task lists include granted roots; canonical task IDs disambiguate same-named tasks. Foreign roots remain inaccessible.
Explicit planner tools
The runtime injects planner guidance into the coordinator context and wraps its task tools, including after recovery/reload. Ask the coordinator to construct the contract; users need not hand-author every JSON object.
For task/DoD/plan mutations, the planner calls root_prepare_operation({tool,input,root_id?}), then invokes that same tool with exactly that input plus the returned root_id and root_operation_id. Preparation returns the durable ID and expectedRevision, but does not apply the draft or dispatch work. Keep the operation ID, body and original revision on retry, including after provider recovery. Do not prepare a new operation to sidestep an uncertain receipt. Under Claude, preparation first returns a context-bound ticket pool; the planner selects an unused preparation_id, retains it on retries, and holds on exhaustion.
task_create, task_update and spawn_worker are draft proposals. Missing execution, budget or acceptance specifications produce needs-spec holds, not legacy dispatch. root_plan_propose can propose a complete graph. Separately preparing and invoking root_plan_commit commits the exact current draft version and digest, subject to revision and contract checks. A response, idle transition or spawn request never implies commit.
Root-installed tool schemas are closed and advertise the supported planning fields, including workspace_policy, verifier_task_id, verifier_for and dependency fields. They retain the complete spawn_worker inputs and each tool's required fields; input fields never grant host authority. At task_create/task_update/spawn_worker, budget supports only optional maxTokens:null and maxCostUsd:null, not numeric budget overrides. The complete root_plan_propose contract is separate. Old tool syntax with an incomplete specification still returns needs-spec, never false execution success.
For a worker and independent-review group:
| Contract | Planner inputs and meaning |
|---|---|
| Producer A | task_id, description or prompt, agent_type, plus the selected tool's required fields; workspace follows the host-resolved isolated/shared plan |
| Acceptance of A | Nonempty criteria plus verifier_task_id:"B" declares independent review; criteria alone selects human acceptance |
| Independent B | A separate read-only reviewer task with verifier_for:"A"; the host pins A's evidence, criteria and verifier identity |
| Downstream C | blocked_by:["A"] waits for A's accepted result, not just execution completion; C needs its own acceptance contract |
| Integration | mergeOnSuccess:false retains output; otherwise isolated workers use an unambiguous host-selected target, or an authorized root_integration:{targetRef,targetBase} |
B submits a typed root_verifier_decide through its own prepared operation. The host applies it only after B's execution settles, against the exact evidence revision/digest and acceptance version. B's terminal acceptance is protocol-complete, not an independent claim that B's own work was accepted. Do not give B an accepted dependency on A: verifier_for supplies the required execution-finished edge so B can review A before acceptance.
The verifier receives a host-pinned envelope containing the subject attempt, evidence ID/revision/digest, criteria, acceptance version, and its own binding and evaluator principal. Its prepared root_verifier_decide input contains decision:{id,subject,evidenceId,evidenceRevision,evidenceDigest,acceptanceVersion,evaluatorPrincipalId,verifierAttemptId,verdict,supersedes:null} and rationale. Copy the pins from that envelope, not from producer prose; verdict is accepted, rejected, or human-required. The host publishes the rationale artifact. A changed/stale pin or a producer impersonating B is not a valid decision. requires_human:true retains the operator gate even after independent review; unattended operation does not remove it.
A root proposal is not a physical attempt. In particular, workflow preparation records root-planning ownership and the original operation, policy and input identity without inventing a task attempt or executor fence. Physical allocation requires an actual admitted dispatch and its committed input.
Read-only root enumeration
root_list takes no arguments, mutates nothing and never allocates or grants a root. It answers even while the session's default root binding is ambiguous, which is precisely when the other root-bound tools hold on missing/ambiguous root selector. Use it to recover: read the catalogue, then re-issue the blocked call with an explicit root_id.
Each entry is an allowlisted summary — root_id, status, revision, phase, draft_version, committed_version, has_uncommitted_draft, task_count, attempt_count, hold_count, hold_codes, pending_outbox and last_reconciled_at. Draft bodies, artifacts, owner credentials and executor identities never cross this boundary. A granted-but-unopened scope reports status:"prepared" rather than failing. The response also carries bound_root_id: the root an unqualified call would bind to, or null while that is ambiguous. Workers see only their own single bound root.
