Copyable kit · Claude Code + Codex · through your subscription

Your agents using the tools you already have

A runtime/ folder that teaches Claude Code and Codex to discover, connect to, and use your systems, with clear rules on what they can do on their own. No server, no paid API.

INEMA Agent Runtime banner: agents using your tools through your subscription and with a permissions policy
What it is

A kit, not a platform

Four policy files, diagnostic and verification scripts, bridges, a guard, and 7 tested recipes. Copy them into your project and your agents will follow the same rules. The files inside runtime/ are written in Portuguese; your agent reads them and answers in your language.

The kit's building blocks: access ladder, capabilities, policy, routing, MCP bridge, and recipes

🪜 Access ladder

Before saying "impossible," the agent climbs the ladder API → MCP → CLI → SDK → computer use → local bridge and uses the most stable available path.

🛡️ Permissions policy

Reading is unrestricted; it changes files and tells you; sending requires asking first; spending money or deleting data is prepared only. .claude/settings.json already blocks rm -rf.

💳 Through your subscription

Uses the Claude Code and Codex CLI you are already logged into. No paid API is required. Ollama local models are optional.

How it works

The runtime cycle

Each step has a file. Every action passes through POLITICA.md.

Discover→ Connect→ Route→ Execute→ Observe→ Verify→ Learn
1

CAPACIDADES.md

Tool map: one line per system, with the access path, level, and test date. A system without an entry is not used.

2

POLITICA.md

Autonomy levels N0 to N4 and the ceiling for each action type. "Always allow" never exceeds the ceiling.

3

ROTEAMENTO.md

Which model for which task (super, top, executor, smaller). Start with the smallest model that can handle it.

4

LEIA-ME.md

The cycle, the getting-started order, and the access ladder with examples.

The access ladder (use the highest available level)

LevelPathExampleStability
1Official APIERP APIhigh
2MCPclaude mcp listhigh
3CLIcodex exec, gh, githigh
4SDK / librarynpm/pip packagemedium
5Computer useautomated browser, on-screen clickslow
6Local bridgeCSV export, folder, SQLite database, local portmedium
7Reverse engineeringobserve the app running to find the access pathlab only: breaks at the next update

Ceiling by action type

ActionCeilingIn Claude CodeIn Codex
Read a file, page, or spreadsheetN4allowed-s read-only
Create/change a project fileN3acceptEdits-s workspace-write
Command that changes the systemN2asks for confirmationno auto-approval
Send (email, message, post, push)N2asks for confirmationno auto-approval
Spend money or creditsN1blockeddo not execute
Delete data / productionN1 + backupblocked (rm -rf)do not execute

N0 only chats · N1 prepares and the human executes · N2 executes after asking · N3 executes and tells you · N4 executes without notice. The agent does not change its own rules: it proposes a row in the "Learning" table of POLITICA.md, and you approve it.

Prerequisites

What needs to be installed

Linux or Mac. On Windows, use WSL. The diagnostic only reads local versions and status: it does not call a model or API.

Node 18+

Runs the diagnostic, the MCP bridge, and the observe and verify scripts.

node --version

Claude Code and/or Codex

At least one of the two, logged in through your subscription.

npm i -g @anthropic-ai/claude-code
npm i -g @openai/codex
codex login

Ollama (optional)

Free local models for lightweight tasks. The diagnostic shows whether it is installed.

ollama --version
User guide · step by step

From clone to your first agent team

Each recipe ends with proof: a command and the output that should appear. If the proof does not match, the step is not ready.

1

Copy the kit and run the diagnostic

Shows what is installed and logged in: Node, Claude Code, Codex, and Ollama.

git clone https://github.com/inematds/inema-agent-runtime meu-projeto
cd meu-projeto
node runtime/scripts/doctor.mjs   # proof: PRONTO at the end
2

Fill in the capabilities map with the agent

Open claude (or codex) in the folder and ask it to climb the ladder level by level. Only add an entry after a test has passed.

