OSWork v6.2 · 8 modules · lessons of about 15 minutes
From chat to your agents environment, one short lesson at a time. You organize files, teach procedures to the AI, and build routines you can check. Each lesson ends with the complete material on the topic for people who want to go deeper.

Compare models with a real task and a quality criterion.
Write a work order with inputs, output, and review.
Open a training project in Codex and produce a verifiable change.
Build the digital house and separate knowledge from credentials.
Create project instructions and a reusable capability with a review criterion.
Save a version, inspect differences and recover a training change.
Run a restricted query bot and understand where AI comes in.
Prepare a deployment plan, monitoring, backup and service verification.
OSWork v6.2
The course’s technical terms in simple words. Each term links to the lessons where it appears.
AI that runs multiple steps on its own, like reading files, creating and comparing, instead of just responding to a message.
Shown in: Lesson 5 Lesson 6 Lesson 8 Lesson 9 Lesson 11 Lesson 12 Lesson 16 Lesson 17 Lesson 18 Lesson 20 Lesson 24 Lesson 25 Lesson 26 Lesson 27 Lesson 28 Lesson 29 Lesson 30 Lesson 31 Lesson 32 Lesson 37 Lesson 41 Lesson 42 Lesson 48
Markdown file with the instructions that the agent reads before working in a folder: rules, limits, and how to verify.
Shown in: Lesson 16 Lesson 17 Lesson 18 Lesson 19 Lesson 24 Lesson 25 Lesson 26 Lesson 27 Lesson 29 Lesson 30
AGENTS.override.md file: when it’s in the same folder as an AGENTS.md, the Codex reads the override and ignores the AGENTS.md from that folder.
Appears in: Lesson 26
Entry point for a program to use an AI service without going through the chat screen. API usage is charged based on consumption.
Appears in: Lesson 5 Lesson 6 Lesson 15 Lesson 37 Lesson 41 Lesson 42 Lesson 43
A file that Git already includes, because it was added from some saved version. .gitignore doesn’t apply to it.
Appears in: Lesson 23
A test that the kit’s own bot runs without Telegram and without internet, with fake messages, to check your rules.
Appears in: Lesson 42
A security copy of files, stored somewhere else so you can recover if something gets lost.
Terminal command language on Linux and macOS. The commands in this course are written for it.
Appears in: Lesson 13 Lesson 16 Lesson 18 Lesson 19 Lesson 24 Lesson 31
A program that talks through a messaging app and responds on its own, following the rules you set.
Appears in: Lesson 36 Lesson 37 Lesson 38 Lesson 39 Lesson 40 Lesson 41 Lesson 42 Lesson 43 Lesson 45 Lesson 46 Lesson 47 Lesson 48
The official Telegram account that creates bots and generates each one’s token.
A parallel line of work in Git, where you test changes without touching the main version.
An address for a folder or file, with the names separated by slashes, like ~/projetos/config.
Appears in: Lesson 5 Lesson 9 Lesson 14 Lesson 19 Lesson 24 Lesson 26 Lesson 37 Lesson 42 Lesson 47 Lesson 48
A long password that identifies who uses the API and which account it belongs to. Never put it in a request, in a shared file, or in a screenshot.
The public half of an SSH key pair. It’s registered on the VPS; the other half, the private key, stays only on your computer and is never pasted anywhere.
A command that defines who can read or change a file.
A copy of a GitHub repository onto your computer, with all its history.
An OpenAI programming agent that works inside a folder on your computer, using the terminal. The course installs it in module 3.
Shows up in: Lesson 3 Lesson 5 Lesson 12 Lesson 13 Lesson 14 Lesson 15 Lesson 16 Lesson 17 Lesson 18 Lesson 19 Lesson 25 Lesson 26 Lesson 27 Lesson 28 Lesson 29 Lesson 30 Lesson 41 Lesson 45 Lesson 48
Saved version in Git, with a message that explains the change. You can go back to it later.
Shows up in: Lesson 23 Lesson 31 Lesson 32 Lesson 33 Lesson 34 Lesson 35 Lesson 36
Terminal of the VPS opened by the provider’s panel, in the browser, without SSH. It’s the way back when SSH fails.
The material the AI receives to do a task: the files, the instructions, and the information you point it to.
Shows up in: Lesson 9 Lesson 11 Lesson 19 Lesson 24 Lesson 30 Lesson 34
The full order, with six parts: goal, inputs, result, limits, verification, and stop.
Five lines you write before connecting an AI to a bot: sent data, model, cost limit, max time, and what to do if the AI fails.
Shows up in: Lesson 41
A plain-text spreadsheet, with values separated by commas. Opens in Excel or Google Sheets.
Shows up in: Lesson 21 Lesson 25 Lesson 26 Lesson 27 Lesson 29 Lesson 30 Lesson 37 Lesson 40 Lesson 42 Lesson 48
ChatGPT app on your computer, which works closer to your files and can read the folders you allow.
Comparison that shows, line by line, what changed in a file.
Shows up in: Lesson 18 Lesson 32 Lesson 35 Lesson 36 Lesson 48
Another name for folder, used in the terminal.
Shows up in: Lesson 18 Lesson 26 Lesson 30 Lesson 41 Lesson 47 Lesson 48
Work request that states what must exist at the end: goal, inputs, output, limits, and stopping point.
File that stores keys and passwords outside the code. Never goes to Git, to a request, or into a screenshot.
Appears in: Lesson 15 Lesson 22 Lesson 23 Lesson 24 Lesson 33 Lesson 36 Lesson 38 Lesson 39 Lesson 40 Lesson 42 Lesson 46 Lesson 47 Lesson 48
A copy of the .env with the same variable names and fictional values. It shows what you need to fill in without giving access to anything, so you can share it.
Appears in: Lesson 22 Lesson 23 Lesson 24 Lesson 38 Lesson 42
Work that runs on your own computer. It depends on it being turned on, with a network connection, and with the right permissions.
Appears in: Lesson 10
A short document where you write down how an AI task works: tools, access, decisions, and pending items. It can be a note on your phone. In module 4, it becomes a file in the project folder.
Filter that decides which network connections can enter the machine or leave it.
Program that keeps the history of the versions of a project folder: what changed, when, and why.
Appears in: Lesson 18 Lesson 23 Lesson 30 Lesson 31 Lesson 32 Lesson 33 Lesson 34 Lesson 35 Lesson 36 Lesson 45 Lesson 46 Lesson 48
Website where you store a copy of your Git repository on the internet, so you can work from another computer or with other people.
Appears in: Lesson 31 Lesson 33 Lesson 34 Lesson 35 Lesson 36
File that lists what Git should not store, like passwords and temporary files.
Appears in: Lesson 22 Lesson 23 Lesson 24 Lesson 33 Lesson 36 Lesson 46
In Git, the version you’re on right now.
Appears in: Lesson 35
A fixed number that Telegram assigns to each account. It doesn’t change when the person changes the displayed name.
Short sequence that identifies the VPS. On the first connection over SSH, you check whether it matches the one the VPS provider tells you.
To put a program on your computer so it can be used. Module 3 does the first installation from the official source.
Appears in: Lesson 6 Lesson 9 Lesson 12 Lesson 14 Lesson 17 Lesson 18 Lesson 24 Lesson 30 Lesson 31 Lesson 36 Lesson 38 Lesson 39 Lesson 42 Lesson 45 Lesson 48
The screen where you give the objective to the AI, like the chat window. The course shows other interfaces throughout the modules.
Appears in: Lesson 1 Lesson 6 Lesson 7 Lesson 10 Lesson 12 Lesson 37
Example of a classification model mentioned in the course. It doesn’t chat: it receives a text and closed answer options and returns a choice—yes or no—or a score.
Appears in: Lesson 2
A hub that gives access to image and video models from several providers, with its own credit.
List of the numeric IDs that the bot serves. In the kit, it's on the ALLOWED_USER_IDS line of the .env.
Language model: a program trained with a lot of text that produces text based on what you provide. It’s the kind of AI behind chats.
Record of what a program did, line by line, with date and time. This is where you look for the cause of an error.
Appears in: Lesson 33 Lesson 36 Lesson 40 Lesson 42 Lesson 46 Lesson 47 Lesson 48
Sign in to a tool with your account, like your ChatGPT account. The rights and limits come from that account’s plan.
Appears in: Lesson 5 Lesson 14 Lesson 15 Lesson 18 Lesson 44
How the bot asks Telegram, from time to time, whether a new message arrived. It doesn't require a server with a public address.
A way to write plain text with light markup, like # for a title and - for a list. Files end in .md.
Appears in: Lesson 16 Lesson 20 Lesson 24 Lesson 25 Lesson 27 Lesson 29 Lesson 30
Reference files with stable facts, decisions, and causes of failures, which the agent reads when you indicate. It doesn't change the model; someone needs to keep them up to date.
Appears in: Lesson 28
Text editor that opens inside the terminal. Ctrl+O saves the file and Ctrl+X exits.
Computers in a company, accessed through the internet, that run the work and store files outside your machine.
Appears in: Lesson 10
A hub that gives access to language models from multiple companies through a single point, with its own credit.
Name that Git gives, by default, to the address on GitHub where the folder came from and to where it sends.
A folder with only fictional files or copies, created to test the AI without any risk to the real material.
Appears in: Lesson 6 Lesson 9 Lesson 12 Lesson 18 Lesson 24 Lesson 30 Lesson 31 Lesson 36 Lesson 42 Lesson 48
Your main folder on your computer, where Documents, Downloads, and the rest are stored. In the terminal, it shows up as ~ (til).
A number that identifies a service inside the machine. SSH usually uses port 22, but your VPS may use a different one.
Shows up in: Lesson 2 Lesson 13 Lesson 37 Lesson 40 Lesson 44 Lesson 46 Lesson 48
A company that offers an AI model. A hub gathers models from multiple providers in one place.
Git command that brings the new changes from GitHub to your computer.
Git command that sends your commits to GitHub.
Shows up in: Lesson 36
A text file in the project folder that explains what it’s for, what’s inside, and how to check the result.
Shows up in: Lesson 6 Lesson 12 Lesson 16 Lesson 17 Lesson 18 Lesson 19 Lesson 20 Lesson 22 Lesson 23 Lesson 24 Lesson 25 Lesson 26 Lesson 30 Lesson 32 Lesson 33 Lesson 34 Lesson 35 Lesson 36 Lesson 38 Lesson 42 Lesson 48
A short list of criteria, written before the request, that tells you what the response must include to be accepted.
A project folder accompanied by Git, with the full version history.
Shows up in: Lesson 22 Lesson 27 Lesson 31 Lesson 33 Lesson 34 Lesson 36 Lesson 47
Git command that discards changes that haven’t been saved yet in a file, bringing it back to what it was in the last version. What gets discarded won’t come back.
Git command that creates a new commit undoing a previous commit, without deleting anything from the history.
File with a sequence of commands that your computer executes all at once.
A computer that stays on, providing a service to others, such as responding to messages from a bot.
Shows up in: Lesson 37 Lesson 40 Lesson 43 Lesson 44 Lesson 48
A program that interprets the commands you type in the terminal.
A packaged procedure that the agent can reuse: instructions, steps, and how to verify, saved in a folder.
Appears in: Lesson 26 Lesson 27 Lesson 29 Lesson 30 Lesson 48
A secure way to open the terminal of another computer over the internet.
The Git area where the chosen changes are kept to go into the next commit.
A command that runs the next instruction with administrator permission. It asks for your password.
Appears in: Lesson 44 Lesson 45 Lesson 46 Lesson 47 Lesson 48
A systemd command to start, stop, and view the status of a service.
Part of Linux that starts, monitors, and restarts programs by itself, including after you reboot the machine.
A messaging app. In the course, it becomes the conversation screen with your own bot in module 7.
Appears in: Lesson 6 Lesson 12 Lesson 18 Lesson 24 Lesson 30 Lesson 36 Lesson 37 Lesson 38 Lesson 39 Lesson 40 Lesson 41 Lesson 42 Lesson 43 Lesson 46 Lesson 47 Lesson 48
A text program where you type commands for the computer to run. Module 3 teaches you how to open and use it.
Appears in: Lesson 5 Lesson 12 Lesson 13 Lesson 14 Lesson 15 Lesson 16 Lesson 17 Lesson 18 Lesson 19 Lesson 20 Lesson 21 Lesson 22 Lesson 23 Lesson 24 Lesson 26 Lesson 27 Lesson 28 Lesson 29 Lesson 30 Lesson 31 Lesson 32 Lesson 33 Lesson 34 Lesson 35 Lesson 36 Lesson 38 Lesson 39 Lesson 40 Lesson 42 Lesson 44 Lesson 45 Lesson 46 Lesson 47 Lesson 48
Password that Telegram generates for your bot. Anyone with the token controls the bot; that’s why it’s stored in the .env.
Appears in: Lesson 22 Lesson 36 Lesson 38 Lesson 39 Lesson 40 Lesson 42 Lesson 46 Lesson 48
A piece of text, like a short word or part of a word, that the model reads and writes. Usage and billing are usually measured in tokens.
Appears in: Lesson 3 Lesson 5 Lesson 6 Lesson 12 Lesson 18 Lesson 22 Lesson 24 Lesson 30
Popular Linux version, common on servers.
Appears in: Lesson 13 Lesson 14 Lesson 43 Lesson 45 Lesson 46 Lesson 48
Ubuntu command to set up the firewall in a simple way.
Appears in: Lesson 46
File that tells systemd which program to start, which user, and in which folder.
A name with a value stored, written as NOME=value. The program looks up the value by the name.
Appears in: Lesson 15 Lesson 22 Lesson 24 Lesson 38 Lesson 42
A computer rented from a provider, connected all the time and under your responsibility. Module 8 teaches you how to use it.
Appears in: Lesson 6 Lesson 10 Lesson 12 Lesson 18 Lesson 24 Lesson 30 Lesson 36 Lesson 40 Lesson 42 Lesson 43 Lesson 44 Lesson 45 Lesson 46 Lesson 47 Lesson 48
How Telegram notifies your server immediately when a message arrives. It requires a public address on the internet.
Appears in: Lesson 40
Module 1 · Lesson 1 of 6

You can draw the seven pieces of your AI system and point out which one is missing to complete a real task this week.
When the answer comes out bad, the common reaction is to switch tools or write a bigger request. Often the problem is in another piece: the file was missing, there was a permission issue, or the way to check was wrong. This lesson shows where to look.
In 1 minute
When this course talks about AI, it means language models, the LLMs. A model is a mechanism trained to produce text based on what you give it.
It doesn’t see your school, your team, or last week’s meeting. Whatever is missing from the request, it fills in with the most common way to respond.
Denise, the educational coordinator, asked for a plan for a parents meeting. Without the agenda, the AI imagined priorities. With the agenda and the previous minutes pasted in, it returned a proposal she was able to review.
YouMake a plan for the 8th grade parents meeting.
AIPlan suggestion: 1. Welcome. 2. Presentation of the educational project. 3. Test calendar…
Invented priorities. None of that was on the school’s agenda.
YouMake a plan for the 8th grade parents meeting, using only the agenda and the minutes below. Mark what was left pending from the previous meeting. [pasted agenda] [pasted previous minutes]
AIPlan based on the agenda sent: 1. [agenda item 1] 2. [agenda item 2] Pending from the previous minutes: [issue recorded in the minutes]
Same AI. Now each item points to a role Denise has in hand.
There are several models, with different names, sizes, and costs. The question "which one is best?" doesn’t have a useful answer.
The helpful question is different: which model solves this task, within this timeframe, at this cost, and with how much you’ll need to check? That’s why the module compares models with a real task, not an opinion.
Lúcia, a science teacher, stopped looking for "the best AI". Now she asks which tool corrects the 8th grade exercise list within the time she has.
"What is the best AI?"
Each person answers something. No answer applies to your task.
"Which model summarizes this meeting minutes in ten lines today, and lets me check the three responsible people?"
You can test and compare.
A model produces responses. A system organizes how those responses become work. OSWork combines seven pieces: model, interface, files, instructions, tools, memory, and automations.
The name OSWork is a metaphor for organization. You won’t replace your computer’s system.
Denise drew the seven boxes for the task "parents meeting minutes." There was a template and an interface. The missing files were the issue: the agenda was in someone else’s email.
Think of a small workshop. The professional’s skill matters, but tools, materials, and quality criteria also decide the result.
Test yourself
On the school computer, the meeting plan worked out. On your phone, with the same chat, the AI invented two items. You’d pasted only half of the agenda. Which piece failed?
Separating the pieces prevents the reflex to write a request that keeps getting bigger. First you ask where the failure was born. Then you fix only there.
And a piece never leaves the system: you. The model reasons, the tools execute, and you are the one who checks.
Lúcia’s AI said it saved the notes, but the file didn’t appear. A tool with permission to save was missing. Writing the request again wouldn’t solve it.
Stuck here? That's normalSeven pieces seem like a lot at the start. In this lesson, you only need to judge three: template, interface, and files. In the other four, a "?" is the right answer for now.
Practice now 0/3
Done when you circle, among template, interface, and files, the missing piece in a real task from this week. About 8 minutes, on paper or in your phone’s Notes.
It’s just a drawing: nothing gets sent to anyone. If all the pieces seem present, choose a task that recently caused rework.
You just saw your use of AI as a system and pointed out the missing piece.
Lesson cheat sheet
When this course talks about AI, it means language models, the LLMs. A model is a mechanism trained to produce text from what you give it. There are several, with different names, sizes and costs, and the first question is usually which one is best. That question has no useful answer: there is no best model, there is the model suited to the task, the deadline, the cost and the level of checking that work requires. That is why this module compares models against a real task rather than against opinions. A model produces answers; a system organises how those answers become work. OSWork combines model, interface, files, instructions, tools, memory and automations. Think of a small workshop: the professional's skill matters, but tools, materials and quality criteria also determine the result. We are not installing a new computer operating system: we use that expression as a metaphor for organisation.
Without this distinction, every failure turns into an attempt to write a larger prompt. Sometimes only the input file, a permission, or the way to verify the output is missing. Separating the pieces allows you to fix the right point.
Model reasons; interface receives the goal; files provide evidence; tools execute; you verify.
A coordinator asks for a meeting plan. Without an agenda, the AI imagines priorities. With an agenda and previous minutes, it can prepare a verifiable proposal.
Draw seven boxes with the system pieces. Mark which ones you already have and which are missing to complete a task.
Accepting a conclusion without checking the input that supports it.
Lesson 1 · OSWork v6.2 · INEMA.CLUB PRO
Module 1 · Lesson 2 of 6