Task metadata and DoD
Task create/update, dependency edits and team_add_member can propose work; read tools and /tasks project native state. A reported status:"completed", result text or dod_update passing claim is candidate metadata, not acceptance or permission to integrate. Pending/in-progress intent uses native controls; stop/delete intent does not erase the journal or prove external work stopped. Owner/blocked scheduling intent preserves a manual reservation.
dod_generate supports root-local append/replace catalogs and safe plan slugs, exporting .plans/<slug>/06-definition-of-done.md after the draft receipt. dod_ids associate requirements with criteria; dod_coverage and AGENTS_FLEET_DOD_GATE=off|warn|enforce (default warn) retain the existing coverage checks, not an acceptance bypass. A slug is an export location, not cross-root authority; concurrently changed files are not silently overwritten. New tasks and permitted amendments can be committed after earlier work finishes. Attempted contracts cannot be rewritten, consumed acceptance cannot be amended, and planner edits cannot silently remove manual or human gates.
Local example
Use a clean, disposable local Git repository with an existing commit and a configured Git author identity, and a CLI built from this source. Use Windows or Linux, authenticated Copilot, enabled Fleet worktrees, and a current policy permitting coder/reviewer workers. This example needs no MCP or YOLO configuration; their absence is not a native admission prerequisite. Do not use a planning mode that disallows those types.
agents-fleet --native-root --provider copilot --max-workers 2Paste this as one prompt in the interactive REPL:
Create a native ROOT draft containing exactly tasks A and B. A is agent_type coder with workspace_policy "isolated-worktree" and mergeOnSuccess false. A must create ROOT-DEMO.md containing exactly "Native root demo." followed by a newline, commit only that file, and finish with a clean worktree. A's criteria are: the retained commit adds only ROOT-DEMO.md with that exact content and has no other changes. Set A.verifier_task_id to B. B is agent_type reviewer with verifier_for A and mergeOnSuccess false; evaluate the host-pinned evidence against those criteria and submit the native typed verifier decision before finishing. Use root_prepare_operation for each mutation and preserve returned IDs on retries. Persist the complete draft, show me its root ID, then explicitly prepare and invoke root_plan_commit. Do not request human acceptance, integration, push, cleanup, or any additional tasks.Then use /root list to obtain the full rootId, followed by /root status <rootId> with that returned value. Observe committedVersion, attempt execution/evidence/acceptance, decisionId, effects and holds. An accepted outcome requires A's finished execution, valid evidence and accepted decision plus B's settled verifier protocol. A rejection, missing decision or policy mismatch stays visible; the prompt is not a guarantee of model success. The file is in A's retained worktree, not your checked-out branch: mergeOnSuccess:false intentionally performs no integration.
This is the supported CLI/planner route, not a test-fixture command or a preallocated secret operation ID. From the built source repository, the launch equivalent is node .\dist\index.js --native-root --provider copilot --max-workers 2. For the disposable-repository walkthrough, invoke that built index.js by its absolute path while your working directory is the disposable repository. The native progress proof holds the parent model send at a fake provider transport boundary while real runtime verification proceeds; it does not establish live-model planning quality or recovery from every SDK/UI outage.
Native status and controls
Startup and /status display the execution mode. In legacy mode, /root reports that native controls are unavailable; it never aliases legacy /wf controls or changes execution mode.
/root list
/root status <rootId>
/root pause <rootId> <operationId> <expectedRevision> [taskId]
/root resume <rootId> <operationId> <expectedRevision> [taskId]
/root stop <rootId> <operationId> <expectedRevision>
/root abort <rootId> <operationId> <expectedRevision>
/root release <rootId> <operationId> <expectedRevision> <holdHash>
/root reclassify <rootId> <operationId> <expectedRevision>
/root approve <rootId> --operation <id> --revision <n> --task <id> --rationale "Reviewed the pinned evidence"
/root deny <rootId> --operation <id> --revision <n> --task <id> --rationale "The pinned evidence fails the criteria"
/root manual-start <rootId> --operation <id> --revision <n> --task <id>
/root reconcile <rootId> --operation <id> --revision <n> --proof <nativeProofId> [--task <id>]
/root abandon <rootId> --operation <id> --revision <n> [--task <id>]Replace placeholders; do not type angle brackets. Get rootId, task-local IDs, the current revision, and hold hash from native status. For a new native control choose a unique operation ID (for example pause-local-1); unlike model tool mutations, this does not require root_prepare_operation. Identity strings are 1-200 characters, start with an ASCII letter/digit, and thereafter allow letters, digits, _ . : @ / -. Revisions range from 0 to 9007199254740990 in plain decimal for positional controls (no sign, fractional part or leading zero); use plain decimal for --revision too. Hold hashes are 64 lowercase hex characters. There is no implicit current-root form.
