diff --git a/docs/agent-lifecycle/agent-hierarchy.md b/docs/agent-lifecycle/agent-hierarchy.md index e3b484d3..e9d7d7c6 100644 --- a/docs/agent-lifecycle/agent-hierarchy.md +++ b/docs/agent-lifecycle/agent-hierarchy.md @@ -131,17 +131,6 @@ Manager}` switch picks the MCP tool allow-list claude sees. Both are injected uniformly via `systemd.globalEnvironment` for every container including the manager, so all token/state paths resolve through it the same way everywhere. -- **Scattered ownership checks** — a handful of independent -manager-only overrides exist across `hive-c0re` today: `destroy` -refusing to act on the manager, and crash-watch skipping -the manager (it autorestarts via systemd instead of going through -the crash-watch loop). Each is planned to become a capability -check instead of a manager-name check — see the -module docs for `stores/broker.rs`, `actions.rs`, -and `workers/crash_watch.rs` for the current owner-check logic in -each. (The harness handles reminder cancellation fully in-agent — see -the note on `CancelLooseEndKind::Reminder` in -`hive-c0re/src/socket_server/mod.rs`.) None of the above is a stable interface — treat the module doc