For each task you repeat, can you say what kind of model it asks for — text, image, video, or classification — before you choose a name?
Adopting a model as "the best" closes the door to everything it doesn’t do. A great text model doesn’t generate a video. A classifier doesn’t write your report. This lesson teaches you to separate by function first.
In 1 minute
Language models, the LLMs, write, summarize, explain, and program. Image and video models generate or edit visual material.
There are also classification models. They don’t chat: they receive options and return a choice, yes or no, or a score.
Lúcia listed what she does with AI in a month. Summarizing the class council minutes needs text. The science fair brochure cover needs image. Separating two hundred class comments needs classification.
ChatGPT, Gemini, and Copilot are chatbots: behind each one there are language models. Within each type, there are families with their own names. In text, the GPT family has Sol, Terra, and Luna, plus GPT-6 Astra. The Claude family has Opus and Fable.
You don’t need to memorize this list: these names come from a query on 09/20/2026. Names, versions, and availability change. That’s why the choice happens when the task appears, and it can be different the next week.
Denise heard from a colleague that "this model is the best" and wanted to use it for everything. When she requested the artwork for the June festival invitation, she found out it only writes text.
"I’ll use the model that everyone praises, for everything."
The invitation artwork doesn’t come: the model is text-based.
Invitation in text: a language model. Invitation artwork: an image model.
Each task goes to the type that knows how to do it.
A classifier, like the Jev, receives a text and a closed list of alternatives. It returns a choice—not a paragraph.
To triage many items across a few categories, this can be simpler to check than a conversation. It’s a hypothesis to test, not a guarantee. You can try the idea today in the same chat: paste the items and ask "respond with only one of these categories".
Lúcia pasted a student comment into the chat and the three categories, asking for only the category. It returned a single word. She checked ten responses by hand before trusting the others.
YouComment: "I didn’t understand the part about photosynthesis that showed up on the test." Categories: question · praise · complaint
AIquestion
A choice among the given alternatives. Easy to verify in bulk.
Test yourself
Denise received 300 open responses from parents about the entry time. She wants to know how many request a schedule change. What type of model does she test first?
There are also gateways, which give access to multiple providers at a single point. The OpenRouter brings together language models. The Kie brings together image and video models.
Availability varies by account, plan, and release. A model that shows up for a colleague may not show up for you.
For the ten-second graduation vignette, Denise didn’t need to sign a video service by model. In a text and video hub, she compared two models in the same place, with one account.
OpenRouter
Multiple language models in one access point.
Kie
Multiple image and video models in one access point.
Stuck here? That's normalThe list of names gets tiring and ages quickly. Keep only the four functions. You check the names in "Where to find the current names", in the practice of this lesson, when the task shows up.
Practice now 0/3
Ready when each task has a model type, and only then a name. About 8 minutes, on paper or in your phone’s Notes.
No one else sees this list besides you. Were you unsure between two types? Write both: the module lab, in the lesson 6 supplementary material, compares them in practice.
TASK 1: <ex.: summarize the board minutes> Type: <text, image, video, or classification> Name to test: <fill in last> TASK 2: <…> Type: <…> Name to test: <…> TASK 3: <…> Type: <…> Name to test: <…>
Official pages list what’s available today: ChatGPT models, Claude models, OpenRouter catalog and Kie. Course lookup: 20/09/2026.
You just chose by function before the name, for the tasks you repeat the most.
Lesson cheat sheet
Before comparing names, sort by function. Language models, the LLMs, write, summarise, explain and program: that is where families like GPT sit, with Sol, Terra and Luna, GPT-6 Astra, and the Claude family, with Opus and Fable. Image and video models generate or edit visual material. And there are classification models, such as Jev, which do not converse: they take alternatives and return a choice, a yes or no, or a score. There are also hubs, which give access to several providers through a single point: OpenRouter for language models and Kie for image and video. Names, versions and availability change; this reading is from 20/09/2026.
Choosing a model as the best locks the port for everything it doesn’t do. An excellent LLM doesn’t generate a video, and a classifier doesn’t write your report. Understanding what each type is for comes before choosing, and the choice happens when the task shows up, which can be different the next week. Availability also varies by account, client, authentication, and permissions.
Text; image; video; classification; access hubs; availability.
Summarising minutes calls for a language model. Sorting two hundred comments into three categories may fit a classifier such as Jev better. Producing a ten-second sting requires a video model, usually reached through a hub. These are hypotheses to test, not guarantees.
List the three AI tasks you repeat most. Next to each one write the kind of model it calls for, and only then the name you intend to test; check the sources at the end of the module.
Lesson 2 · OSWork v6.2 · INEMA.CLUB PRO
Module 1 · Lesson 3 of 6

You can repeat a request by changing only reasoning effort and say, with evidence, whether the result improved.
A lot of people set maximum effort for every task, for safety. That can waste more time and more consumption without improving anything. And no effort will bring back the document that was missing from the request.
In 1 minute
The model is the chosen mechanism. Reasoning effort is a setting of that mechanism: how much it analyzes before responding.
Higher levels can spend more time and more tokens. The selector names change between Chat, the Work, and the Codex. There is no single list of levels that applies to all products.
Denise thought changing the level meant changing the AI. She found out that, within the same model, you can ask for a quick response or a longer analysis.
Increasing effort doesn’t provide a document that was left out. If the answer depends on some data, the data needs to be included in the request.
First complete the inputs. Then evaluate whether the problem calls for more analysis.
Lúcia wanted to know why the secretary’s grades spreadsheet didn’t match hers. At maximum effort, without the spreadsheets, she received general hypotheses. With the default, with both spreadsheets pasted in, she got the exact line of the difference.
Request: "Why don’t the two grades spreadsheets match?"
Result: a list of possible causes, without pointing to any of them.
Request: the same, with both spreadsheets pasted in.
Result: "[student] has a different score in [assessment] between the two versions."
Net gain: the right input fixed what the maximum control, at most, didn’t fix.
For most everyday tasks, the default effort works. Save more analysis for what involves multiple steps or lots of data.
Denise needed to rewrite a five-line invitation for the parent meeting. In the default, the response came in seconds and it worked.
YouRewrite this invitation in a cordial tone, in up to five lines. Keep the date and time exactly as they are. [invitation pasted]
AIDear families, we invite you to [the invitation event] on [invitation date], at [invitation time]…
Short, well-defined task: the standard is enough.
Test yourself
First round: default effort, one spreadsheet. Second round: maximum effort, two spreadsheets. The second came out better. What can you conclude about effort?
To see whether effort helped, repeat the same request, with the same material, using the same model. Change only the effort.
Then record: was there an improvement you can show? One more fact, one fewer mistake, a correct calculation. “Got better” without evidence doesn’t count.
Lúcia asked for the same correction, commented on, twice. At the highest level, a unit error appeared that the standard had let slip. She noted which one it was.
Stuck here? That's normalYour chat may not show an effort control: it depends on the product and plan. In this case, write "no effort control" in the record and make another comparison of a single control: change only the model. It’s a different test, but the method is the same. No control for either one? Compare two chats you already use, with the same request and the same material.
Practice now 0/3
Ready when the record says whether there was a demonstrable improvement, with the evidence. About 10 minutes, in the chat you already use. Look for the effort control near the message box or in the model selector; sometimes it shows up as a reasoning option or as “think more.”
Use a piece of your own material that isn’t confidential, or invent a short one. If the two responses come out the same, that’s also a result: the standard is enough for this task.
REQUEST (same in both rounds) <ex.: point out the errors in this student response and explain each one in one line> MATERIAL (same in both rounds) <paste here the text, the table, or the response> RECORD Control that changed: <effort · model · chat> Round 1 · <ex.: standard effort> · what came: <…> Round 2 · <ex.: above standard effort> · what came: <…> Measurable improvement? <yes or no> · evidence: <the extra fact or the one error less>
You just tested one control at a time and decided with evidence.
Lesson cheat sheet
The model is the chosen mechanism. Reasoning effort is a setting of that mechanism. Higher levels may consume more time and tokens, units of text processing. The selector names change between Chat, Work, and Codex; there is no single list of Instant, Medium, High, and Pro that represents all products.
Requesting the maximum on every task can increase consumption without improving the result. Increasing effort also does not provide a missing document. First complete the inputs, then assess whether the problem requires more analysis.
Model and effort are different axes; start with the default; compare under equal conditions.
To rewrite a five‑line invitation, the template may solve it. To explain why two spreadsheets disagree, providing the two spreadsheets usually matters more than moving a control.
Lesson 3 · OSWork v6.2 · INEMA.CLUB PRO
Module 1 · Lesson 4 of 6

You can write three criteria before the request and use this ruler to decide, without discussion, which of two responses works.
Without criteria, you pick the most beautiful response. A summary can sound convincing and change a name or invent a deadline. This lesson shows how to decide based on what the response contains, not on the tone.
In 1 minute
A quality ruler says, before the request, which facts need to appear, which errors are unacceptable, and how the output will be used.
Written beforehand, it doesn’t get carried away by the response. Written afterward, it usually approves what came.
Denise was going to ask for a summary of the planning meeting for the science fair. Before opening the chat, she wrote three lines on paper.
"I want a good summary of the meeting."
Any well-written text passes.
1. The three people responsible, with no deadline that isn’t in the minutes.
2. A section for pending items.
3. Each sentence is something you can find in the minutes.
Net gain: three yes-or-no questions, answered in less than a minute.
To start, use three criteria. Faithfulness to the data: no data from the material changes or disappears. Combined format: the size and sections you asked for. Verifiable conclusions: nothing is added that you can’t find in the material.
The three criteria are the template. In each task, they turn into concrete items. In Denise’s minutes, fidelity became “the three responsible people, no invented deadline”; format became “a pending items section”; verifiable became “each sentence can be found in the minutes.”
Lúcia used the same template for a chapter summary from a science book. The items changed: chapter concepts, a page, each statement with the page number.
The test needs to reflect the work you will deliver, not a demo made to impress. An elegant sentence doesn’t make up for losing a responsible person.
Denise got two versions of the summary. The first was smooth and pleasant to read. The second was dry. She applied the rule to both.
AIThe meeting was productive and full of energy. Lúcia will organize the groups with her usual enthusiasm, and Marcos reserves the patio until Friday. The fair promises!
Renata was missing, and “until Friday” isn’t in the minutes. There are no pending items. “Full of energy” can’t be found in the minutes. Rejected on all three items.
AIDecisions: Lúcia organizes the groups. Marcos reserves the patio. Renata buys the material. Pending items: confirm the date with management.
Three responsible people, no invented deadline, recorded pending item. Passes all three.
Test yourself
The answer includes the three responsible people, has the pending items section, and ends with “the team left motivated.” That’s not in the minutes. Which criterion rejects it?
Turn the rule into a four-column table: criterion, expected, observed, and passed? That way the decision is written down and you can repeat the test later.
Also keep a bad answer. It reminds you what you’re trying to avoid.
Lúcia pasted the table at the end of the corrections document. The following week, she used the same rule to compare a new model, without starting from scratch.
Stuck here? That's normalWriting criteria feels bureaucratic the first time. Start with just one: "no data that isn't in the material". The other two show up on their own after the first wrong response.
Practice now 0/3
Ready when you fill in the table for both responses and choose one based on it. About 10 minutes. Write it down on paper or in a notes app.
It’s a fictional case made for training: there’s no one’s real data. Disagreed with the answer key? Re-read the announcement and check line by line.
The (fictional) material: Excursion of 7th A to the science museum. School leaves at 7:30, returns at 12:00. The authorization signed by the responsible people must be turned in by Thursday. Each student brings their own snack.
The request you made to the AI: "Write a short notice for families with the excursion information."
Response 1: "Hello, families! Our class is going to have an amazing day at the science museum. Departure at 7:30 and return at 13:00. Don’t forget the snack!"
Response 2: "Excursion of 7th A to the science museum. Departure at 7:30, return at 12:00. Turn in the signed authorization by Thursday. Each student brings their own snack."
You just decided between two responses using a written rule, not the tone.
Lesson cheat sheet
A rubric turns opinion into observation. Define before the request which facts must appear, which errors are unacceptable, and how the output will be used. Use three small criteria: fidelity to the data, combined format, and verifiability of the conclusions.
Without criteria, you choose the prettiest answer. A report can sound convincing and alter values. The test should reflect the work you need to deliver, not a demonstration made to impress.
Acceptance; evidence; representative sample; controlled comparison.
In a fictional minutes with three responsible parties, the test requires the three names, no invented deadline, and a pending items section. An elegant sentence does not compensate for missing a responsible party.
Use the table: criterion | expected | observed | passed? Keep a bad answer as well to remember what you are trying to avoid.
Mix the training copy with private files or production work.
Lesson 4 · OSWork v6.2 · INEMA.CLUB PRO
Module 1 · Lesson 5 of 6