The five flag-based actions use separate flag/value pairs, not --flag=value. Their REPL parser accepts single- or double-quoted rationale text as one value; it is not a shell escape parser. Use the other quote delimiter if the text contains one, or send a JSON socket request. approve/deny require --task and nonempty --rationale; only these verdict actions accept --supersedes <decisionId>, required when replacing a prior decision. They do not accept --proof. manual-start requires a task and accepts neither rationale nor proof. reconcile requires proof, not a rationale. abandon accepts neither proof nor rationale.
Retry an uncertain control with the same operation ID, full input and original revision, even if status has advanced. Identical retries preserve the original request/receipt; changing the input or scope under that ID is a conflict. For a genuinely new request, read status again and use a new ID. Wrong values, unknown IDs, stale revisions and unauthorized scopes fail explicitly. Receipts acknowledge persistence, not completed drain/cancellation. Follow status to distinguish pause-requested from paused, or aborting from aborted. Task-scoped stop/abort (including task-scoped abandon) install a task control hold rather than proving cancellation. Use root-scoped stop/abort for root drain/cancellation intent. abandon maps to stop intent, not to evidence of cessation; unresolved children/effects can remain unknown.
| Hold | Supported response |
|---|---|
| Missing specification | Complete the draft and explicitly commit. Amendments preserve attempted contracts and existing reserved/human gates; unrelated finished tasks do not prohibit new work. |
| Root/task control pause | Native resume, or release of the exact operator-releaseable paused control hold; neither grants acceptance. |
| Manual reservation | manual-start releases only the exact operator-owned, unattempted admission reservation in the committed plan. It neither supplies acceptance nor clears unrelated holds. |
Human acceptance / human-required | Authenticated approve/deny pins the latest finished attempt, valid evidence and criteria version. Independent contracts still require the declared settled verifier; approval is not a shortcut around missing review. Explicit supersession is required for a prior decision and cannot undo consumed acceptance. /root release is not approval. |
| Unknown in-flight attempt, Git crossing or outcome | Reconciliation is evidence-based, never blind replay. The current --proof path resolves an existing native worker-settlement record with matching root/workspace/binding and drained owned children. It is not a file path, report, Git SHA, arbitrary artifact or generic remote/Git repair token. Without such proof, keep the hold. |
| Unsupported policy, rejected evidence/decision | Correct an unstarted plan where permitted, otherwise inspect/escalate. Marking a task verified cannot clear the gate. |
With opt-in --control-socket, the authenticated NDJSON transport also accepts nativeRoot frames (id is transport correlation, request is the native action) and returns nativeRootResult. Native frames are capped at 16 KiB, strictly parsed and bound to the authenticated host principal, not client role labels. Operator preparation/proof resolution is asynchronous; correlate responses by frame id, separately from durable operationId. Local controls and raw named-pipe requests bypass the LLM queue. They still run on the Node event loop: a blocked loop can delay them. This is not a promise that every UI stall, warning-clock issue or RPC problem is fixed.
Host-resolved execution and messaging
Native admission uses the same host worker resolver for roles, multiple skills, the deprecated skill alias, active crew/member selection, model precedence, effective permissions, configured MCP servers and provider settings. It preserves name, agent_type, prompt, task_id, model, cwd, role, skills, skill, permissionOverrides, requiredCapabilities, localArtifacts, completionContract and mergeOnSuccess. Required-capability preflight and structural completion checks still run. Both Copilot and Claude can execute authorized read/write profiles. Canonical coordinator remains nonspawnable; workflow-runner is an internal workflow route, not a public spawn escape. Planning-mode restrictions and read-only verifier policy remain. Explicit role wins over skill; explicit composition wins over crew heuristics. Worker model selection prefers the explicit model, then crew-member model, then role model, before the Fleet fallback. Composition is host-resolved, not an authority claim supplied in the prompt.
