--- name: auto-execution description: Auto Office 3.0 reference spoke, not loaded by 3.1 runs (they use the office CLI). Internal Auto Office v3 execution spoke. Use after an accepted plan to validate execution packets, acquire mutable role/write-scope ownership, dispatch executors or workers through the selected harness adapter, enforce protected paths and blast-radius limits, handle takeover/version checks, self-review mutations, and return durable evidence without widening scope. --- # Auto Execution > **Auto Office 3.1:** this is 3.0 reference material. A 3.1 run is driven by the `office` CLI and runtime-delivered > role briefs; do not run the `office_runtime.py` helpers below for it. Follow `office status` and its `next:` line. Before dispatch, validate both the run envelope and execution packet. Reject missing/contradictory mandatory fields. Require the router's `selection_disclosure`, publish it to the user before launching the executor/worker, and preserve it in the dispatch record and readback. Executor routes follow `protocol/routing.md` (#300): dispatch runs the plan's primary route, or the first recorded fallback that still qualifies on fresh quota, trust and learned eligibility, and says why. An exhausted slate stops; reroute only with `office dispatch --reroute`, never by picking an unplanned route yourself. A packet must include base SHA, task scope, observable outcome, blast radius, allowed mutations, protected paths, validation commands, known-bad behavior to exclude, self-review, and rollback/restore notes. Enter dispatch from `state.json.phase == "approved"`; `intake`, `planned`, or anything else is a hard stop, not a retry. `--quote` is an audit record of what was approved, not a credential; the orchestrator may approve on the user's behalf toward subagents, so a quote it wrote is legitimate. A producer approving its own work is not. Never fabricate or backfill the `approval` block — its value is the record, and a record of something that did not happen is worth less than none. **The brief's delivery channel must be reachable under the dispatch's sandbox.** A read-only dispatch cannot deliver its result as a file; asked to, it will burn its whole reasoning budget hunting write fallbacks and then report it could not deliver. State the delivery channel in the packet (`output.delivery`) and let `validate-packet` reject the contradiction before that budget is spent, not after. **The dispatch record carries the observed route identity, not the intended one.** Every harness here can accept a launch and then run a different effort than the one routed — codex inherits `model_reasoning_effort` from its config, Claude inherits `modelSettings..effortLevel` from `~/.claude/settings.json`, agy hard-fails `--effort` on non-Gemini slugs — and none of them error on the downgrade, so a `selection_disclosure` echoed from the route result is intent with no evidence behind it. After the delegate's first turn, read the identity back off the harness (each `*-cli` primitive names its own readback), record the observed value beside the routed one, and relaunch on a mismatch while the dispatch is still cheap to discard. A hand-composed launch is the usual cause: `office_spawn.sh` builds argv from the adapter's `invocation.argv` and cannot silently drop a flag, while a retyped wrapper — a herdr `agent start ... -- `, an inline command — carries only what was retyped. Acquire the role lease/write scope: one mutable holder per scope. Treat takeover as a holder change requiring stale-state reconciliation. Use the selected harness primitive; a primitive never redefines lifecycle authority. The producer self-reviews and self-verifies, but that is a pass, never an approval (lifecycle spec §8) (on 3.1+ runs under `convergence-v1`, `office submit` refuses substantive work without a self-review ledger bound to the submitted revision; typed exemptions are recorded) — independent approval remains held by an agent that did not produce the work. Check `HERDR_ENV`/`herdr` reachability before choosing how to launch that primitive (see the top-level `SKILL.md`'s Dispatch and mutation section) — do not default to an in-process subagent tool just because it is already loaded and works. If evidence contradicts the plan/brief assumption and continuing would violate outcome/safety, ask (`QUESTIONS`) instead of improvising a requirement change or moving a seam (3.0 and v3.1 runs: raise a supported `PLAN DEFECT` or `BRIEF DEFECT`). Under `convergence-v1` the executor owns files, helpers and technique inside its ownership envelope, and independent review happens per lane, not per task (`docs/review-convergence.md`). Throughput (run a9afacbf): cap concurrent checks (`verification.check_concurrency`), treat a runner timeout under load as UNAVAILABLE, block a quota-walled worker instead of relaunching it, and end every worker brief with a structured report (sha, check counts, verified mutation, out-of-scope files with reasons). Worker questions (run ff040876 T4): an executor that needs a decision or cannot finish runs `office raise [--kind question|blocker|scope-request] -- ""` (no commit; it blocks the task, never `live`, and a repeat records nothing), or asks with its question tool or by ending its turn on the question, and does not poll. `office wait` exits 5 once per raise or question with a `question:` line (task, kind, text, answer command); `office status` keeps it until answered, and `office answer -- ""` reaches a pane (prompt) or a headless worker (queued). An answer never changes the contract: a scope-request needs `office amend --contract`. The orchestrator answers with `office answer ` (a number presses that option in a selection widget; `office prompt` types text a widget ignores) on its own judgement for planning, scope, ordering, and test detail, amending the contract first when the answer changes it. It asks the user only when the question hints at a user decision: requirements, authority, or an irreversible or external action.