Guth architecture · one real handoff, end to end

You ask once. Your staff handles the handoffs.

Ask for today's Instagram post. Rebecca owns social. If the publisher breaks, she pauses the post, calls Stan, and resumes with the repair—while you stay in the same conversation.

Follow this request

A scroll story showing how bounded workers, durable records, configured authority, and inspectable evidence keep one agent focused and accountable.

00 — The request

“Post the carousel” sounds simple. The work underneath crosses several jobs.

Old pattern

Push one model through everything

Make one chat remember the brief, write the post, debug the publisher, hold the approval rules, and recover every old decision after each compact.

Guth pattern

Let each specialist own a lane

Rebecca keeps the social work. Stan keeps the engineering work. The point guard moves the result between them and preserves the trail.

01 — The point guard

One point guard stays with you. Each specialist owns a job.

You do not have to choose a model, window, or machine. The point guard knows who owns the work and gives that specialist only the task, files, and authority the job needs.

  • Recognizable jobs. Website work goes to Willa, social to Rebecca, research to Tilly, and system repair to Stan.
  • Less repeated context. Each person works from a smaller field record instead of crowding every source, tool, and decision into one window.
  • They pick up where they left off. Reopen Rebecca and the same drafts, schedule, corrections, and receipts return. Stan resumes from engineering history—not a blank prompt.
The names make the routing easy to understand; the saved lane records make it possible to resume the work without rebuilding the whole conversation.

02 — A real specialist handoff

Rebecca finds the problem. Stan repairs it. Neither starts over.

This happened inside Guth on July 23. Rebecca had the social assets staged when she found the publisher was treating image slides like video. She held the post and called Stan instead of guessing around the failure. The alert crossed from her Codex task into Stan's active Claude task while he was already working another lane.

  • A worker is not a tool call. Stan decides what to inspect, uses bounded tools, repairs the system, verifies the result, and returns the repair with evidence.
  • The lane persists. The point-guard window can compact or change models; Rebecca's social state and Stan's engineering state resume from their own saved records.
Rebecca · social mediaSocial desk · Codex
Saved work state loadedToday's carousel · copy + slides staged · approval still required
Tony

Can we get the Instagram carousel out today?

Rebecca · social media

I found the blocker before approval. The publisher is treating the image slides like video, so I'm holding the post and calling Stan.

Repair request to StanFix the image handoff without weakening approval, no-retry, or read-back checks.Assets stay staged · no publish authority transferred
Stan · engineeringRepair desk · Claude
Saved engineering state loadedPublisher runbook · prior gate tests · no posting authority
Stan · engineer

Received while I was on another task. Keep the draft staged. I'll repair the publisher without bypassing the gate.

  1. Reason

    Reproduce the failed image handoff before changing code.

  2. Pull tools

    Open the publisher, failure record, media server, and test suite.

  3. Act

    Fix PNG handling without weakening the approval boundary.

  4. Return

    23 of 23 checks pass. The post is still held for Tony.

Repair returned to RebeccaImage handling fixed · invalid cross-posts still fail closedTest receipt attached · production unchanged
Rebecca · same social lane

Repair received. I'm back in the same carousel, with the draft and schedule intact. I'll restage Instagram only, then send the exact post to Tony for approval.

Point-guard windowcompact · switch model · reopen
Rebecca's social lanefrozen · resumed with the same draft
Stan's engineering lanefrozen · resumed with repair history
Public-safe, plain-language reconstruction of a real internal handoff. Internal paths and message IDs are removed. “Frozen state” means the specialist resumes from a durable brief, approved sources, prior decisions, corrections, and receipts—not perfect memory or added authority. Named runtimes describe this run; a second model is not independent proof by itself.

03 — Source-linked memory

When Rebecca returns, the draft and repair are still attached.

Her social lane keeps the brief, assets, schedule, hold decision, Stan's repair receipt, and Tony's approval state in one source-linked record. The next visit starts from the relevant state—not a retelling of the whole chat.

  • Sources stay attached.
  • Events stay in order.
  • Missing evidence is qualified, withheld, or reviewed.
Brief + assetsdraft + schedule + decision
Saved lane recordrepair + source + time attached
Same worker resumesonly what the social job needs
The worker reloads the approved record for its field even when the model window compacts or changes.

04 — Challenge retrieval

Retrieve to answer. Retrieve again to challenge the answer.

The approved record that helps a worker answer can also reveal why a candidate should not pass. Guth examines its support, governing evidence, freshness, contradictions, and authority before the work advances.

Retrieval supplies evidence. It is not truth, and it never grants permission. A verifier, reviewer, or configured gate decides the disposition.

Candidate answerbuilt from approved context
Challenge evidencecontradictions + current policy
Explicit dispositionnamed decision + reason
ContinueorStop
AcceptQualifyRepairEscalateWithhold
Guth can retrieve for support and retrieve again for rejection. The evidence informs the decision; it does not make the decision by itself.

05 — Change control

If the setup changes, this request gets a new setup ID.

Sources, memory policy, tools, runtime, and test versions are bound to one manifest. Change any part and the digest changes, so the old and new setup cannot silently look the same.

Important: a matching digest shows that the recorded bytes match. It does not prove a claim is true.

Sources + memorytools + runtime + tests
Manifest digestone setup ID
SameorChanged
The digest makes configuration changes visible. Permission remains a separate gate.

06 — Permission gates

Before anything leaves the system, the right human gate applies.

A protected action can stop at the Desk until an authorized person approves the exact action. The customer can make the gate stricter as the consequence rises, and the decision becomes part of the receipt.

The approval record can be a plain confirmation, a typed allowance naming the action and limit, or—when separately integrated—a signed authorization.

Requested actionexact effect
Desk gateauthorized person
Approval recordmethod agreed in scope
PermitorWithhold
Choose an illustrative consequence tierControlled
Illustrative consequence tiers
Selected gateRetyped scoped phrase
Record keeps
Exact phrase, named limit, authorized person, and expiry.
Still withheld
A changed version or wider effect requires a new approval.

Illustrative policy mapping. The actual approval method is separately scoped, integrated, and tested.

The approval method is separately configured and tested for the customer's consequence policy. Identity and memory never grant permission.

07 — Receipts and status

The answer returns with what happened and why.

Receipts record the exact work in order. They preserve the runtime, sources, decisions, permissions, and evidence state so the record can be inspected later.

A certificate commits to one scoped manifest and evidence state. The resolver reports whether that state is current, expired, superseded, or revoked.

Exact workwhat the agent did
Ordered receiptssources + decisions + permissions
Current statusUNISSUED
The certificate describes one disclosed evidence state—not the person, company, provider, or platform as a whole.

The model is swappable.

The evidence system is the product.