The bundled /code-review reviewers return final assistant findings for the workflow coordinator to collect with read_worker_output; their roles do not implicitly require a report-tool receipt. An explicit completionContract.requireStructuredReport: true instead requires successful delivery through report_to_coordinator. Markdown findings alone do not satisfy that contract, and a message acknowledgement is not independent acceptance.
The host appends this explicit per-run requirement to the actual worker system prompt for both providers, after the role and normal final-output guidance. At least one successful delivery during the run satisfies the reporting gate; it does not require a special final report type or coordinator approval. The worker must still return its final assistant output. A silent topology or filtered-out reporting tool makes an explicit reporting contract unsatisfiable and is rejected before provider dispatch, without granting additional tools.
A missing completion requirement is reported as failed once the provider turn and disconnect have settled without pending effects. The failed worker's final text remains available as untrusted output, but read_worker_output returns ok: false. An owned coordinator-prompt workflow drains its descendants and records their failures rather than reporting success. Stage runners retain their existing bounded retry and recovery policies. Lost provider responses, unsettled tools, failed disconnects during contract failure, and unresolved children remain unknown; they are not automatically retried.
Permission precedence is canonical profile, wildcard config, type config, then per-spawn overrides; the highest supplied write scopes replace rather than union. Existing SEC-4 escalation authorization still applies. Explicit and inherited cwd, enabled/disabled worktrees and authorized shared-directory writes are resolved by the host, not granted by workspace_policy. Shared directory effects already happen in that directory; acceptance does not defer or undo those writes. Host-authorized shell/full-trust plus scopes is not categorically rejected, but scopes do not contain arbitrary shell effects. A trusted full-shell attempt is not an OS sandbox or a guarantee that arbitrary detached processes can be contained.
MCP selection keeps the existing rules: coordinators receive resolved fleet servers; without an active crew workers inherit them; an active crew without an MCP declaration gives none; nonempty member declarations override crew defaults and filter against configured servers. Existing stdio/local, SSE and HTTP transports remain provider-resolved. Project MCP trust, project role/skill/crew trust, workflow command synthesis, and project gates/intake trust remain separate settings. Native mode grants none of them.
Already authorized configuration needs no new native acknowledgement. YOLO still needs its existing per-bypass or all-SEC acknowledgements (including supported configuration/environment provenance); it is not a new global bypass. --unattended suppresses blocking interaction, not permission checks or escalation. See YOLO migration. Prepared launches pin composition/source hashes, model, profile, provider/MCP configuration, workspace and host grants; reload/recovery rechecks those pins rather than refreshing authorization behind an existing operation.
Root-origin messages have a root-owned action, not a fabricated worker attempt. Worker-origin reports/messages carry the real sender attempt and topology. Authorized send_message, peer messages and broadcasts retain one durable crossing and delivery/unknown outcome. Queued same-contract turns drain before terminal settlement. A message to a settled worker instead needs a separately journaled and admitted successor, retaining policy/session continuity and remaining deadline/attempt allowance, with a separate verifier when required; it does not reopen acceptance of the old task. Uncommitted unrelated drafts or changed policy can hold that admission.
Permitted workers can prepare and explicitly commit only their own descendant work through Fleet tools; hidden SDK Task/task delegation is not a bypass. Teams and member dispatch retain real physical/session bindings. Coordinator broadcast resolves the entire host-selected recipient set across already granted roots; a foreign recipient fails rather than silently gaining access or being filtered away. Worker scope remains narrower. Safe reads, registry/ configuration tools, reports and attachment effects remain on their existing role-specific catalogs with native ownership. Under Claude, communication/ configuration tools can return root_action_id; retry that same tool/body with the returned ticket and root. Worker views remain read-only.
Accounting and accepted integration
The default root budget is 32 attempts, concurrency 4 (also bounded by the host worker cap), and a four-hour duration. Attempt/concurrency accounting and absolute deadlines persist; pause/restart does not reset elapsed time. Token/cost caps are null (unconfigured), not zero usage or a hard billing guarantee. Numeric token/cost hard caps hold when no bounded meter exists. The execution unit is a whole worker or workflow-child attempt; there is no exactly-once guarantee for individual SDK tools/model steps.