You can identify the access method of each AI tool and record it in the project worksheet, without exposing any credential.
A test might be consuming a different account than the one you think. Subscribing to a chat doesn’t give you free balance for any program that calls the API. If today you only use the chat with your account, your worksheet will have one line. The others come later, when the course reaches those programs, in module 3.
In 1 minute
Doing a login with the ChatGPT account uses that account’s rights and limits. They come from its plan and its workspace. What you can use—and how much—comes from the plan.
These limits and rules change. The source of truth is the current configuration of your account, not what someone told you.
Lúcia uses the school’s account to access the chat. When she hit the day’s usage limit, she found out the limit was from the school’s plan—not hers.
Programs use the AI through an API. For that, they use a API key, charged per usage on the platform.
Subscribing to the chat doesn’t mean you get free balance for any program that calls the API. It’s two accounts, with two charges.
Denise ran a reports program with an API key from the school. The tokens used showed up on the platform, not in the chat subscription.
Who uses: you, on the chat screen or in an agent connected to the account.
Billing: the account plan, with its limits.
Who uses: a program.
Billing: by usage, on the API platform.
Centres like the OpenRouter and the Kie have their own credit, billed by usage. It’s separate from any subscription.
So there are at least three places where the money can come from: the chat plan, the API platform, and the centre credit.
Lúcia generated the reading week posters on a centre, with a small credit that she bought herself to test. The credit ran out in the middle of the batch. The chat subscription was still active, but it didn’t cover that.
Test yourself
Lúcia subscribes to a chat plan. She generates posters on a centre, and the centre credit ran out. What fixes it?
Before leaving something running for a long time, check which method is active: in the tool settings, look at the account plan, or the key in use. Later, in Codex, a command in the terminal shows that.
In the project sheet, note the method: account, key, or centre. The credential itself never goes on the sheet, for a request, or in a screenshot.
Before asking for the summary of the forty meeting minutes from the year, Denise checked the settings and wrote in the sheet: "school chat · school account · plan limit". Without any password.
$ codex login status
Logged in using ChatGPT
The first line is what you type. The second one, in English, says "connected using ChatGPT": the method is the account.
Stuck here? That's normalCodex only arrives in module 3. For now, check the method on the settings screen of the tool you use and note what it shows.
Practice now 0/3
Done when the sheet has one line per AI tool you use, with the method and where you checked. About 8 minutes, on your computer or phone.
Do you only use the chat with your account? Then the sheet has one line, and that’s fine. You only write down the type of access—never a password or key. If you find a key stuck in some document, delete it from there and tell whoever manages that account.
PROJECT SHEET · ACCESS Tool: <ex.: school chat> Method: <account · API key · central> Where I checked: <ex.: Settings › Plan> Spend limit: <ex.: the plan’s limit> Credential: DO NOT NOTE HERE
You just mapped where the cost for each tool comes from, without exposing any credential.
Lesson cheat sheet
Signing in with ChatGPT uses the rights and limits tied to the account and the workspace. An API key uses pay-per-use billing on the platform. Subscribing to ChatGPT does not mean receiving free balance for any program that calls the API. Hubs such as OpenRouter and Kie have their own credit, billed per use and separate from any subscription. Check the active method before a long run.
This precaution avoids discovering later that an experiment is consuming a different account. Usage limits, model access, and data rules can change; the source of truth is the current configuration of your account.
Subscription; authentication; API; consumption; spending limit.
A student uses Codex connected to ChatGPT and then runs a program with OPENAI_API_KEY. They are different paths, even if they use a model with a similar name.
In Codex, use codex login status to check the method. In the project sheet, record the method, never the credential.
Lesson 5 · OSWork v6.2 · INEMA.CLUB PRO
Module 1 · Lesson 6 of 6

You can write an authorization in five parts—goal, files, actions, time, and stop—and ask for a closure that says what was done and how it was verified.
An agent executes multiple steps and can get several of them wrong. Without a written limit, it can waste time, credits, or touch the wrong file. A simple limit protects all of that without blocking useful work.
In 1 minute
In a chat, you send a message and get a response. An agent receives an objective and goes alone: it reads files, creates, compares, corrects.
This saves you work. It also multiplies the places it can make mistakes without you seeing.
Lúcia asked an agent to organize the notes from the grading period. It read three spreadsheets, created a new one, and renamed the old ones. The last step she hadn’t asked for.
One message, one response.
You see each step before the next one.
One objective, multiple steps: read, create, compare, correct.
You see the result at the end.
Combine five things before you start: the objective, the permitted files, the authorized actions, the time limit, and the stop condition.
In a chat, time turns into “respond in a single message”; in an agent, it’s an execution ceiling. Technical permission and written instruction complement each other: the tool limits what’s possible, and the authorization says what’s desired.
Denise wrote the authorization for the agent that prepares the monthly attendance report. It took two minutes and fits on a sticky note.
Sending a message, posting, or deleting are external actions. Each one requires explicit instruction. The fact that a send button exists does not authorize using it.
Lúcia authorized the agent to create the draft of the scavenger hunt announcement and compare it with last year’s. Sending it to families was left out on purpose.
YouCreate the draft of the scavenger hunt announcement using only the scavenger hunt rules file. Compare with last year’s announcement. Stop before sending to anyone.
AIDraft created. Comparison: three repeated excerpts from last year, marked in the draft. Not sent: sending wasn’t authorized.
Stop where the authorization told it to stop, and said that.
Test yourself
The authorization only said "organize the tests folder". The agent could delete files and deleted three that looked like copies. Which part of the authorization was missing?
Always ask for a three-part closing: what was done, how it was verified, and what’s still pending. This way, the result becomes something you review, not something you have to trust.
Denise’s agent finished the draft of the attendance report and listed what she checked. She opened the spreadsheet, checked one of the numbers, and approved the rest.
AIDone: draft of the report with attendance by class. Verified: the total by class matches the sum of the spreadsheet rows. Pending: class 8º C has two rows without a date. I didn’t complete them.
Three parts, and the pending item wasn’t filled in with a guess.
Stuck here? That's normalYou might not be using any agent yet. This lesson practice is in the chat, where you can’t send anything: it trains you to write the authorization, not to prove the AI follows it. The test with a real agent comes in module 3, with the authorization you write today.
Practice now 0/3
Ready when the closing comes with what was done, how the three points were verified, and what’s still pending. About 10 minutes, in the chat you already use.
Use made-up data or your own text without personal information. Nothing is sent to anyone: the stop point ensures that. If the AI goes past the limit, note what it did and reinforce that line.
1. OBJECTIVE <ex.: draft of a notice about the school fair> 2. FILES: USE ONLY THIS MATERIAL <paste the text or made-up data here> 3. AUTHORIZED ACTIONS <ex.: write the draft in up to eight lines; don’t invent dates or names> 4. TIME Respond in a single message. 5. STOP POINT Stop before publishing or sending. CLOSING (the three points are your rubric for lesson 4) Say what you did, how you verified these three points, and what’s still pending: - <ex.: the date matches the material> - <ex.: no name that isn’t in the material> - <ex.: up to eight lines>
1. Objective: draft of the notice about the library schedule change.
2. Files: [old and new hours pasted]
3. Actions: write the notice in up to six lines; don’t invent a reason.
4. Time: respond in a single message.
5. Stop point: stop before sending.
Closing: say what you did, how you verified the two times, the absence of names, and the six-line limit, and what’s still pending.
You just delegated a task with scope, verification, and a stop point.
Lesson cheat sheet
Autonomy is an authorization with scope, not an invitation to do anything. Combine objective, permitted files, authorized actions, time limit, and stop condition. The output must include what was done and how it was verified.
An agent can execute more steps than a chat, including making multiple mistakes. A simple limit protects time, budget, and files without preventing useful work. Technical permission and written instruction complement each other.
Scope; approval of external actions; execution ceiling; reviewable result.
Authorize creating a draft and comparing fictional data. Sending the proposal to a client is another action and requires explicit instruction. The existence of a send button does not mean permission to use it.
Write: use these files; generate this result; verify these three points; stop before publishing or sending.
Use fictional files and a training folder. Practices with installation, Telegram, or VPS may require extra time for sign-up and configuration.
Read the block before using. Fields like Your Name and usuario@ip-da-vps are examples to adapt; administrative commands belong only to your training environment.
Task: summarize a fictional meeting
Input: agenda with 5 items
Criteria: keep 5 items; don’t invent deadlines
Model / effort: write down what’s available
Observed result: record correct answers and mistakes
Choice: justify based on the result, not the nameCompare models with a real task and a quality criterion. Record the produced file, the test run and the observed result.
Use this rubric after the lab. Each line asks for evidence; checking reading does not mean the practice was performed.
One answer arrived faster, but invented two deadlines. Which result should guide the choice?
Verifiable quality and rework; speed alone is not enough.
If your answer was different, return to the corresponding topic and write the difference in one sentence. The check does not block your study.
Tools verified on 20/09/2026; screen names and availability may change.
Terms for this section: OpenRouter, Kie.
Lesson 6 · OSWork v6.2 · INEMA.CLUB PRO
Module 2 · Lesson 1 of 6

You can ask a short question with audience and purpose and get the answer with the AI’s assumptions right in view.
Not every task requires a big tool. Building a complicated routine for something that only needed an answer wastes time—and it also creates more things to check. Knowing when the chat is enough is the first filter in this module.
In 1 minute
The chat is a interface for conversation. Think about the question you ask a coworker in the hallway, between two lessons. It’s short, the answer comes right away, and you decide what to do with it.
If the answer didn’t work, you don’t start over. Send an adjustment in the same conversation.
Lúcia will cover a math lesson for a colleague. She asked for three ways to explain fractions using the ingredients from a recipe. She chose one, adjusted another, and took them to the class.
YouGive me three ways to explain fractions using the ingredients from a cake recipe.
AI1. Half a cup of sugar: the cup divided into two equal parts. 2. One quarter of a stick of butter: four pieces, use one. 3. One third of a cup of milk: the cup in three parts, use one.
YouSwap the third: I want an example with three eggs divided between two recipes.
AI3. Three eggs for two recipes: each one takes one and a half eggs.
The third message is the adjustment: same conversation, without starting over.
A free-form question gets an encyclopedia-style answer. Say who will read it and what you’re going to do with the text. The answer already comes in the right length and tone.
Denise needed to explain the class council to the parents of 6th grade. The first question brought a technical paragraph. With the audience and purpose, two ready-made sentences came for the message.
YouWhat is class council?
AIClass council is a group evaluation process provided for in school organization, bringing together teachers and the educational team to analyze the teaching and learning process…
Correct, but too long and too technical for a message to parents.
YouExplain what class council is in two sentences, for parents of 6th grade. It should go in an agenda message.
AIClass council is a meeting of teachers with coordination to talk about how each class and each student are doing. From it come agreements to help those who need it.
Same topic, now in the size and tone of the message.
Every short question leaves gaps. The AI fills those gaps without telling you: it assumes the students’ age, the tone, the size. Ask it to list what it assumed.
That way you can see the guess before you use the answer. Correcting a guess costs a message.
Lúcia asked for an opening question for the lesson about mixtures. The list of guesses showed that the AI thought of high school students. She corrected it with one line.
YouCreate an opening question for a lesson about mixtures. In the end, list the assumptions you made.
AIQuestion: why does the salt disappear in water, but the sand doesn’t? Assumptions: high school students; a 50-minute lesson; the question will be asked out loud.
YouThe class is in 8th grade. Adjust the question if you need to.
AIFor 8th grade: what happens to salt when it goes into water, and why does the sand stay at the bottom?
The wrong assumption showed up in the list, not hidden in the text.
The choice is based on the task’s intent, not on a technical restriction. Some chats also read attached files. If the delivery is a response you read and check right away, the chat is enough.
If the delivery is a document with multiple entries, the conversation gets too short. Some chats have a mode for bigger tasks; in ChatGPT, it’s called Work. It’s the topic of the next lesson, which also shows how to do it without that.
Denise almost opened a long task to write a three-line message. She went back to the chat and got it done in two minutes.
Explain a concept in a few lines.
Draft a short message or email.
Brainstorm for a lesson.
Combine multiple sources into a table.
Deliver a ready document to review.
A task that takes more time than a conversation.
Test yourself
You only need a two-sentence explanation for a message. Do you need to use Work?
Stuck here? That's normalDon’t know whether your chat has Work or reads files? You don’t need to know that now. This lesson and the practice work with any chat, even on the free plan, on your phone.
Practice now 0/3
Ready when the response comes with a list of assumptions and you’ve corrected one of them. About 8 minutes, in the chat you already use, on your phone or computer.
It’s a question from your work, with no student name and no personal data. If the AI doesn’t list the assumptions, just send: "List the assumptions that you made."
Question: <your one-line question> Audience: <who will read or hear the answer> Purpose: <what you’ll do with it> Length: <e.g., up to five lines> In the end, list the assumptions you made about what I didn’t say.
Question: how to explain the difference between evaporation and boiling?
Audience: 8th grade students.
Purpose: to open tomorrow's lesson.
Length: up to four lines.
At the end, list the assumptions you made about what I didn't say.
You just asked a question that pays off on the first round—by correcting the AI's guess before using the answer.
Lesson cheat sheet
Chat is a conversational interface. You present a question, receive an answer, and can adjust the request. It works well for clarifying a concept or drafting a message. Additional features vary: a chat can also work with files and tools when available. The pedagogical distinction is the task’s intent, not a technical prohibition.
Recognizing a small need prevents building an automation for something that only requires an answer. The best environment is the one that lets you verify delivery with minimal friction.
Conversation; clarification; draft; human review.
A teacher asks for three ways to explain fractions using ingredients from a recipe. She analyzes the examples and chooses one before taking it to class.
Write a short question with audience and purpose. Then ask the answer to indicate its assumptions.
Accepting a conclusion without checking the input that supports it.
Lesson 7 · OSWork v6.2 · INEMA.CLUB PRO
Module 2 · Lesson 2 of 6

You can turn a vague request, like "search suppliers", into a short request with five parts: objective, inputs, result, limits, and stopping condition.
A project with multiple sources needs a definition of done. Without it, the AI can keep researching when you only needed to compare three options. And you get a long text that you don’t know where to review.
In 1 minute
In Work, you don’t chat sentence by sentence. You submit a task, like an analysis or a document, and get the result to review. It can use files and approved tools.
Think of the request for a cake at the bakery. You say flavor, size, and day. You don’t keep watching the oven. Work doesn’t show up in every plan. Can’t find it there? Use the request in regular chat: it works the same.
Denise needs to hire a bus for the museum field trip. She has three quotes and wants a comparison to take to management.
You ask, read, adjust.
You follow each answer.
You describe what must exist at the end.
You review the result when it arrives.
A request says five things. The goal. The inputs, which are the material the AI can use. The output, which is the format of the result. The limits. And the stop, which is when the work ends.
It looks like lesson authorization 6, in module 1, and it’s related. The authorization says what the AI can do; the request says what must exist at the end.
Denise wrote the request for the bus quotes in five lines. It took three minutes.
A vague request opens the door to endless research. The request closes that door: three options, the documents you provided, a format.
Notice the field with no information. The request asked for "not informed", and the AI didn’t fill it in with a guess.
YouSearch bus companies for a school field trip.
AII found many options. First, an overview of the school charter sector, with hiring tips and required documents…
Long, beyond the three quotes, and without saying when it ends.
YouCompare only these three bus quotes in a table with price, confirmation deadline, and risks. Missing data becomes "not informed". Deliver the table and stop. Company A: R$ 1.800, confirms in 2 days. Company B: R$ 1.500, deadline not cited. Company C: R$ 2.100, confirms in 1 day; buses without seat belts in the back seats.
AIA · R$ 1.800 · 2 days · not informed B · R$ 1.500 · not informed · not informed C · R$ 2.100 · 1 day · back seats without seat belts
Three lines, only what was in the quotes. "Not informed" means the quote doesn’t say that, and it’s not that the risk is zero.
Without a stop point, the AI decides on its own when it arrives. Sometimes it stops too early. Many times it goes too far. Tell it the size of the result and the point where it should deliver.
Lúcia ordered a comparison of microscope kits for the lab. She limited it to three kits, from the catalogs she pasted, and a table. In one page, she got what used to take five.
Request: "Compare microscope kits."
Result: five pages, with kits from stores she didn’t even know.
Request: "Only the three kits from the pasted catalogs. A table. Deliver it and stop."
Result: one page, three lines, ready to check.
Net gain: from five pages to one, with everything coming from the material she provided.
Stuck here? That's normalYour account doesn’t have Work? The request works the same as a regular chat. Paste the practice template, with the material, and ask for the delivery in a single response. What changes is the request, not the tool.
Practice now 0/3
Ready when the result comes only with the options you gave, in the requested format, and with "not informed" where a piece of data was missing. About 10 minutes, in Work if your account has it, or in the chat you already use.
Use fictional options or public data, without a student name or secret value. Are the options in PDF or on WhatsApp? Type only the essentials of each one, on one line. If the AI brings an option you didn’t give, reply: "Use only the options I pasted".
OBJECTIVE <ex.: compare three options of ... to decide ...> INPUTS: USE ONLY THIS MATERIAL <paste here the three options> OUTPUT <ex.: table with price, timeline, and risks> LIMITS Don’t search for other options. Missing data becomes "not informed". STOP POINT Deliver the table and stop.
Objective: choose a microscope kit for the lab.
Inputs: Kit 1: R$ 900, 10 units. Kit 2: R$ 750, delivery in 15 days. Kit 3: R$ 1.100, 12 units, 1-year warranty.
Output: a table with price, quantity, timeline, and warranty.
Limits: don’t search for other kits; missing data becomes "not informed".
Stop point: deliver the table and stop.
You just swapped an endless search for a delivery with a beginning, middle, and end.
Lesson cheat sheet
Work allows delegating a task with a reviewable result, such as an analysis or a document. It can use approved files and tools. Instead of monitoring every sentence, you define what must exist at the end and track the relevant steps. Availability depends on the account and environment.
Work with multiple inputs needs a clear definition of “ready”. Without it, the agent may keep researching when you only needed a comparison of three options.
Goal; sources; delivery; limits; stop condition.
A manager provides fictional data of three suppliers and requests a table with price, deadline and risks. Determines that missing fields be marked as not informed.
Turn “search suppliers” into a one‑page order, limited to three alternatives and the provided documents.
Lesson 8 · OSWork v6.2 · INEMA.CLUB PRO
Module 2 · Lesson 3 of 6

