Learning path map
Detailed content
🚦 Autonomy policy
POLITICA.md: five levels of autonomy, a limit for each type of action, and how Claude Code and Codex apply the same rules.
N0 only talks, N1 prepares and the human executes, N2 executes after asking, N3 executes and notifies, N4 executes without notifying.
It’s the scale that determines how much the agent can do without you. The kit’s default is “prepare and ask.”
Autonomy, N0–N4, prepare and ask, impact of the action.
The POLITICA.md table: reading goes up to N4, modifying files up to N3, system commands and sending up to N2, and spending and deleting only at N1.
The greater the impact of the action, the more you participate. The table determines this before the agent starts.
Limit, action type, send, spend credits, delete with a backup.
The rule in POLITICA.md: a "always allow" permission never exceeds the action limit.
One hasty click must not turn "send" or "delete" into an automatic action.
Always allow, ceiling, accumulated permission.
The kit's .claude/settings.json blocks rm -rf, git push --force, git push -f, and git reset --hard.
In CHANGELOG 0.1.0, even in the mode that allows everything, touch ran and rm -rf was denied.
Permissions, deny, acceptEdits, written block.
In Codex, the policy becomes a sandbox: read-only to read, workspace-write to make changes, and no auto-approval for everything else.
The codex-exec.sh bridge rejects danger-full-access: the same rule applies to both agents.
Sandbox, read-only, workspace-write, refusal due to POLICY.
Only official tools through the subscription, never pass credentials from one tool to another, reverse engineering only in a lab.
These are the three lines that protect your account and your data when connecting one tool to another.
Subscription, credential, LIMITES.md, production.
📚 The agent proposes, you approve
The kit's learning cycle: the Aprendizado table, the AGENTS.md Lessons, FALHAS.md, and LIMITES.md, one line at a time.
The AGENTS.md rule: the agent doesn’t change the rules; to propose a change, it adds a row to the Aprendizado table.
An agent that rewrites its own rules may give itself more freedom than you allowed.
Proposes, approves, incorporates; separation of roles.
Date, what happened with evidence, one-line proposal, and status: proposed, approved, or rejected.
You can approve a proposal with evidence in seconds; without evidence, you can't decide.
Evidence, one-line proposal, status.
What you approve becomes a rule in the Lessons section of AGENTS.md, which Claude and Codex read.
The lesson applies in future sessions for both agents, without you having to repeat it.
Lessons, AGENTS.md, CLAUDE.md, approved rule.
Date, what broke, the smallest fix, and whether it was a prompt or infrastructure issue. Real example from the kit: the doctor read only Codex’s stdout.
After a few lines, the pattern emerges, and you stop rebuilding what only needed a safeguard.
Smallest fix, prompt × infrastructure, one line.
Date, what was attempted, what blocked it, the workaround, and the status. Bugs go in FALHAS.md; environment limits go here.
Quota, permission, or network blocks don’t disappear on their own: once recorded, they become a list to resolve.
Environment limitation, workaround, open or accepted status.
Once a week, the agent reads FALHAS.md and LIMITES.md and proposes entries for the Learning table; you approve or reject them.
It’s the “learn” step of the cycle becoming a habit, without taking the decision away from you.
Weekly review, failure patterns, approve or reject.
🧱 Guard and panel
Recipe R7: official hooks that ask before stepping on another session’s work or deleting too much, and the team dashboard in the background.
Mod is the nickname for official plugins. The guard uses PreToolUse and PostToolUse hooks: the rule lives in the script, the interface in the mod.
The videos showed collision and blast-radius guards; the kit does the same using only official features.
Hook, plugin, mod, PreToolUse, PostToolUse, worktree.
Before editing a file another session has touched, or that changed externally in the last 30 min, the guard asks: continue, worktree, or cancel.
In one of our projects, one session emptied a file another was editing.
Collision, toques.json, 30-minute window, Codex limit.
Before rm or git clean, the guard counts the files that would be deleted, shows their size, and asks for confirmation.
The R7 proof runs the script on its own and shows "permissionDecision":"ask" without deleting anything.
Blast radius, disk read-only, backup.
claude --plugin-dir for one session, or the hooks block copied into the other project's settings.
The protection applies wherever your agents work, not just in the kit’s folder.
--plugin-dir, hooks block, kit path.
An optional mod that shows claude --bg sessions with Refresh and Stop buttons.
Monitor and stop the team without leaving Claude Code; just your click for a session.
Panel, plugin validate, plugin test, 1 pass.
Mods run with Claude Code permissions. Before installing a third-party one, ask the agent to read and explain it without running it.
The same power that protects can cause damage: reading the code is the only guarantee.
plugin.json, hooks.json, network, credentials.
🧪 Lab and final project
The right place for reverse engineering, and the project that wraps up the course: a system of your own without an API becomes a bridge, a team works on it, and the verifier proves it.
Before any reverse engineering, test each level with one command, from API to local bridge.
Often the route exists; it just wasn’t documented.
Ladder, evidence by level, rung 7.
Test machine, one line in LIMITES.md, "fragile" label with date, and never in production.
The lab answers “where does it communicate?”; the answer leads back to an official route.
Test machine, LIMITES.md, fragile, production.
Only official tools through the subscription, and never pass credentials or a token from one tool to another.
Whoever has the token acts as you; the right bridge doesn't carry a password.
Credential, token, terms of use, human login.
A system of your own without an API, one line in CAPACIDADES.md, and the highest-level path that works.
Without an entry in the map, the agent won’t use the system; it’s the first step in the final project.
Final project, CAPACIDADES.md, via, pending.
The bridge through recipe R3 (file) or R5 (site), with the three-role team working on it under N2 policy.
It’s the whole course applied to your work: connect, route, and execute with rules.
Bridge, selftest, Connected, planner, executor, reviewer, N2.
One goal with command → expected criteria, the output from verificar.mjs with all OK, and one approved row in the Aprendizado table.
Done means proof, not a guess; and the cycle only closes when learning becomes a rule.
Goal, verificar.mjs, delivery checklist, Lessons.