The CLI option --root-integration-target <refs...> requires resolved native mode: fresh sessions opted in with --native-root and saved native sessions can use it, but fresh sessions without the flag, explicit legacy and legacy saved-session resume reject it before startup effects. It does not select a mode or authorize adoption. It accepts a space-separated allowlist of exact local ref names. The planner supplies a selected ref and its full 40-character SHA-1 base in root_integration; model arguments cannot extend host authorization. Without an explicit target list, the host can select its existing unambiguous default merge target for an isolated worker. The Git driver validates the refs/heads/... form with git check-ref-format at execution preflight; the CLI option itself only collects strings.
Only a finished, validated, accepted retained commit can advance the target. An authorized checked-out target, including current main/master, uses the existing local merge under Fleet's repository lock, supporting non-fast-forward history. The nonchecked-out-ref strategy remains fast-forward update-ref compare-and-swap. Remote/symbolic refs and non-SHA-1 commit pins are unsupported. The source branch, exact accepted commit, clean retained workspace, target/base, decision and evidence pins are rechecked. Dirty target state is preserved by refusing integration; conflicts retain the source branch and visible hold. A changed target or uncertain crossing is not blindly retried, and a matching tip alone is not proof of the original operation.
mergeOnSuccess:false retains the worker branch without integration or cleanup. Omitted worker intent can use the default above, but missing/ambiguous target information still holds. Managed and opaque workflow children can supply an accepted retained aggregate commit with an explicit authorized target; they do not require --legacy-workflow-dispatch to integrate. Synthetic workflow commands initially propose retention, not an automatic aggregate merge. See Building Workflows for child contracts.
The local integrator neither pushes nor cleans up worktrees. Existing configured push/PR/handoff operations require their existing explicit authorization and the exact accepted source/evidence before delivery. A lost remote reply remains unknown, not exactly-once remote success. Local Git/MCP/provider fixtures are not certification of real remote services, model quality or universal reliability.
Restart, storage and planning compatibility
Stale-root reclamation
roots.sqlite otherwise grows without bound, and /root reclassify adds an empty root on every policy change. After restore completes, the session runs one best-effort reap pass over the private root database. It is maintenance only: it never transitions, resolves or settles anything, and a failed pass is reported rather than fatal.
A root is deleted only when all of the following hold: it is unowned; it owes no undelivered notification outbox entry; every effect is settled or known-not-dispatched; no attempt is pending, running, cancel-requested or unknown; it is not granted to the live session; and it is past the retention window measured from the newest of lastReconciledAt, usage.startedAt and its created_at stamp. Eligible roots are terminal (stopped, aborted, completed, failed), past their own budget deadline plus grace, or never-started abandoned drafts. A non-terminal root carrying operator-releasable holds is work in progress and is retained. A row with no known timestamp — for example one written before the created_at column existed — is never reaped on a guess. A racing claim/transition, or a foreign table still referencing the root, aborts that deletion and reports it as retained. Pending projection outbox rows are stale read-model refreshes and do not block reclamation.
| Variable | Default | Meaning |
|---|---|---|
AGENTS_FLEET_ROOT_REAP | on | Only an explicit 0/false disables the pass; every other value leaves it on |
AGENTS_FLEET_ROOT_REAP_RETENTION_DAYS | 30 | Quiet age before a reclaimable root is deleted; unparseable or non-positive values fall back to the default |
AGENTS_FLEET_ROOT_MAX_WALLCLOCK_MS | unset (off) | Root duration is metered work-in-flight; set this to ALSO impose a raw wall-clock ceiling on live roots. An explicit 0/false, an unset value or garbage leaves it off |
The wall-clock ceiling is deliberately independent of stall credit: it is compared against usage.startedAt with no credit subtracted. Stall credit itself is never capped — capping it would re-expire roots that are merely waiting on a human or a verifier — so without a ceiling a permanently wedged root accrues credit forever, never reaches budget-expired, and is retained as active indefinitely. When the ceiling is set it applies to both the scheduler's expiry decision and the reaper's budget-expired classification, and /root status reports the earlier of the two deadlines rather than "clock paused".
Deletion removes the root row and its receipts, journal, effects and outbox rows. agents-fleet does not delete, truncate or rewrite any other tool's storage.