You can set up a training folder with two texts. And have the AI say which files it received, with the first and last line, before the summary.
Many task failures are access failures. You imagine the AI sees a folder, but it was never shared. Then the answer talks about documents the model never read.
In 1 minute
The Desktop is the app that sits on your computer. If your app offers that, it can open folders and other apps, always with your permission.
In the browser chat, you attach or paste each file. In both cases, the AI only reads what reached it.
Lúcia uses the chat in the school’s browser and the Desktop on her home notebook. In both, she checks what the AI received before asking for the request.
You attach or paste each file.
The AI reads what you handed in.
It can open a folder you chose when granting permission.
The AI reads what that permission allows it to reach.
Giving access is like handing over the key to a drawer, not the key to the whole school. Put only what the task needs into a subfolder. When the app asks for access, choose only that subfolder. Screen names change between versions; what doesn’t change is choosing the smallest folder possible.
The science fair folder has three versions of the budget. Denise wants to test the AI without risking the original. She authorized only the examples subfolder, with two copies.
Before the comparison, ask for the names of the files the AI can read. Along with that, the first and last line of each one. A name alone doesn’t prove it was read. The first and last line show the beginning and the end arrived, and you verify it in the file.
If the list comes back wrong, the problem is access, not the request. Fix access and repeat the list.
YouList the files you can read and copy the first and last line of each. Don’t compare or summarize yet.
AII can read 2 files: orcamento-v1-copia first: "Science fair, materials budget, version 1" last: "Total: $ 640.00" orcamento-v2-copia first: "Science fair, materials budget, version 2" last: "Total: $ 710.00"
Two names, with the first and last line matching the files. Now the comparison can begin.
If Desktop doesn’t exist on your account, or it can’t reach the folder, send the files using a path that works. Attach it in the chat using the attach button next to the message box. Or paste the text with a header that includes the file name.
Lúcia pasted two texts into the browser chat, each with the name on top. She asked for the list before the summary.
You=== file: roteiro-experimento === Mix water and oil in a clear cup. Observe for two minutes. === file: lista-materiais === Clear cup, water, cooking oil, spoon. Total time: ten minutes. List the files you received, with the first and last line of each. Don’t summarize yet.
AII received 2 files: roteiro-experimento: "Mix water and oil in a clear cup." … "Observe for two minutes." lista-materiais: "Clear cup, water, cooking oil, spoon." … "Total time: ten minutes."
The header gives a name to each text; the first and last line show that the beginning and the end arrived.
Stuck here? That’s normalNo Desktop, and you don’t know if your chat supports attaching files? Use the header path: paste each text with "=== file: name ===" on top. It works in any chat, even on your phone.
Practice now 0/4
Ready when the AI lists both names and the correct first and last line of each one, before you ask for the summary. About 10 minutes. On the computer, follow the steps. On your phone, write the two notes in the notes app and paste them into the chat, each one with the step 4 header.
The practice folder has only made-up text, so nothing real leaves your computer. That’s the one you attach, and that’s the one you would choose in Desktop. If the list comes back with the wrong or missing name, don’t ask for the summary: resend the file and ask for the list again.
You just separated an access problem from a request problem, before it turned into the wrong answer.
Lesson cheat sheet
Desktop means an app installed on your computer. In compatible environments, it can access folders and apps with permissions. Having the app doesn't give universal access to your documents. If a tool is unavailable, provide the files via a supported path.
Many task failures are access failures: the student assumes the agent sees a folder, but it wasn't shared. Verifying the context before execution avoids conclusions about documents the model never read.
Authorized folder; local access; tool available; read confirmation.
A folder contains three budget versions. The manager authorizes only the examples subfolder and asks the agent to list the files it can read before comparing.
Lesson 9 · OSWork v6.2 · INEMA.CLUB PRO
Module 2 · Lesson 4 of 6

You can write, for your own task, where it runs, where it reads the inputs, and where it saves the results.
A task doesn't stay permanent just because you started it on a modern screen. If you don't know where it runs, you don't know why it stopped. Or where to look for the result.
In 1 minute
In local execution, the work runs on your machine. It’s like a cake in your home oven: if the power goes out, the oven stops.
Power, network, and your computer’s permissions matter. If the notebook sleeps, the task can stop halfway through.
Lúcia asked the app Desktop, from lesson 9, for a review of lesson plans that only exist on her notebook. She closed the lid at 6:00 PM and left. The next day, the review had stopped halfway through.
In the cloud, the work runs on remote computers. It’s like a bakery: the oven doesn’t depend on your home. But the baker only has the ingredients you brought.
The chat you already use is an example: the model works on the company’s computers. That’s why it only knows what you pasted or attached.
Denise wants the draft of her attendance report to be ready even if she turns off the notebook. For that, the spreadsheet needs to be somewhere the cloud can reach.
Depends on: your turned-on computer, with network.
Reads: the folders on your machine that you allow.
Depends on: the tool and your plan, not your machine.
Reads: only the files that were sent or connected to it.
Some environments run in the cloud and keep going without your machine turned on. That depends on the feature, not just the name Work or whether the screen is modern.
When in doubt, replace the assumption with three questions. Look for the answer in the tool’s help page. Or test: start a short task, close your notebook for ten minutes, and see if it made progress. Couldn’t tell? Turn it into an open item. In your everyday chat, wait for the full answer to appear before closing the tab. That way you don’t have to guess what happens to a response halfway through.
"I started in Work, so it runs on its own."
"The result must be somewhere."
Where does this task run?
Does it keep going with the notebook closed?
Where does it save what it creates?
Test yourself
Denise started a task in Work and closed the notebook. Does the task keep running?
For each task, write where it runs, where it reads the inputs from, and where it saves the outputs. Don’t know one of them? Write it as an open item. A written open item is better than a forgotten assumption.
The right place is the project sheet, created in lesson 5. Didn’t do lesson 5? Use any notepad.
Denise wrote the three lines from the attendance report and an open item. With the open item, she went to ask the school’s support.
Stuck here? That's normalLocal and cloud feel abstract until the first task stops. If you can’t answer a line, write "open item" and keep going. The lesson still meets its goal: you know what you need to find out.
Practice now 0/3
Done when you have three lines, or two lines and one open item, for a real task. About 8 minutes, on your computer or phone, in the project sheet or in a notepad.
It’s just notes: nothing is run or sent. If no answer comes back, that’s fine. Three written open items already show what to ask.
Task: <ex.: review lesson plans> Runs: <on my computer / in the cloud / don’t know> Reads the inputs from: <which folder or file> Saves the outputs to: <where the result is> Open item: <what I still don’t know>
You just mapped where your work happens—something almost nobody does before the first failure.
Lesson cheat sheet
Local execution runs on your machine. Cloud execution runs on remote infrastructure. A local job depends on power, network, and computer permissions. Some environments offer cloud execution that continues without the machine being on; this depends on the functionality, not just the Work name.
An automation doesn’t stay permanent just because it was started in a modern interface. You need to know where the process lives, where the files are, and which connections it depends on.
Execution location; persistence; file access; continuity.
A file review that exists only in the notebook can stop if the computer sleeps. A service on the VPS continues, but it only knows the files transferred to it or connected to it.
In your record, write where the task runs, where it reads inputs and where it saves outputs. If you don’t know, treat this as a pending item.
Mix the training copy with private files or production work.
Lesson 10 · OSWork v6.2 · INEMA.CLUB PRO
Module 2 · Lesson 5 of 6

You can fill in all six parts of a delivery contract and swap "good" for a criterion another person can check.
The AI doesn’t need to guess whether you want an explanation, a file to edit, or a ready text to publish. When you name what must exist at the end and how to verify it, the detour shows up before it becomes rework.
In 1 minute
Think about the service work order of a technical support shop. It has fixed fields: the device, the problem, what not to touch, how to test on delivery. Nobody writes "fix it properly".
The delivery contract is the work order of lesson 8 with a sixth part: verification. The lesson 6 authorization, in module 1, fits inside it: objective and stopping continue, files become inputs, actions and time become limits.
Denise wants the draft minutes from the educational meeting based on the agenda. She filled in all six fields in four minutes.
"Make minutes" leaves the format, size, and what to do with what’s missing open. The contract answers all three: fixed format, defined length, and absent data marked. The AI stops guessing.
YouMake good minutes for this meeting. [agenda pasted]
AIMinutes of the Educational Meeting, held on March 12, at 2:00 PM, in the teachers' room. The following teachers were present…
The date, time, and location were not in the agenda. The AI filled them in with a guess.
You[the six contract fields] Agenda: 1. Science fair calendar. Responsible: Lúcia. 2. Math reinforcement. Responsible: Marcos. 3. Science fair materials.
AIDraft minutes. Date: [not provided in the agenda] 1. Science fair calendar. Responsible: Lúcia. 2. Math reinforcement. Responsible: Marcos. 3. Science fair materials. Responsible: [not provided]. Verification: the 3 items and the 2 responsible parties from the agenda are in the minutes. The missing date and responsible party were marked. I did not send anything.
Nothing was invented, and what was missing appears marked.
"Good", "clear", and "complete" are wishes. Nobody can verify a wish. Verification uses criteria that anyone can check by looking at the result, like the quality ruler of lesson 4.
Lúcia asked for experiment scripts that were "well explained." She replaced that with two criteria. Now she checks each script in one minute.
"A well explained and complete experiment script."
Every step starts with a verb.
Every material mentioned in the steps is in the materials list.
Net gain: two criteria that any peer can verify without asking what she meant.
An easy-to-inspect outcome shows the error on the first read. That’s why the contract asks for a fixed format and a written check at the end.
In Denise’s minutes, the check said "2 responsible parties". She counted in the agenda and in the minutes: 2 and 2. It took 30 seconds, because the minutes was a list.
A one-page, continuous text about the meeting.
To find an error, you reread everything.
One item per agenda point, with the responsible person.
You compare line by line with the agenda.
Test yourself
Which of these checks can another person verify by looking at the result?
Stuck here? That's normalSix fields look like a lot the first time. Write one sentence per field, even if it’s short. If a field doesn’t apply, write "none". The field that makes the biggest difference is the check.
Practice now 0/3
Ready when the response ends with the verification you asked for and you’ve checked a direct criterion in the material. About 10 minutes, in the chat you already use.
Use an invented agenda, with no real names. The prompt asks that nothing be sent; in lesson 12 you check whether it was like that. Save the response: lesson 12 uses this submission for the review.
OBJECTIVE <ex.: revised meeting agenda, ready for me to send> INPUTS: USE ONLY THIS MATERIAL <paste an invented agenda with five items> OUTPUT <ex.: numbered list with the five items and the responsible person for each> LIMITS Don’t invent dates or names. Missing data becomes [not provided]. CHECK Say whether the five items are in the output and mark what’s missing. PROMPT Submit the revised agenda and send nothing else.
Objective: revised meeting agenda for parents of the 8th grade.
Inputs: 1. Term grades, with the science teacher. 2. Science fair, with coordination. 3. Phone use. 4. Trip to the museum. 5. Questions.
Output: numbered list with the five items and the responsible person for each.
Limits: don’t invent dates or names; missing responsible party becomes [not provided].
Check: say whether the five items are in the output and mark what’s missing.
Prompt: submit the revised agenda and send nothing else.
You just wrote a request that says what must exist at the end and how to check.
Lesson cheat sheet
A good request includes an objective, context, inputs, constraints, a result, and verification. These are fields of a shipment, not magic words. The easier it is to inspect the output, the easier it will be to catch a deviation before it turns into rework.
The agent doesn’t need to guess whether you want an explanation, an editable file, or a publication. Naming the artifact and the ready condition shortens the distance between intent and execution.
Artifact; format; authorized sources; observable criterion.
“Use pauta.txt to create ata-rascunho.md. Preserve all responsible parties, flag missing dates and do not send anything.” This request determines inputs, output and a concrete limit.
Use the file materiais/contrato-de-tarefa.md. Fill each field with a sentence and replace “good” with a criterion that someone can verify.
Lesson 11 · OSWork v6.2 · INEMA.CLUB PRO
Module 2 · Lesson 6 of 6

You can verify a fact, a format, and an action in an AI delivery. And note what you observed in each one.
The word "ready" doesn’t show that the file opens or that the data was kept. A small review you do yourself usually finds more problems than asking again to "improve".
In 1 minute
It’s like checking a grocery bag against the receipt before you leave. It’s not enough for the bag to be full. Each item on the receipt has to be there, and nothing extra.
Lúcia received the minutes from the sciences area meeting. She compared each decision with the agenda. She found a responsible person the AI invented.
1. Lab schedule. Responsible: Lúcia.
2. Purchase of reagents. Responsible: not defined.
1. Lab schedule. Responsible: Lúcia.
2. Purchase of reagents. Responsible: Paulo.
Net gain: an invented name, found in two minutes of comparison.
You don’t need to reread everything. Choose three points. A fact that matches the source. A format, which is what was requested. And an action, that works or was done the way it was agreed.
In the attendance report, Denise checked the total number of absences for a class and whether the file opened with the requested columns. Then, she tested the spreadsheet link mentioned in the report.
Ask the AI for the evidence of what it checked. And ask it to separate what it truly verified from what it only suggests you check.
"I reviewed everything" doesn’t say what was reviewed. A list does: and it shows what’s left for you. Even the AI’s "I verified" is a claim—check one item from the list as a sample.
YouAre you ready to sign the minutes?
AIYes! I reviewed everything and it’s correct.
It doesn’t say what was verified. You can’t know.
YouShow what you verified, side by side with the agenda, and say what you left unverified.
AIAgenda 1, Lab time → minutes 1, Lab time: same. Agenda 2, Purchase of reagents → minutes 2, Purchase of reagents: same. Not checked: whether each responsible person is the same as in the agenda. I suggest you compare that column.
The items appear side by side for you to verify, and what’s missing is stated: the responsible persons column.
Test yourself
Which of these AI answers includes evidence that you can verify?
Write down what you observed in each verification, with the exact result. Did you find an error? Correct the request too before reusing it, or the source if the mistake came from it. If not, the same error will come up again next time.
Lúcia corrected the name in the minutes. Then she added a line to the delivery contract: "responsible that the agenda doesn’t define becomes [not informed]".
Stuck here? That's normalDid you find no errors at all? Great sign, and the verification mattered just the same. Write "✓" next to what you compared. The record shows that you looked—not just that you trusted.
Practice now 0/3
Ready when you have three notes—one for each check—with the result you observed. About 10 minutes, on paper or in a notepad, on your phone or on your computer.
You only read and compare: nothing is changed or sent. Didn’t do lesson 11? Use the outline and the practice minutes right below.
Outline: 1. Exam week, with coordination. 2. Room change for 8º B, with no responsible person defined. 3. June festival, with teacher Ana.
Received practice minutes: 1. Exam week. Responsible: coordination. 2. Room change for 8º B. Responsible: teacher Ivo. 3. June festival. Responsible: teacher Ana. Sent to the teachers group.
You just did the part of the submission that no AI does for you: checking.
Lesson cheat sheet
A submission only ends after the check. Open the file, compare numbers with the sources, and test the relevant links or formulas. Ask the agent for evidence of what it verified, distinguishing between test run and test suggestion.
The word “ready” does not demonstrate that the file opens or that all data were preserved. A small independent verification often finds more problems than a new generic improvement request.
Open; compare; test; record limits.
The minutes have a list of decisions. The teacher confronts each decision with the agenda and finds an invented responsibility. She corrects the source or the request before reusing the procedure.
Review three elements of your delivery: a fact, a format and an action. Note exactly the observed result for each.
Use fictional files and a training folder. Practices with installation, Telegram, or VPS may require extra time for sign-up and configuration.
Read the block before using. Fields like Your Name and usuario@ip-da-vps are examples to adapt; administrative commands belong only to your training environment.
Goal: prepare a revisable outline
Input: entradas/reuniao.txt
Output: saidas/pauta.md
Limits: do not send messages; do not invent dates
Check: the 5 original items are still present
Stop: deliver the file and report the open itemsDraft a work order with inputs, output and review. Record the produced file, the executed test and the observed result.
Use this rubric after the lab. Each line asks for evidence; checking reading does not mean the practice was performed.
You only need an explanation of two sentences. Must you necessarily use Work?
No. Choose the interface based on the result you need; Chat may be enough.
If your answer was different, return to the corresponding topic and write the difference in one sentence. The check does not block your study.
Tools verified on 20/09/2026; screen names and availability may change.
Lesson 12 · OSWork v6.2 · INEMA.CLUB PRO
Module 3 · Lesson 1 of 6