# inside claude or codex:
Read runtime/LEIA-ME.md and help me fill in CAPACIDADES.md for my work.
3

R1 · Claude uses Codex

CLI bridge (level 3). By default, Codex only reads; changing files (N3) requires passing workspace-write.

chmod +x runtime/pontes/codex-exec.sh
runtime/pontes/codex-exec.sh "Reply with PONG only"   # proof: PONG
runtime/pontes/codex-exec.sh "Create notas.txt with the word OK" "$PWD" workspace-write
4

R2 · Three-role team

Planner (opus), executor (sonnet), and reviewer (haiku), defined in .claude/agents/. Each uses the model it needs, so you get more out of your quota.

claude -p "Use the team (planner, executor, reviewer). Task: create saudacao.txt with the sentence 'Olá, comunidade INEMA'. Finish with the reviewer's response."
# proof: saudacao.txt contains the sentence and the response ends with APROVADO
5

R3 · MCP bridge for a system without an API

The ERP or calendar exports a file; the bridge reads that file and provides it to the agent as a read-only tool. Dependency-free MCP server, already registered in .mcp.json.

node runtime/pontes/mcp-modelo/server.mjs --selftest   # proof: tools: 2 and TOTAL: R$ 856.00
claude mcp list                                         # ponte-modelo … Connected
codex mcp add ponte-modelo -- node "$PWD/runtime/pontes/mcp-modelo/server.mjs"
6

R4 · Team in the background

Several Claude sessions at once, each with a name, role, and model. Mark the folder as trusted once. Each session uses your quota.

claude --bg --permission-mode plan --name reviewer "Read runtime/POLITICA.md and answer in one line what the ceiling for 'Enviar' is."
claude --bg --model sonnet --name executor "Create resumo.md with 3 lines about what this kit is."
node runtime/scripts/observar.mjs   # table with id, type, name, and state
7

R5 · Browser with a policy

For systems that exist only as websites. Reading a page is N4; filling in or sending requires asking first; never make payments.

npm i -g agent-browser
agent-browser install
agent-browser open https://example.com
agent-browser get title   # proof: Example Domain
agent-browser close
8

R6 · Long-running agent with verification

The agent only finishes when the goal's command → expected output criteria pass, not when it thinks it is done.

node runtime/scripts/verificar.mjs runtime/exemplos/goal-exemplo.md
# proof: 4/4 criteria OK and exit 0; break a criterion and the line becomes FALHA
9

R7 · Guard and dashboard

With several agents running at once, the guard catches two risks before they happen, and never decides on its own: it asks (N2). Collision: before editing a file another session edited, or that changed externally (Codex, editor, another person) in the last 30 min. Blast radius: before rm or git clean, it shows how many files would be deleted, their size, and the first paths. It is already enabled in this kit through .claude/settings.json; to bring it to another project, use one of these methods: the command below or copy the hooks block from .claude/settings.json and change the path.

# guard in another project (this session only)
claude --plugin-dir /caminho/do/kit/runtime/mods/runtime-guarda
# optional dashboard: in the session, type /painel
claude --plugin-dir runtime/mods/runtime-painel
claude plugin test runtime/mods/runtime-painel   # proof: 1 pass

The dashboard lists claude --bg sessions (name, state, minutes), with Refresh and Stop: only your click stops a session. INEMA_COLISAO_MIN=60 changes the collision window. Codex does not yet have an equivalent "before editing" hook: collision protection covers Claude sessions and detects edits made by Codex through the file date.

Examples

From the office to the clinic

The example files in runtime/exemplos/ simulate the community's two most common cases: a system without an API that exports a spreadsheet.

🧾 Accountant with an ERP without an API

The ERP exports a sales CSV. The bridge exposes the resumo_vendas tool; the R2 team puts together the summary and the reviewer checks the totals.

# runtime/exemplos/erp-vendas.csv
data,cliente,produto,quantidade,valor_unitario
2026-10-01,Mercado Sol,Café 500g,10,18.50
# bridge selftest → TOTAL: R$ 856.00

🩺 Clinic with a spreadsheet calendar

The schedule lives in a spreadsheet. The listar_horarios_livres tool returns only livre rows, filtered by date and professional.

claude -p "Use the listar_horarios_livres tool from ponte-modelo and list the free appointment times for 2026-10-07."
# proof: 08:00 (Dra. Ana) and 16:00 (Dr. Bruno)

To use it with your system: set PONTE_DADOS=/caminho/da/exportacao in the env field of .mcp.json, change the columns used in run(), keep the tools read-only, and note the bridge in CAPACIDADES.md with the test date.

Roadmap

Phases, each with proof

Each phase closes only when its proofs pass. The proofs run for each version are listed in CHANGELOG.md.

Phase 1
Minimal kit · 0.1.0 · readyFour convention files, diagnostic, codex-exec.sh bridge, R1 and R2 recipes, and blocks in .claude/settings.json. Proofs run on Linux through the subscription.
Phase 2
Bridges, observe, and verify · 0.2.0 · readyDependency-free MCP bridge, observar.mjs, verificar.mjs, and recipes R3 to R6.
Phase 3
Guard and dashboard · 0.3.0 · readyruntime-guarda mod (collision and blast radius, already enabled in the kit), optional runtime-painel mod with /painel, and recipe R7.