Native session saves retain rootRefs and rootSessionId; legacy saves do not add either field or create the private root database. A saved session containing either field resolves native without a mode flag; --no-native-root is refused. Presence counts even for empty/malformed values: valid empty rootRefs:[] restores native ownership, while malformed references, invalid session identities or a missing reference list are refused before composition/migration. This never replays, rewrites or deletes the root journal. A save without native metadata resolves legacy and opens no native resources. Explicit --native-root on such a save is refused; start fresh rather than reclassifying its tasks. Native session resume restores from the authoritative journal under the original workspace/session authorization; changed provider session IDs do not grant ownership of other roots. Native owner fencing and current policy checks still apply. Unknown in-flight work, manual reservations and pauses survive. There is no silent old-session/M0 adoption, task-JSON overwrite of native state, or conversion of legacy completed tasks into accepted work.
Resume refuses an existing Fleet JSON save that cannot be read or decoded as a JSON object, even with an explicit mode flag. The error names the file and read/parse problem without printing saved content. The startup picker leaves such files untouched rather than rebuilding away unknown native ownership from SDK history. Only a genuinely absent Fleet JSON file retains the legacy SDK-only orphan fallback; it is never adopted as a fresh native session. Readable saved state is pinned from mode selection through task/root adoption. Existing transcript-only migration is unchanged; no orchestration migration or automatic repair of unreadable metadata is performed at startup.
Unattempted prepared work is rebound only after current source/profile/grant checks and private owner acquisition. Settled continuations and teams restore their actual incarnation/session identity; uncertain interrupted work is not relaunched from a missing handle. Old native profiles and experimental physical-shaped planning anchors stay visibly held when their identity cannot be established. /root reclassify <rootId> <operationId> <expectedRevision> opens a new empty root under fresh policy; it leaves old attempts, decisions, holds and effects unchanged and requires new proposals/commit. It is not live M0/frontier-shell adoption or a migration of uncertain work. The command output leads with the new rootId, the unchanged previousRootId, whether the open actually persisted (opened) and whether the session's default binding moved (sessionRebound). A durable open rebinds the session to the fresh root, so later unqualified planner calls no longer wedge on two grants; the old root stays addressable by explicit root_id//root status <rootId>. If opened is false, nothing was rebound and the session still uses the previous root.
To restore either mode, use its normal --resume <sessionId> route or select the save in the --resume picker. Cancelling the picker or selecting its new-session entry starts fresh (legacy unless explicitly opted in with --native-root). To restore native state, keep the original workspace and journal available. Do not remove native metadata to force legacy restore or truncate Copilot host logs to force SDK resume; the oversized-host-log guard still applies, without a fresh-conversation fallback. Starting a fresh session is a separate continuity choice, not recovery of the old conversation.
After positive owner acquisition and workspace/session/source-grant checks, production reconciliation can reclaim strictly older-generation pre-intent reservations in indexed pages of at most 64 rows. Reclamation requires no matching snapshot attempt, retained effect or native pre-effect budget permit; the original admission deadline and root epoch remain intact. Same-generation reservations and unknown/effected work are retained. This is not a blanket reset of preexisting capacity holds or manual/user gates.
Correctness uses a dedicated private SQLite journal, separate from optional intelligence and bounded forensic logs. The host protects its dedicated directory/files with POSIX permissions or current-user-only Windows DACLs. Journal artifacts and references are unredacted, and storage also contains private owner credentials; do not publish the database or raw artifacts. This protection does not retroactively secure ordinary transcript/forensic files. Forensic retention limits are not correctness-state retention or an authoritative replay source. Native owner identity currently supports Windows and Linux; unavailable storage/ownership holds mutations, without legacy fallback.
The existing grill/DoD guidance remains useful for requirements: skip ceremony for ordinary chat, self-grill mechanical work, and ask bounded questions for novel work (self-answered assumptions under unattended operation). But native acceptance requires the contracts above. DoD authoring/coverage is available, but DoD/report text cannot accept work. Correctness journaling is independent of best-effort forensic capture, and native progress is not a claim that all watchdog warnings or external RPC stalls have been fixed.
See Building Workflows for child eligibility and Composition for the separation between prompt guidance and runtime authority.