You can open the terminal, type two commands, and tell where the folder is and what's inside it.
Starting in this module, the AI works in a folder on your computer. If you don't know what folder you're in, it doesn't know either. A lot of what looks like an AI failure is just the wrong folder.
In 1 minute
pwd tells where you are. ls tells what is there.The terminal is already included on your computer. You just need to know where it is. The commands in this course are written in Bash, the terminal language on Linux and macOS. Mac uses a variation of it, and the commands work the same.
On Windows, they work inside the WSL. The terminal that comes with Windows uses a different language. Don't paste the course commands into it without adapting them.
Lúcia uses a notebook with macOS. She pressed Cmd+Space, typed "Terminal", and hit Enter. It took ten seconds.
WSL is from Microsoft itself. Open the Start menu, search for "PowerShell", right-click › Run as administrator. Type the command below, press Enter, and restart the computer when it asks.
> wsl --install
After you restart, search for "Ubuntu" in the Start menu: this window is the terminal where the course commands work. On the first run, it asks for a new username and password: write the password down somewhere safe.
Stuck here? That's normalIs the computer from the school or did it ask for a password you don't have? Don't force it: read this lesson today and ask the WSL installation from whoever manages the computer. In lesson 14, the official page of the Codex also shows the path for Windows.
When you open it, the terminal shows a short line that ends with $, with a blinking cursor. On the Mac, it ends with %: it’s the same thing. It’s the computer waiting for your command.
You type the command and press Enter. The response appears right below. Then the $ comes back, ready for the next one.
Denise opened the terminal for the first time and waited for something to happen. Nothing happened, because it was waiting for her.
denise@notebook:~$ pwd
/home/denise
denise@notebook:~$
The line with $ (on the Mac, %) is your turn to type. The line without $ is the computer’s response.
$ back: it’s always this back-and-forth.pwd is the "you are here"Do you know the school map with the "you are here" sticker? The pwd command does that. It tells you the full path of the folder you’re in right now.
Read the path like an address. Each slash separates a folder, and the last one is where you are. On macOS, your personal folder starts with /Users; on Linux, with /home.
Lúcia typed pwd and read /Users/lucia. So she was in the personal folder, the same one that opens when you click the little house in Finder.
$ pwd
/Users/lucia
A single line: Lúcia’s personal folder. Nothing was created or deleted.
pwd command only informs. Use it whenever you’re unsure where you are.ls shows what’s in the folderOnce you know where you are, see what’s there. The ls command lists the folders and files in the current location, side by side. On the Mac, the personal folder’s folders appear with English names, like Documents and Downloads.
To change folders, use cd. It’s in lesson 16. For now, just know that the starting folder matters.
Denise opened the Codex in the Downloads folder, during a test by a colleague. He couldn’t see her project, which was in another folder. The pwd would have shown that earlier.
$ pwd
/home/denise
$ ls
Documentos Downloads Imagens Músicas
First the location, then the contents. The names change from one computer to another.
ls shows what the program will see if it starts working from there.Test yourself
Lúcia typed ls and the project folder didn’t appear in the list. What does she check first?
Practice now 0/3
Ready when you’ve written down the answer from pwd and three names that ls showed. About 8 minutes, on the computer.
Those two commands only read: nothing is created, moved, or deleted. If you see “command not found”, check what you typed: everything in lowercase, with no space in the middle. On Windows without WSL, stop at step 1 and continue with lesson 14.
pwd ls
You just read, in the terminal, where you are and what’s there, without changing anything.
Lesson cheat sheet
Terminal is the window where you type commands for the computer. Shell is the program that interprets those commands. Here, the terminal examples use Bash on Linux or macOS; on Windows, use a Bash environment via WSL or follow the official installer for Windows. Don’t paste Linux commands directly into PowerShell without adapting them.
Knowing which environment you are in avoids errors that seem like AI failures. The cd command changes the current folder; pwd shows the location in Bash. You do not need to memorize dozens of commands to get started.
Terminal; shell; current folder; command and response.
If you open Codex in the Downloads folder, it is not automatically working inside meu-primeiro-projeto. You need to choose the starting folder.
In Bash, run pwd and then ls. Read the output: first the location, then the files. Do not change anything in this step.
Accepting a conclusion without checking the input that supports it.
Terms for this section: port.
Lesson 13 · OSWork v6.2 · INEMA.CLUB PRO
Module 3 · Lesson 2 of 6

You can install the Codex using the official address and confirm, with a command, that the computer recognizes it.
On the internet, "faster" commands circulate to put programs on your computer. Pasting a command without checking can run anything. Checking the source takes a minute and avoids that risk.
In 1 minute
codex --version confirms it worked.Installing puts the program on your computer. It does not connect your account or choose your work folder. Each thing has its own step and its own check.
This lesson only covers the first one. The other two come in lessons 15 and 16.
Right after installing, Lúcia typed codex and the program asked her to sign in with her account. She thought it was broken. It wasn’t: the first step had worked, and the second one was missing.
codex --version.pwd, from lesson 13.When a box arrives in the office, you check the seal and the sender before you open it. With a command, it’s the same: the sender is the address it comes from.
The official command downloads a script from the address chatgpt.com and runs it. That’s why the address matters so much. Don’t paste commands from an unknown page.
Denise received a "faster way" to put Codex on the computer in a group. The address in the middle of the command wasn’t the official page’s address. She didn’t paste it and used the official page instead.
Address in the command: a site with "codex" in the name, but not chatgpt.com.
Who guarantees: nobody.
Address in the command: https://chatgpt.com/codex/install.sh
Who guarantees: the company that makes the program, on the installation page.
On macOS and Linux, the command from the official page is the one below. On Windows with WSL, paste the same command inside the Ubuntu. Without WSL, follow the official Codex page, which has its own instructions.
Use the copy button: you don’t need to type the vertical bar. The installer writes a few lines while it’s working, and you don’t need to understand each one. Wait for $ (on Mac, %) to come back. The one that confirms it worked is step 4.
Lúcia pasted the command into the Mac Terminal and waited. She didn’t try to decipher the lines that scrolled by. When the % returned, she moved on to the check.
$ curl -fsSL https://chatgpt.com/codex/install.sh | sh
It’s one line, even if your phone screen breaks it into multiple lines. curl downloads the file from the address; the vertical bar pipes it to the sh, which runs its commands.
codex --version confirmsTo see if it worked, ask for the version. If the computer recognizes the program, it responds with a number.
If you see "command not found", the terminal hasn’t found the program yet. Close the terminal, open it again, and repeat.
On Denise’s laptop, the first attempt returned "command not found". She closed the terminal, opened another one, and typed it again. The version number came back.
$ codex --version
codex: command not found
$ # fechou e abriu o terminal de novo
$ codex --version
codex-cli 0.156.1
"command not found" means "I didn’t find this program". After reopening, the version came back. The number changes over time.
Stuck here? That's normal"command not found" right after the first time is common: the terminal that was already open didn’t know about the new program. Close, open again, and repeat codex --version. Did it continue? Copy the error message, with no password at all, and take it to whoever manages the computer.
Practice now 0/3
Ready when codex --version responds with a number. About 10 minutes, on the computer, with internet.
The command only works if it matches the one on the official page: check that it’s chatgpt.com. If it asks for your computer password and it’s yours, type yours: the letters won’t appear while you type. If the computer is from your school, pause and talk to whoever manages it.
Step 2 · paste into the terminal
curl -fsSL https://chatgpt.com/codex/install.sh | sh
Step 3 · paste into the new terminal
codex --version
You just put a program on your computer using the official source and verified that it’s there.
Lesson cheat sheet
The official Codex page offers an installer for macOS/Linux and specific guidance for Windows. Installing means adding the program to the machine. The installation command downloads and runs an official script; read the source, verify the domain, and use your own account. Don’t run commands received from unknown pages.
Installation, login, and running are different steps. A installed program still needs authentication. A completed login doesn’t mean you opened the right folder.
Official source; installation; version; diagnostics.
After installation, terminal shows the version recognized by codex --version. If you see “command not found”, reopen the terminal and check the path indicated by the installer.
On macOS/Linux: curl -fsSL https://chatgpt.com/codex/install.sh | sh. Then check with codex --version. See the source at the footer for other platforms.
Lesson 14 · OSWork v6.2 · INEMA.CLUB PRO
Module 3 · Lesson 3 of 6

You connect the Codex to your account, check which method it used to enter, and record only that method in the form, with no password.
A key pasted into a message, an example, or a screenshot can be used by someone else, and the account is yours. You can also be connected using the wrong method and spend from an account you didn’t expect.
In 1 minute
codex login opens the browser so you can sign in with your ChatGPT account.codex login status tells by which method you signed in.At school, you pass your badge through the turnstile and no one hears your password. The Codex login works like this: the terminal takes you to the browser, and that’s where you sign in.
The password never goes through the terminal. When you’re done in the browser, Codex receives the confirmation and stores what you entered.
ChatGPT plans that include Codex change over time. Before you start, check on the official authentication page whether your plan is listed there. The name of your plan shows up in the settings of your ChatGPT account.
Lúcia typed codex login. The browser opened on the ChatGPT sign-in screen. She signed in with the school account and went back to the terminal.
$ codex login
# o navegador abre; entre com a conta do ChatGPT e volte ao terminal
The first line is what you type. The second is a course reminder: the rest happens in the browser.
codex login status tells you the methodBeing signed in isn’t enough: it matters which path you use. Signing in with your account uses that plan. A API key is charged per usage, on another account.
That difference is from lesson 5, in module 1. If you skipped it, here’s the summary: it’s two accounts, with two charges.
Denise expected to see "ChatGPT" and saw that Codex was signing in using an old school API key. She left with codex logout and signed in again with codex login, using the account.
$ codex login status
Logged in using ChatGPT
In English: "signed in using ChatGPT". The method is the account. With an API key, the response mentions the key, but never the full value.
Are you going to sign in via your ChatGPT account? You can skip this step. If you use the API, the key is stored under a name, OPENAI_API_KEY, which the terminal knows. The official command passes the value directly to Codex, without showing it on the screen.
Typing the key into the command is the common mistake: it stays in the terminal history and shows up in any print. A standalone .env file also doesn’t connect anything. Some mechanism has to load the value.
A coworker asked for the school key to test at home. Lúcia didn’t send it in the group. She explained that the key tells who pays, and each person signs in with their own account.
How it looks: codex login --with-api-key followed by the full key.
Result: the key stays in the history and in any screen print.
How it looks: printenv OPENAI_API_KEY | codex login --with-api-key
Result: the value goes straight to the program. On the screen, you only see the command.
In the project sheet, which method is active and where you checked it. It’s the same access sheet from lesson 5. No sheet yet? A note on your phone is enough.
The credential doesn’t go in the sheet, into a request, or into a screenshot. If it leaks, whoever manages the account needs to rotate the key.
Denise’s line ended up like this: "Codex · ChatGPT · checked with codex login status". No password, no piece of key.
Stuck here? That's normalDon’t know whether you use ChatGPT or an API? Start with your ChatGPT account, with codex login: that’s the path with no key at all. Did the browser not open by itself? Check whether the terminal showed an address, and open that address in the browser.
Practice now 0/3
Done when codex login status reports the method and the sheet has that line, with no password. About 8 minutes, on the computer.
In this approach you don’t type a password in the terminal: it stays in the browser. Didn’t do lesson 14? Check first with codex --version. Computer of another person? When you’re done, sign out with codex logout.
Step 1 · paste into the terminal
codex login
Step 2 · paste into the terminal, after you sign in in the browser
codex login status
You just connected a program to your account and recorded how, without exposing any credential.
Lesson cheat sheet
Run codex login and complete the browser flow to sign in with ChatGPT. If you choose the API, the key needs to be in the variable OPENAI_API_KEY; forward it through standard input, without typing it in the command. A single .env file doesn’t authenticate Codex: some mechanism must load the variable.
Pasting the key in examples, messages, or history can expose the account. It is also possible to be authenticated by the wrong method and consume a different modality than expected.
codex login; codex login status; standard input; active account.
For the API, the documented command is printenv OPENAI_API_KEY | codex login --with-api-key. It sends the value directly to the program instead of displaying the key on the screen.
Lesson 15 · OSWork v6.2 · INEMA.CLUB PRO
Module 3 · Lesson 4 of 6

You can create a training folder with three fake files, enter it using the terminal, and open the Codex there.
Codex works in the folder it was opened in. In the wrong folder, it reads things it shouldn’t and doesn’t find what it needs. A small folder, with only the task material, makes it clear what it could touch.
In 1 minute
cd enters the folder, pwd confirms, and only then codex.If you enter the wrong room, you give the lesson to the wrong group. With Codex it’s the same: it works where it was opened. So you enter the folder before you open the program.
mkdir -p creates the folder, and the previous ones if they’re missing. cd enters it. The ~ sign means "my personal folder": on the Mac Finder, it’s the folder with your name and the house icon.
Denise created the training folder and entered it. The pwd confirmed the address before she opened any program.
$ mkdir -p ~/projetos/meu-primeiro-projeto
$ cd ~/projetos/meu-primeiro-projeto
$ pwd
/home/denise/projetos/meu-primeiro-projeto
The first two commands don’t show anything when they work. The one that confirms is pwd.
You don’t need to open your entire personal folder to experiment. A small area, with training files, reduces confusion. When something goes wrong, it’s clear which files could have changed.
Lúcia thought about opening Codex in the Documents folder, where the exams and class notes are. She preferred the training folder, with a fake agenda. Nothing real was within reach.
The README describes the project’s purpose for anyone who arrives. The AGENTS.md gives working instructions to the agent.
Both end in .md because they are text in Markdown: the # marks the title, and the hyphen marks a list item.
Denise wrote the purpose in the README: prepare the meeting agenda. In AGENTS.md, she added two rules: work only in that folder and don’t send anything.
# My first project
Training project for the OSWork course. Only fictional files.
Purpose: prepare the pedagogical meeting agenda from entries/reuniao.txt.
# Instructions for the agent
- Work only inside this folder.
- Don’t send or publish anything.
Before typing codex, run pwd and ls. If the address and the files match, open the program there.
On the first time in a folder, the Codex asks if you trust it. It’s your training folder: choose "Trust and continue" using the arrow keys and press Enter. In this training, don’t use "Open restricted". To exit the Codex, type /quit and press Enter.
Lúcia checked the address, saw the three items in ls, and only then typed codex. She answered the folder question and exited with /quit, without asking for anything yet.
$ pwd
/Users/lucia/projetos/meu-primeiro-projeto
$ ls
AGENTS.md README.md entradas
$ codex
Trust this folder? Codex can read, edit, and run files here,
subject to your permission settings. …
› Trust and continue
Open restricted
In English: "Do you trust this folder? The Codex can read, edit, and execute files here, within its permissions." "Trust and continue" is "trust and continue"; "Open restricted" opens with restrictions. The answer is saved. The words may change a bit with the version.
Stuck here? That's normalThe question in English scares you the first time. It only shows up because the folder is new to the Codex. Confirm only for folders you know. If you’re unsure, exit with /quit (or press Ctrl+C twice) and check the pwd again.
Practice now 0/3
Done when the ls shows AGENTS.md, README.md, and entries, and the Codex opens in that folder. About 10 minutes, on the computer.
The block creates a new folder and writes three fictional files inside it: each cat > writes into the file everything up to the FIM line. Nothing outside it is touched. Use the block only in this new folder: in another folder, it would overwrite a README.md that was already there. Copy the entire block, up to the last ls. If the terminal sits there showing >, press Ctrl+C and paste the entire block again.
mkdir -p ~/projetos/meu-primeiro-projeto/entradas cd ~/projetos/meu-primeiro-projeto cat > README.md <<'FIM' # My first project Training project for the OSWork course. Only fictional files. Purpose: prepare the pedagogical meeting agenda from entries/reuniao.txt. FIM cat > AGENTS.md <<'FIM' # Instructions for the agent - Work only inside this folder. - Don’t send or publish anything. FIM cat > entradas/reuniao.txt <<'FIM' Pedagogical meeting (fictional) 1. New library schedule 2. Science fair games 3. 8th grade remediation 4. Use the classroom notebooks from the computer lab 5. Exam dates: to be defined FIM pwd ls
You just set up a small workspace and opened the agent exactly inside it.
Lesson cheat sheet
The working folder is the task bench. Create a small area, with training files, before allowing changes. A README.md describes the purpose for people; AGENTS.md gives operational instructions to the agent. You don’t need to open your personal folder in full to experiment.
A small scope reduces ambiguity and makes reviewing differences easier. When something goes wrong, it is clear which files should have been affected.
Local scope; README; AGENTS; input files.
The project contains README.md and entradas/reuniao.txt. The first task is to explain these two files. No access to personal documents or other projects is needed.
In Bash: mkdir -p ~/projetos/meu-primeiro-projeto. Go into cd ~/projetos/meu-primeiro-projeto and start codex.
Mix the training copy with private files or production work.
Lesson 16 · OSWork v6.2 · INEMA.CLUB PRO
Module 3 · Lesson 5 of 6

You can ask the Codex to read the folder with zero editing and check which files it used. Then, you authorize only the creation of a plan.md, which you double-check yourself.
A request like "fix the project" mixes diagnosis and change. If something goes wrong, you don’t know which part it was. Separating reading and changes gives you a reference for review.
In 1 minute
ls.No serious person starts a renovation by breaking down a wall. First comes the inspection: look, write notes, understand. With an agent, it’s the same order, in four steps.
Denise would ask Codex to "improve the meeting folder." She replaced it with two requests: first, read and say what’s missing; then, create a single file.
In the lesson 16 training folder, ask Codex to read the AGENTS.md and the README. Say it in plain words: without editing. And ask it to cite the files it used.
Lúcia made this request in the training folder. The response below is real, from Codex, in that same folder, just shortened.
YouRead AGENTS.md and README.md. Explain the purpose and list what’s missing, without editing. Say which files you used.
CodexThe purpose is to prepare the agenda for a pedagogical meeting using entradas/reuniao.txt. Missing: the produced agenda, the format, the output location, and how to verify the result. The input file exists, but I did not read its contents. Files read: AGENTS.md and README.md. I also consulted the file listing. Nothing was edited.
It explained, listed what’s missing, said what it read and what it didn’t read. No files changed.
The list of files used shows what the answer is based on. Compare it with what ls shows in the folder.
In the real response, Codex read two files and said it didn’t open the agenda. So the list of what’s missing comes only from the README. That’s a good read, but it still doesn’t know the five meeting items.
Denise read "I did not read its contents" and understood the response limit. In the second request, she made it clear that the plan should rely on the agenda.
AGENTS.md
README.md
the list of files in the folder
AGENTS.md
README.md
entradas/reuniao.txt, with the five items
Now authorize a small change: create only plan.md, with three actions and one verification for each. The Codex can ask "Would you like to make the following edits?". Check that the change is only in plan.md and choose "Yes, proceed". If it’s another file, choose the option that starts with "No". Did it create without asking? That also happens: your current permissions let you write in the folder. Check with ls.
After that, exit with /quit and read the file with cat plano.md, which shows the content in the terminal. Check whether the actions rely on what exists in the folder.
The plan Lúcia received covers the five items on the agenda and warns that times and dates still need to be defined. She checked in reuniao.txt: everything was there.
$ cat plano.md
# Plano de ações
Base: entradas/reuniao.txt (reunião pedagógica fictícia).
Horários e datas ainda precisam ser definidos.
1. Ação: Organizar o novo horário da biblioteca e as regras
de uso dos notebooks da sala de informática.
Verificação: Conferir se a proposta registra o horário
da biblioteca e as condições de uso dos notebooks.
…
A real file created by Codex with request 2 from the practice, shortened. If you repeat it, the text comes out different; what you check is whether it relies on the agenda.
Stuck here? That's normalThe plan cited a file that doesn’t exist in the folder? Don’t start from zero. Ask for the specific correction: "That file doesn’t exist. Recreate plano.md using only the files from this folder."
Practice now 0/3
Ready when plano.md exists in the folder and you’ve checked one of the verifications directly in reuniao.txt. About 10 minutes, on the computer.
The first request changes nothing; the second creates only one file in the training folder. Didn’t you do lesson 16? Her practice block sets up the folder in one minute. If Codex wants to change another file, refuse and repeat the request.
Step 1 · paste into the terminal
cd ~/projetos/meu-primeiro-projeto codex
Request 1 · paste inside Codex and press Enter
Read AGENTS.md and README.md. Explain the purpose and list what’s missing, without editing. Tell me which files you used.
Request 2 · paste inside Codex, only after the response to request 1
Create only plano.md, with three actions and one verification for each. Base the plan on entradas/reuniao.txt. Do not change any other file.
Step 3 · paste in the terminal, after exiting with /quit
cat plano.md
cat entradas/reuniao.txt
You just separated diagnosis and change, and checked the result in the real material.
Lesson cheat sheet
Start by requesting inspection: list the structure, read instructions and explain pending items. Ask the agent to cite which files it used. After checking, authorize a small, named change, such as creating plano.md with three next steps.
Separating diagnosis and change creates a reference for review. You learn the flow without mixing installation, major refactoring, and publishing in a single attempt.
Inspect; plan; change; validate.
Initial request: “Read AGENTS.md and README.md. Explain the purpose and list what is missing, without editing.” Second request: “Create only plano.md, with three actions and one verification for each.”
Open plano.md in the editor and check whether the steps are based on the actual project. Ask for specific correction if the agent assumed nonexistent files.
Lesson 17 · OSWork v6.2 · INEMA.CLUB PRO
Module 3 · Lesson 6 of 6

You can save a copy of the training folder and ask the Codex to add two new rules in AGENTS.md. Then, you compare the two versions and see that only this file changed.
In the last lesson, the agent created a file. If it had created the wrong one, or deleted something else, would you be able to say what existed before? Going back requires that you saved the "before" and compare.
In 1 minute
Whoever will use the lab gets the lab’s key, not the whole bunch. With an agent, it’s the permissions that control what it can reach in files, on the internet, and in commands.
Go up one step at a time. Reading files is low risk; writing is medium risk; executing commands is high risk. Each step increases the possible damage.
Denise gave the intern only the reading room key. With Codex, it started from the same principle: access only to the training folder.
What you write in AGENTS.md guides the agent’s behavior. But it’s text: it doesn’t technically prevent anything. What prevents things is the program’s permissions.
In Codex, the /permissions command shows and changes what it can do. Start with the most restricted option that covers the task. Don’t remove all protections to work around an error.
Codex asked Lúcia for internet access to consult documentation. She evaluated that request on her own, without also allowing it to delete files or send messages.
Example: "Do not send or publish anything."
What it does: guides the agent on what you want.
Example: access only to the training folder.
What it does: limits what it can actually do.
The cp -r command copies an entire folder, with everything inside. Make the copy before the change, with a name that tells you what it is.
Later, in module 5, the Git will do this in a more complete way. For now, the copy already gives you a rollback point.
Before authorizing the change in AGENTS.md, Denise copied the training folder with the ending "-before". The ls confirmed both.
$ cp -r ~/projetos/meu-primeiro-projeto ~/projetos/meu-primeiro-projeto-antes
$ ls ~/projetos
meu-primeiro-projeto meu-primeiro-projeto-antes
The cp returns nothing when it works. The ls confirms it: the two folders are side by side.
After the change, the diff compares the copy with the current folder. It shows only the differences, file by file. The lines that start with > are the new ones.
If another file shows up in the comparison, the agent changed something it shouldn’t have. The "-before" copy has the old version for you to recover.
In Lúcia’s diff, only one file appeared: AGENTS.md, with two new lines. It was exactly what she authorized.
$ diff -r ~/projetos/meu-primeiro-projeto-antes ~/projetos/meu-primeiro-projeto
diff -r …/meu-primeiro-projeto-antes/AGENTS.md …/meu-primeiro-projeto/AGENTS.md
3a4,5
> - Todo resultado vem com a verificação que você observou.
> - Esta tarefa não autoriza publicar nada.
One file mentioned, two lines with >. "3a4,5" means: after line 3, lines 4 and 5 were added.
Stuck here? That's normalThe diff output looks like code, but you only need two things: which files appear and which lines have >. Nothing appeared? Then nothing changed: check whether Codex saved the file.
Only if the diff showed a change you didn’t authorize. Copy the file from the "-before" folder over the current one. Attention: this replaces the current AGENTS.md with the old version.
$ cp ~/projetos/meu-primeiro-projeto-antes/AGENTS.md ~/projetos/meu-primeiro-projeto/AGENTS.md
Then, run the diff again: with no differences, the rollback worked.
Practice now 0/3
You’re done when the diff shows only AGENTS.md, with the two new lines. About 10 minutes, on your computer.
Everything happens in the training folder; the "-before" copy stays stored next to it. Didn’t do lessons 16 and 17? The practice block in lesson 16 sets up the folder in one minute. If the diff shows another file, don’t delete anything: write down what changed and recover it using the copy.
Step 1 · paste into the terminal, once
cp -r ~/projetos/meu-primeiro-projeto ~/projetos/meu-primeiro-projeto-antes ls ~/projetos
Step 2 · paste into the terminal
cd ~/projetos/meu-primeiro-projeto
codex
Step 3 · paste inside Codex and press Enter
Add these two lines to AGENTS.md, without changing the ones that already exist:
- Every result comes with the verification you observed.
- This task does not authorize publishing anything.
Don’t change any other file.
Step 4 · paste into the terminal, after exiting with /quit
diff -r ~/projetos/meu-primeiro-projeto-antes ~/projetos/meu-primeiro-projeto
Does the "-antes" folder already exist? Use these two blocks instead of steps 1 and 4. They use the name "-antes2".
cp -r ~/projetos/meu-primeiro-projeto ~/projetos/meu-primeiro-projeto-antes2
ls ~/projetos
diff -r ~/projetos/meu-primeiro-projeto-antes2 ~/projetos/meu-primeiro-projeto
You just made a verifiable change: you know what existed before, what changed, and how to get back.
Lesson cheat sheet
The client’s permissions control access to files, the network, and execution. Instructions in natural language guide behavior, but they don’t replace technical isolation. Start with permissions restricted to the training folder. Don’t teach removing all protections to bypass any error.
Recovering a change requires knowing what existed before. Git and file copies provide rollback points; they will be practiced later. Read what the command will do before expanding permissions.
Minimum permission; small changes; comparison; rollback point.
The agent requests external access to consult the documentation. Evaluate this need separately from permissions to delete files or send messages.
Write in AGENTS.md what results must come with observed verification and that the task does not authorize publishing. Review the diff when Git is active.
Use fictional files and a training folder. The practices with installation, Telegram, or VPS may require extra time for sign-up and configuration.
Read the block before using. Fields like Your Name and usuario@ip-da-vps are examples to adapt; administrative commands belong only to your training environment.
mkdir -p ~/projetos/meu-primeiro-projeto
cd ~/projetos/meu-primeiro-projeto
pwd
codex --version
codex login
codex login status
codexOpen a training project in Codex and produce a verifiable change. Record the file created, the test run, and the observed result.
Use this rubric after the lab. Each line asks for evidence; checking reading does not mean the practice was performed.
Codex did not find README.md. Is the first step to increase reasoning?
No. Check the current directory, the file name, and the read permission.
If your answer was different, return to the corresponding topic and write the difference in one sentence. The check does not block your study.
Tools verified on 20/09/2026; screen names and availability may change.
Lesson 18 · OSWork v6.2 · INEMA.CLUB PRO
Module 4 · Lesson 1 of 6

You can draw the tree of your projects folder, with config and a training project. And you can create it with a command in the terminal.
When everything is in just one folder, the AI reads material on topics that have nothing to do with the request. Then it becomes hard to say where a conclusion came from. Today you separate topics before creating any file.
In 1 minute
In the secretary's steel file, each drawer holds a class. Nobody searches for 8th A in the 7th B drawer. A work folder does the same: it gathers the material for just one topic. That material is the context of the task.
When you open the Codex in a folder, it works from that folder. If the folder mixes topics, anything that doesn't relate to the request becomes noise.
Lúcia stored the science fair project in the same folder as the report cards. She asked the AI for a summary of the fair and got a paragraph with a student's grade mixed in.
Everything in the same place: feira-de-ciencias.docx, boletins-8A.xlsx, ata-do-conselho.pdf.
Result: the fair summary mentions a report card grade.
feira-de-ciencias folder: only the regulations and the groups list.
Result: the summary talks only about the fair.
Net gain: the AI reads less material, and you know where each sentence came from.
In the terminal, the ~ (tilde) symbol represents your personal folder. Inside it, you will create a projects folder, which gathers independent work.
You read the path ~/projetos/config in this order: personal folder, then projects, then config. On the Brazilian keyboard, the tilde is produced with the tilde key followed by the space bar.
Denise typed pwd in the terminal, as in module 3, and saw the full address of her personal folder. The ~ is just the short way to write that address.
$ cd ~
$ pwd
/Users/denise
cd ~ takes you to your personal folder; pwd shows where you are. On Linux, and on Windows with the terminal from module 3, the address starts with /home, like /home/denise.
The config folder, for configuration, stores the knowledge that applies to any project, like your preferences. It sits inside projects, but outside each individual project.
Each project keeps its own entries, the material the AI reads, like minutes or spreadsheets. And it keeps its own results, what it produces. Separated, you can check one against the other. Don’t mix in a project documents from different classes or different schools.
Denise prefers short reports, with the pending items at the end. This applies to the council report and to the agenda for the parents meeting. So you go to config, just once.
Test yourself
Denise wants to store the note "I prefer short reports". Where does she put it?
Before creating anything, draw the tree on paper: one config folder and a single training project. That way you decide the names calmly.
Use short names, with no space and no accent, like meu-primeiro-projeto and saidas. In the terminal, space and accent add work to every command.
Lúcia drew it on a napkin: projects, with config and feira-de-ciencias; inside the fair, entries and saidas. It took a minute and avoided three folders with similar names.
$ mkdir -p ~/projetos/config ~/projetos/meu-primeiro-projeto/entradas ~/projetos/meu-primeiro-projeto/saidas
$ ls ~/projetos
config meu-primeiro-projeto
mkdir -p creates the folders and any folders above that are missing. If a folder already exists, it stays as it is.
Stuck here? That's normalThe command is long because it creates four folders at once. Copy and paste it exactly as it is, on a single line. To paste into the terminal, use the right mouse button › Paste; on your keyboard, Ctrl+Shift+V on Linux and Windows, Cmd+V on Mac. Prefer the mouse? Type cd ~ and then open . on the Mac, or explorer.exe . on Windows, inside the Linux terminal from module 3: the file manager opens in your terminal’s personal folder. Create the folders there, using right click › New folder.
Practice now 0/3
Ready when the first ls shows config and my-first-project, and the second shows inputs and outputs. About 8 minutes, on your computer.
The commands only create empty folders inside your home folder; nothing is deleted. Did you create my-first-project in module 3? All good—the things that are already there stay. Did an error message appear? Stop, check that you pasted the entire line, and try again once.
mkdir -p ~/projetos/config ~/projetos/meu-primeiro-projeto/entradas ~/projetos/meu-primeiro-projeto/saidas ls ~/projetos ls ~/projetos/meu-primeiro-projeto
config meu-primeiro-projeto
entradas saidas
The first line answers to ls for projetos; the second, to ls for the training project.
You just created, with one command, the folder structure that separates what always matters from what belongs to a single project.
Lesson cheat sheet
The symbol ~ represents your home folder in the Bash shell. Inside it, projects brings together independent works. Use clear names and avoid mixing documents from different clients. The config folder stores cross-cutting knowledge; each project keeps its own entries and results.
Separate contexts help limit what the AI needs to read. A folder full of unrelated topics adds noise and makes it hard to explain where a conclusion came from.
Personal folder; projects; context; inputs and outputs.
In ~/projetos/website, you’ll find the site files. In ~/projetos/estudos, you’ll find experiments. On Windows, the manager may show paths like C:\Users\SeuNome\projetos.
Draw the tree before creating files. Choose a single training project and a single global config folder.
Accepting a conclusion without checking the input that supports it.
Lesson 19 · OSWork v6.2 · INEMA.CLUB PRO
Module 4 · Lesson 2 of 6

You can write the README for the training project in Markdown. Each field has real information or "to be defined".
An explanation that only exists in a conversation disappears when the conversation ends. Someone who comes later doesn't know what the folder is for. A small text file solves it and lasts.
In 1 minute
Every lab experiment script for Lúcia has a title, materials, and procedure. She underlines the titles and puts a dash before each material. Markdown does the same with the signs you type.
The # at the beginning of the line creates a title, the ## creates a subtitle, and the hyphen creates a list item. The file is still text: you can read it even without a special program.
Lúcia took the script "Germinação do feijão" and turned it into Markdown in five minutes. She learned nothing beyond these three marks.
# Germinação do feijão
## Materials
- 10 grains of beans
- cotton and a cup
Title: Germinação do feijão.
Subtitle: Materials.
List: two items, one per line.
A Markdown file is a text file whose name ends in .md, like README.md. It opens in the computer's text editor and also in the terminal.
In the terminal, the nano opens the file so you can edit it right there. Then the cat command shows the content on the screen so you can check it.
Denise opened the board project's README with nano. She changed one line, saved with Ctrl+O, confirmed the name with Enter, and exited with Ctrl+X. Then she checked with cat.
GNU nano README.md
# Meu primeiro projeto OSWork
## Propósito
Produzir relatórios de treino a partir de dados fictícios.
^G Help ^O Write Out ^W Where Is ^X Exit
That's what nano looks like: the text in the middle and the shortcuts in the footer, in English. The ^ means Ctrl. Write Out is saving; Exit is exiting. After Ctrl+O, it shows the file name underneath: press Enter.
The course kit template has five sections: Purpose, Read first, Organization, How to check, and Current status. You replace each template text with what matters in your project.
Still unsure about a field? Write "to be defined". An honest open field is better than a template text that nobody checked.
On the science fair README, Lúcia wrote under Purpose: "organize the fair sign-ups". Under How to check: "every registered group shows up on the final list".
Small files with a clear name last longer than a lost conversation. People can review them, and agents can look them up.
The value comes from clarity. The three marks are enough. Bold, table, and link are optional.
Denise took a week off. The colleague who covered in her place opened the council project README and continued the work without needing to call her.
Where it is: in a March conversation with the AI.
Result: the colleague can’t find it and calls Denise.
Where it is: README.md, in the project folder.
Result: the colleague reads the file and moves on.
Net gain: the explanation ends up living in the folder, not in someone’s memory.
Stuck here? That's normalThe nano surprises you the first time: there’s no mouse menu. Want another path? In the project folder, type open -e README.md on Mac, or explorer.exe . on Windows, inside the Linux terminal of module 3, and open the README.md with Notepad. When saving, under Type, choose All files, so it doesn’t turn into README.md.txt.
Practice now 0/3
Done when the cat shows the titles with # and you’ve read each section and put your own text there or "to be defined". About 10 minutes, on your computer.
The template is a text file from the course kit, with no one’s data. Attention: the second line replaces an existing README.md in that folder. Did you already write one? Skip that line. Didn’t you do the previous lesson? Run this first: mkdir -p ~/projetos/meu-primeiro-projeto
cd ~/projetos/meu-primeiro-projeto curl -fsSL https://inematds.github.io/oswork/materiais/README-projeto.md -o README.md nano README.md
$ cat README.md
# Meu primeiro projeto OSWork
## Propósito
A definir.
## Leia primeiro
A definir.
The title can stay like in the template. The section text is yours; check the titles with # and no section is empty. If the terminal tells you it doesn't know nano, use Notepad, as the board "Stuck here? That's normal" says, at the end of step 4 of the lesson.
You just wrote, in Markdown, the project explanation that lives in the folder, not in a conversation.
Lesson cheat sheet
Markdown uses simple symbols to organize text: # creates a title, ## creates a subtitle and a hyphen starts a list item. The file remains plain text, readable even without a special editor. The name ends with .md. You do not need to write code to record clear instructions.
Small, named, easy‑to‑edit files last longer than a lost conversation. They can be reviewed by people and consulted by agents. The value comes from clarity, not elaborate formatting.
Title; list; code block; link; plain text.
A README can contain: purpose, input files, expected result and how to verify. Anyone arriving later understands the task without relying on the original conversation.
Open materiais/README-projeto.md. Copy the template to your project and replace each field with real information or "to be defined".
Lesson 20 · OSWork v6.2 · INEMA.CLUB PRO
Module 4 · Lesson 3 of 6

You can put the four memory files from the kit into the config folder. And you can say which one each note lives in.
A giant document with everything turns into a pile that nobody consults. Worse: an old rule lives alongside the new one, and the AI doesn’t know which one to follow. One file per function fixes this.
In 1 minute
The school secretariat doesn’t write everything in just one notebook. There’s the minutes book, the incidents book, and the procedures notebook. Each one answers a different question.
In the config folder, four files do that job. Separated, you look up only what you need—and the AI does too.
Denise was looking for why the parents meeting had been moved to Saturday. The reason was in a 40-page notebook, among messages and phone numbers. It took half an hour to find it.
Preference is your steady way of working, like "I prefer short reports". It goes in memoria.md.
A decision is a choice with a reason, and the reason can change. "We chose a spreadsheet because the whole team uses the same one" is a decision. It goes in decisoes.md, with a date.
Lúcia prefers exercises with an answer key at the end: that's memory. But "the 8th grade tests have 10 questions because the coordinator standardized them" is a decision.
"I prefer exercises with an answer key at the end."
Change? Almost never. You don't need a reason.
"8th grade tests with 10 questions, because the coordinator standardized them."
Change? It can change; that's why it includes a date and a reason.
The falhas.md records a problem, the cause, and the smallest correction—that is, the small protection that prevents repetition. It's for checking when the problem comes back. The dicas.md stores procedures that already worked.
Copy the entire falhas.md into every request, "just in case." It fills the chat with warnings that have nothing to do with the task. You open it when the problem shows up again.
The meeting minutes summary came out empty on a Monday. The entradas folder was empty. Denise noted it in falhas.md and started checking the folder before asking.
When a decision changes, don't replace the old line in silence. Write the new one with a date and a reason, and mark the old one as replaced.
That way, you never have two contradictory rules valid at the same time. And whoever reads it understands the path the decision took.
In October, Lúcia's tests went from 10 to 12 questions, with two graph-reading questions. She added the new line and marked the August one as replaced.
Test yourself
"The summary stopped halfway because the file was huge; splitting it into parts solved it." Where does this note live?
Stuck here? That's normalSometimes a note seems like it could fit in two files. Ask: does it say how I like it, what we chose, how it’s done, or what went wrong? The first answer that fits decides.
Practice now 0/3
Ready when the ls shows the four files and you’ve written, on paper, the file for each of the five notes. About 10 minutes, on the computer, in the terminal from module 3.
The models are text files from the course kit, and the notes are fictional. If you’ve already written in one of these four files, skip its line: curl overwrites a file with the same name. Did one line fail? The curl command prints an error message right below it; run only that one again. Didn’t do lesson 1 of this module? Run it first: mkdir -p ~/projetos/config
cd ~/projetos/config curl -fsSL https://inematds.github.io/oswork/materiais/memoria.md -o memoria.md curl -fsSL https://inematds.github.io/oswork/materiais/decisoes.md -o decisoes.md curl -fsSL https://inematds.github.io/oswork/materiais/dicas.md -o dicas.md curl -fsSL https://inematds.github.io/oswork/materiais/falhas.md -o falhas.md ls
The five notes (fictional): 1) "I prefer to send notices to families in up to five lines." 2) "The newsletter goes in PDF starting in September, because not all families open spreadsheets." 3) "To combine the month’s minutes: first request the list of the read files, then the summary." 4) "The meeting summary included a date that wasn’t in the minutes; the fix was to ask the AI to leave a blank space when the date is missing." 5) "Reports always have the open items at the end."
You just set up the config folder and placed each note where it belongs.
Lesson cheat sheet
memoria.md records stable preferences; decisoes.md explains choices; dicas.md stores useful procedures; falhas.md documents problems and fixes. Do not put everything in one giant document. When a decision changes, record the date and reason so you don’t keep contradictory rules.
Separating functions makes it easier to consult only what’s needed. A failure history should not become a list of mandatory commands in every task. Queryable knowledge and permanent instructions are different things.
Selective memory; dated decisions; procedure; history.
“I prefer short reports” is a preference. “We chose CSV because it’s compatible with the team’s spreadsheet” is a decision. “The service stopped without supervision” belongs to failures.
Lesson 21 · OSWork v6.2 · INEMA.CLUB PRO
Module 4 · Lesson 4 of 6

You can create the .env.example from the training project, with the variable names and fictional values. No real values go into it.
A password pasted into a document, a screenshot, or a request turns into access for whoever reads it. And it keeps working after the conversation ends. Separating the secret from the rest lets you share the folder without worry.
In 1 minute
At the school’s front desk, the key board shows which rooms exist. Nobody worries about that list being visible. With keys, it’s different: whoever takes the key opens the room.
A credential works like a key. A password, a API key or the bot token let whoever has them act on behalf of your account.
Denise was going to send to the team group a screenshot of the notes system configuration. Before sending, she noticed the entire coordination password in the corner of the image.
What it shows: the settings screen, with the password visible.
Result: the 30 people in the group now have access.
What it shows: the same screen, with the password covered before sending.
Result: the team sees what it needs, and access stays limited to coordination.
The file .env stores variables: a name, an equal sign, and a value. For example, TELEGRAM_BOT_TOKEN or DATABASE_URL, the address of a database, with the password inside.
It's not encrypted. Anyone with access to the file can read what's inside. That's why it stays only on your machine. In lesson 7, the command chmod restricts reading to you only.
In lesson 7, Lúcia will create a lookup bot for the class. Its token will live in the .env in the project folder, and nowhere else.
The .env.example has the same names, with fake values. Anyone who receives the project sees what they need to fill in, but gets no access to anything.
The course kit includes TELEGRAM_BOT_TOKEN=fill_in_locally. You replace the value only in your private copy, the .env. With the example value, no bot works.
Denise shared the reports project with the vice-director using the .env.example. The vice filled in her own .env with the password she received from the office.
TELEGRAM_BOT_TOKEN=fill_in_locally
DATABASE_URL=fill_in_locally
TELEGRAM_BOT_TOKEN=[the real token]
DATABASE_URL=[the real address]
Stuck here? That's normalThe two names look like twins. Remember it like this: what ends in example is the example, and it can circulate. The other one is the real one, and it stays at home.
Real values don't go in prints, in course examples, or in a file you send to the AI without need. To help, the AI almost always only needs to know that the variable exists.
Did you paste a key by mistake? Deleting the message isn't enough. Replace the key on the site that generated it, in the security area or the account keys area. If you never generated a key, keep this rule for when you generate one.
Lúcia's report wasn't connecting to the school's spreadsheet. Instead of pasting the .env, she told the AI which variables had been filled in.
YouThe report won’t connect. My .env: DATABASE_URL=[real address with the password inside]
AILet’s take a look. I’ll use that address to test the connection…
The password is now in the conversation history.
YouThe report won’t connect. In my .env, DATABASE_URL is filled in. What do I check, without sending you the value?
AICheck whether the address is complete and whether the password inside it still works. You don’t need to send me the value.
The help is the same, and the secret stays at home.
Test yourself
A colleague will test your project on their computer. What do you send?
Practice now 0/3
Ready when the cat shows both names with the value: fill in preencha_localmente and make sure `ls -a` lists the .env.example. About 8 minutes, on your computer, in the terminal.
The values are fake; no real access goes into the file. Never replace preencha_localmente with a real value in the .env.example. Don’t create the .env now: it will only be needed in module 7. Didn’t you do lesson 1 of this module? Run first: mkdir -p ~/projetos/meu-primeiro-projeto
cd ~/projetos/meu-primeiro-projeto printf '%s\n' 'TELEGRAM_BOT_TOKEN=preencha_localmente' 'DATABASE_URL=preencha_localmente' > .env.example cat .env.example ls -a
TELEGRAM_BOT_TOKEN=preencha_localmente
DATABASE_URL=preencha_localmente
. .. .env.example README.md entradas saidas
The first two lines come from cat; the last one comes from ls -a. The order can vary, and there may be other files of yours.
You just created the template that shows what to fill in without handing over any key.
Lesson cheat sheet
A .env file can store variables such as TELEGRAM_BOT_TOKEN or DATABASE_URL. It is not encrypted: anyone with access to the file can read it. Use appropriate permissions and never include real values in screenshots, course examples, or files sent to the AI without necessity.
Credentials allow actions on behalf of an account. Separating the .env.example model, without real values, from the local .env lets you share the structure without distributing access.
Variable; secret; .env.example; runtime reading.
The kit includes TELEGRAM_BOT_TOKEN=fill_locally. The student replaces this only in their private copy. No bot is authenticated with this example.
Create .env.example with variable names and fake values. Keep .env outside the repository and never paste your key into the chat.
Mix the training copy with private files or production work.
Lesson 22 · OSWork v6.2 · INEMA.CLUB PRO
Module 4 · Lesson 5 of 6

You can create the .gitignore before the first commit. And you can point to the line that keeps the .env out and the one that keeps the .env.example.
In module 6, the Git will store versions of your folder. What goes into a version stays in the history. That’s why the list of what never goes in comes before the first version.
In 1 minute
Each version saved by Git is called a commit. The .gitignore is a text file in the project folder with the list of what Git should leave out.
This list includes the .env, its private variants, and the temporary folders that programs create on their own.
In the reports project, Denise put the .env in the list before saving the first version. The file with the notes system password never made it into the history.
README.md, .env.example, and the other files from the work.
.env, keys, passwords, and temporary folders.
Who decides: the .gitignore, written before the first version.
The .env line picks up the .env file. The .env.* line picks up variants like .env.local: the asterisk matches any ending. The line that starts with ! opens an exception.
So !.env.example returns the example to the list of what’s kept. The last lines cover temporary folders and files that some programs create on their own. You don’t need to touch them.
Lúcia found the exclamation strange on the third line of the kit file. It was the one that kept the .env.example in the project, so her math classmate would know what to fill in.
The .gitignore doesn’t apply to a file that’s already been saved, the tracked file. If the .env already entered a commit, the line written afterward doesn’t remove it from the history.
It’s like the office courier envelope: the paper that shouldn’t go out stays in the pile until the envelope is sealed. After the envelope has left, scratching the paper off the list doesn’t bring it back.
A coworker of Denise put the .env into the .gitignore a week after the first version. The file with the password was still there, in the old version.
If a key was published, the first fix is to revoke the key at the source—meaning cancel it on the site that created it. This is in the keys or security area of the account, like the API platform’s keys page. Deleting the line from the file doesn’t invalidate a copy that someone already saw.
Only then comes the fix to the history, depending on the case. Module 6 shows how.
The API key from a Lucia project appeared in a version shared with the team. She canceled the key on the platform site in the same minute and created a new one. Only then did she take care of the file.
What you did: removed the key from the file.
Result: the old key still works for whoever copied.
What you did: canceled at the source, created another one, and then cleared the file.
Result: the leaked copy won’t open anything anymore.
Net gain: the risk ends when the key dies, not when the file changes.
Test yourself
A key was already published in a version. Putting the .env in .gitignore now fix it?
Stuck here? That's normalThe Git only reaches module 6. Today, you just need the .gitignore ready in the folder. When you save the first version, it will already be in place.
Practice now 0/3
Ready when cat -n shows the lines .env and !.env.example and ls -a lists the .gitignore. About 8 minutes, on your computer, in the terminal.
The template is a text file from the course kit and stores nothing by itself: it only becomes a rule once Git sees it, in module 6. Pay attention: the second line replaces a .gitignore that already exists in this folder. Didn’t do lesson 1 of this module? Run first: mkdir -p ~/projetos/meu-primeiro-projeto
cd ~/projetos/meu-primeiro-projeto curl -fsSL https://inematds.github.io/oswork/materiais/gitignore.txt -o .gitignore cat -n .gitignore ls -a
1 .env
2 .env.*
3 !.env.example
4 __pycache__/
5 *.pyc
6 node_modules/
7 .verificacao/
This is the cat -n answer. Lines 4 through 7 are temporary program settings; leave them as they are. Line 1 keeps .env out; line 3 keeps .env.example in.
You just added the list of what must never enter the history before the first version exists.
Lesson cheat sheet
The .gitignore lists files that Git should ignore when they’re not being tracked yet. Include .env, private variants, and temporary folders. Keep an explicit exception for .env.example. Before saving a version, check git status and the prepared files.
Ignoring later does not erase a secret from history. If the key leaked, the first fix is to revoke or rotate it at the source; deleting the line from the file does not invalidate a copy already seen.
Tracked files; exclusion patterns; change review; revocation.
Useful patterns: .env, .env.*, !.env.example, __pycache__/. To discover which rule applies, use git check-ignore -v .env.
Copy materiais/gitignore.txt as .gitignore before git add. Verify that .env.example remains available and .env does not appear among new files.
Lesson 23 · OSWork v6.2 · INEMA.CLUB PRO
Module 4 · Lesson 6 of 6

You can add to the README a "Read first" section with three paths that exist and are up to date.
Having memory in the folder is not enough: the AI doesn't open every file that’s there by itself. And an old file gets in the way more than no file at all, if it includes a process that has already changed. Cleaning the context means choosing what the AI reads and keeping that material up to date.
In 1 minute
The AI doesn't automatically read every computer file in Markdown. You tell it which documents it should consult.
When a reference applies to the whole project task, it goes in AGENTS.md, the project's instruction file. Module 5 takes care of that.
Denise asked for a draft of the council report without citing any file. The AI didn't consult decidedes.md, and the format came out different from what the team had decided.
YouDraft the council report.
AIHere’s a draft in a table, with the average for each class and three recommendations…
Format on its own and numbers nobody provided.
YouRead README.md and ../config/decisoes.md. Then build the council report draft, without making up any data.
AII read both files. I’ll follow the format recorded in decisoes.md and list as pending anything that isn’t in the entries.
The answer says what it read and follows the team’s decision.
In the README, the Read first section lists the files that any project task must open before starting. Three paths are enough.
Write each path starting from the project folder. The ## makes a subtitle, like in lesson 2 of this module. Read ../ as "go up one folder": from meu-primeiro-projeto you go to projetos and, from there, enter config.
In the science fair project, Lúcia put the fair regulations second. In your training project, use the three paths from the board below.
The teachers’ lounge bulletin board with the notice of a March meeting confuses more than an empty board. The same happens with AI memory.
An old file can bring the address of a service or process that has already changed. Before a task, update the expired decision and remove from the working folder what doesn’t matter.
Lúcia’s decisoes.md still said "exams with 10 questions". The AI built the exam with 10. It added the new line and marked the old one as replaced, as in lesson 3 of this module.
decisoes.md: only the August line, exams with 10 questions.
Result: the AI builds the exam in the old format.
decisoes.md: the October line, with 12 questions, and the August one marked as replaced.
Result: the exam comes out with 12 questions.
Net gain: an updated line prevented redoing the entire exam.
When you start a task, ask for the README and the decision that matters to be read. Don’t load contact lists or passwords just because they’re in the same folder.
Review now and then. First check whether each path exists; then open the file and see if it still describes today’s situation.
Denise put on the coordination calendar: every first Monday of the month, ten minutes to review the council project’s first read.
$ ls AGENTS.md ../config/decisoes.md ../config/memoria.md
AGENTS.md ../config/decisoes.md ../config/memoria.md
All three paths exist. If one were missing, the ls would warn you with "No such file or directory", and the first read would be wrong.
Stuck here? That’s normalDid the ls respond "No such file or directory"? Check the name letter by letter, including the dot and slash. Still stuck? The file doesn’t exist yet: practice tells you which lesson it’s created in.
Practice now 0/4
Ready when the ls lists the three paths with no error, the README has the first read section, and the two config files have today’s date. About 10 minutes, on the computer, on the terminal.
The files are from the course kit, with fictional data. Nothing is being replaced: the second line only downloads the AGENTS.md from the kit if the folder doesn’t have it yet. Did the last ls show "No such file or directory"? Go back to the lesson that creates what’s missing: README in lesson 2 of this module, config in lesson 3.
cd ~/projetos/meu-primeiro-projeto ls AGENTS.md || curl -fsSL https://inematds.github.io/oswork/materiais/AGENTS-projeto.md -o AGENTS.md ls AGENTS.md ../config/decisoes.md ../config/memoria.md nano README.md
$ ls AGENTS.md ../config/decisoes.md ../config/memoria.md
AGENTS.md ../config/decisoes.md ../config/memoria.md
$ nano ../config/memoria.md
Three listed paths, in any order, and no error warning. Then, the nano opens each config file for the date.
You just, in writing, told the AI what it should read first, and checked that everything exists and is up to date.
Lesson cheat sheet
The AI does not automatically read every existing Markdown file on the computer. Specify which documents to consult and keep references in AGENTS.md when needed. Before a task, remove irrelevant data from the working copy and update expired decisions.
Useful memory needs to be findable and correct. An old file can be more harmful than no memory if it contains a service address or process that has already changed.
Context selection; date; source of truth; periodic review.
When starting a report, request reading of README.md and the decision about format. Do not load contact lists or credentials because they are in the same folder.
Add to the README a section “Leia primeiro” with three real paths. Open each path and check whether it describes the current situation.
Use fictional files and a training folder. Practices with installation, Telegram, or VPS may require extra time for sign-up and configuration.
Read the block before using. Fields like Your Name and usuario@ip-da-vps are examples to adapt; administrative commands belong only to your training environment.
~/projetos/
├── config/
│ ├── memoria.md
│ ├── falhas.md
│ ├── dicas.md
│ └── decisoes.md
└── meu-primeiro-projeto/
├── AGENTS.md
├── README.md
├── .gitignore
├── entradas/
└── saidas/Build the digital house and separate knowledge from credentials. Record the produced file, the test run and the observed result.
Use this rubric after the lab. Each line asks for evidence; checking reading does not mean the practice was performed.
If you add .env to .gitignore, does it automatically remove a key that was already published?
No. Revoke the exposed key and fix the history as appropriate; ignoring only prevents new untracked files.
If your answer was different, return to the corresponding topic and write the difference in one sentence. The check does not block your study.
Tools verified on 20/09/2026; screen names and availability may change.
Lesson 24 · OSWork v6.2 · INEMA.CLUB PRO
Module 5 · Lesson 1 of 6

You can rewrite the AGENTS.md of your training folder with five short rules, and for each one, say how you check that it was followed.
Every new conversation with the agent starts from scratch. Without an instructions file, you repeat the same warnings for every request. And a vague instruction, like "do your best", doesn’t change anything in what it does.
In 1 minute
In a science lab, the sign on the door tells you how to work inside. AGENTS.md does the same for a project folder. The Codex looks for that file by itself when it starts working in the folder.
It’s a text file in Markdown. You open and edit it in a text editor, like any other text.
Lúcia created the training folder in module 3 and completed it in module 4. Inside it, next to the README, there’s AGENTS.md. It’s the first file she will improve.
Four topics fit in AGENTS.md: where to start reading, how to check the result, what not to do, and the delivery format. The school story and the reasons behind each decision are left out.
A short file is read in full. A long file hides the rule that matters in the middle of paragraphs.
Denise opened the AGENTS.md she had written for the meeting minutes project. They were two paragraphs about the school’s founding and only one work rule. She deleted the paragraphs.
"The school was founded in 1987 and has always valued communication with families. That’s why it’s very important that everything is done carefully."
"1. Read README.md before editing."
"2. Use only entries/ and results/."
"3. Report what you changed and how you checked it."
Do the plate test. "Use protective eyewear before starting the experiment" can be checked by looking. "Be careful" can’t.
In AGENTS.md it’s the same. A good rule asks for an action and leaves evidence you can see in the delivery.
In the training report, Lúcia replaced "be excellent" with a checking rule. In the next delivery, the agent wrote the sum and the difference it found. She checked it in one minute.
"Be excellent."
How to check: there’s no way.
"Compare the total from the report with vendas.csv and indicate the difference."
How to check: the delivery includes the sum and the difference.
Test yourself
Which of these rules can you check just by looking at the agent’s delivery?
Start with five rules and run each one through this question: can I observe whether it was followed? If the answer is no, rewrite it with an action. If the rule changes nothing in the work, delete it.
The board below is the course template, with rules like this. You adapt the purpose to your folder.
Denise started from these five rules for the AGENTS.md of the minutes and only changed the folder names. Most useful: "Don’t invent missing data: describe the pending item."
Stuck here? That’s normalWriting an observable rule feels hard the first time. Use the test phrase: "I’ll know it was followed because in the delivery it shows up ___". If you can’t fill in the blank, the rule is still too vague.
Practice now 0/3
Done when the AGENTS.md has five rules and, next to each one, the evidence you’ll see in the delivery. About 10 minutes, on your computer.
You only edit a text file from the training folder; nothing is executed. Don’t have the folder? In your personal folder, create projects and, inside it, my-first-project. Creating the AGENTS.md from scratch? In the Save as window, choose the type "All files" and type the full name, so it doesn’t turn into AGENTS.md.txt. If a rule doesn’t pass the test, rewrite or delete it; there’s no single correct answer.
# Training project instructions Purpose: <e.g., report drafts based on fictitious data> 1. <rule> (I check because in the delivery it appears: <evidence>) 2. <rule> (I check because in the delivery it appears: <evidence>) 3. <rule> (I check because in the delivery it appears: <evidence>) 4. <rule> (I check because in the delivery it appears: <evidence>) 5. <rule> (I check because in the delivery it appears: <evidence>)
Replace everything that’s between < and >, including symbols. What’s inside parentheses is your check: it can stay in the file; it won’t interfere with the agent.
Purpose: drafts of science exercise lists based on my lessons.
Rule: use only files from the entries folder. I check because the delivery lists the sources, and all of them are in entries.
Rule: mark with [check] every exercise answer that isn’t in the material. I check because I can see the marks in the draft.
You just turned loose notes into rules you can verify at delivery.
Lesson cheat sheet
AGENTS.md is the instruction file that Codex discovers in the applicable scope. It describes how to work: initial files, verification commands, limits and delivery format. No need to explain the whole organization history; prefer short rules that change a real decision.
Objective instructions avoid repeating the same details in each conversation. The file should help the agent choose a concrete action, such as verifying the report before considering it finished.
Operational instruction; scope; observable rule; conciseness.
“Be excellent” is hard to test. “Compare the total of the report with vendas.csv and indicate the difference” defines an action and its evidence.
Write five rules. For each one, ask: can I observe if it was fulfilled? Remove guidelines that do not change the work.
Accepting a conclusion without checking the input that supports it.
Lesson 25 · OSWork v6.2 · INEMA.CLUB PRO
Module 5 · Lesson 2 of 6

You can say which instruction files apply in a folder. And you can check the summary the Codex makes from them against the real files.
Sometimes the agent follows a rule you don’t remember writing. Other times it ignores one you wrote, but in another folder. Before you blame the model, it’s worth knowing where each instruction comes from.
In 1 minute
The rule book applies across the whole school. The class agreement applies in the room. With AGENTS.md, it’s the same: by default, the global one is in the hidden folder .codex, inside your personal folder. The project one is in the project folder.
In the terminal, the ~ sign is a shortcut to your personal folder. Folders with a name starting with a dot are hidden.
Denise wants the agent to always include what it checked, in any project. This rule was for the global. "Compare the total with the frequency sheet" only makes sense in the frequency project.
A subfolder can have its own AGENTS.md. With Codex open in it, both apply, and the closest instruction takes precedence, like a lab agreement inside the school.
"Can" because it applies to what it covers. What the nearby rule doesn’t mention keeps coming from the upper file.
Lúcia created a provas subfolder inside her science project, with an AGENTS.md that asks for a separate answer key. When she opens the Codex inside provas, this rule applies. If it’s opened in the exercise lists, it doesn’t.
There’s also the AGENTS.override.md. In the same folder, the Codex reads the override and ignores the AGENTS.md. You didn’t create any? Great. But it can show up in a folder copied from a colleague and, forgotten there, it explains a lot of weird behavior.
None of these files beats three things. The system instructions, which are the tool’s factory rules. The permissions, which you approve or deny, like in module 3. And what you explicitly ask for in the conversation. They guide; they don’t unlock what the tool blocks.
Denise’s AGENTS.md says "submit in bullet points". Today she asked, in the conversation, for a continuous paragraph for the email to the administration. Today’s request is valid.
How to work in the folder when the request doesn’t say anything: sources, checking, format.
The system instructions.
Tool permissions.
Your explicit request in the session.
Test yourself
The global says "respond in bullet points." The project’s AGENTS.md doesn’t talk about format. In the conversation, you ask for a table. Which one counts?
Inside the folder, ask the Codex to summarize the instructions it loaded and to say which file each one came from. Then open the files and compare.
The summary cites a rule that isn’t in any file? Or does it forget one that is? That’s where you found the cause before blaming the model.
Lúcia asked for the summary in the training folder. The rule showed up: "relate what you checked", which she hadn’t written there. It was in global, which she created in March and forgot.
YouSummarize the instructions you loaded into this folder and say which file each one came from. Don’t change anything.
AIFrom the global: relate what you checked. From the AGENTS.md of this folder: read README.md and list the sources before you change anything; use only entries/ and saidas/; don’t invent missing data; compare the totals before you deliver; don’t send or publish without explicit instruction. I didn’t change any file.
Each rule with its source. Now you can open both files and verify.
Stuck here? That's normalDidn’t you find the .codex folder? It’s hidden, and you may have never created a global. It’s okay: then only the project’s AGENTS.md counts, and practice shows you how to verify it.
Practice now 0/3
Ready when you’ve written down every rule from the Codex summary and the file where you found it. About 10 minutes, on your computer, using the module 3 terminal.
The three commands only read and list; nothing is changed. The request to Codex says "don’t change anything". If Codex asks for permission to change any file, refuse. Still no Codex? Just do steps 1 and 2 and write down what you found.
$ cd ~/projetos/meu-primeiro-projeto
$ ls -a
. .. AGENTS.md README.md entradas saidas
$ cat ~/.codex/AGENTS.md
cat: /home/seu-nome/.codex/AGENTS.md: No such file or directory
The ls -a list also includes hidden files; the dot and the two dots at the beginning represent the folder itself and the one above, so you can ignore that. Look for an AGENTS.override.md: if it shows up, open it and see whether it should still exist. The last line, in English, says "file or folder does not exist": there’s no global. If the file exists, the cat shows its text.
Summarize the instructions you loaded into this folder and say which file each one came from. Don’t change anything.
You just traced where each instruction the agent follows in that folder comes from.
Lesson cheat sheet
By default, ~/.codex/AGENTS.md stores global instructions. In the project, AGENTS.md adds specific rules; files in closer folders can prevail in the corresponding scope. AGENTS.override.md has priority over AGENTS.md at the same level. This does not override system instructions, permissions or the explicit request of the session.
The path matters. A local rule may not apply to another folder, and a forgotten override file can explain an unexpected behavior. Keep the global rule small and leave local details in the project.
Discovery; hierarchy; scope of directory; override.
Global: “record the tests you ran”. Project: “validate the CSV with python3 validar.py”. The two instructions work together; you don’t need to repeat the script for each project in the global file.
Ask Codex to summarize the instructions you loaded. Check the response against the real files before attributing an error to the model.
Lesson 26 · OSWork v6.2 · INEMA.CLUB PRO
Module 5 · Lesson 3 of 6

You can create the Skill semanal report in the training folder, with the name and description at the start of the file. And you can also check that it’s in the right place.
There are tasks where you explain to the agent every week, step by step, the same way. Pasting all that into the AGENTS.md makes the file huge. And the agent starts loading the entire manual even for tasks that don’t need it.
In 1 minute
The lab door plate is valid every day. The experiment script comes out of the notebook only on the day of that experiment. The AGENTS.md file is the plate. The Skill is the script.
A Skill brings together the instructions for an activity that repeats. The agent triggers it when the task calls for it.
Lúcia explained every Friday to the agent how to set up the weekly exercise list: read the lesson, choose five questions, and separate the answer key. This step-by-step became a Skill. The AGENTS.md kept five rules.
"Use only inputs/ and outputs/."
Valid for every task in the folder.
"1. Read the weekly lesson. 2. Choose five questions. 3. Separate the answer key."
Enter only when the task is the weekly list.
The Skill lives in a folder named after it, in a file called SKILL.md. At the top, between two lines of three dashes, the name and description appear. This block is the header.
After the header comes the procedure: what goes in, the steps, what comes out, and how to check. In the terminal, a command shows the beginning of the file.
Before writing the Skill for the list, Lúcia opened the course report Skill—the same one used in the practice—to understand the format. In four lines, she learned the name, when to use it, and when not to use it.
$ head -4 .agents/skills/relatorio-semanal/SKILL.md
---
name: relatorio-semanal
description: Gerar rascunho de relatório semanal quando o usuário fornecer um CSV de vendas. Não usar para enviar relatórios ou tratar credenciais.
---
The command in the first line shows the first four lines of the file. The dashed lines open and close the header.
The description is what the agent reads to decide whether to activate the Skill. It needs to say in what situation to use it. And it’s worth saying where the Skill stops.
In this description, "credentials" are passwords and access keys: the Skill doesn’t touch them.
The first description of Denise’s report Skill was "help with reports". The agent activated the Skill even in a request for meeting minutes. She rewrote it, stating the situation and the limit, in the same way as the card.
"Help with reports."
When to use? When not to use? It doesn’t say.
"Generate a draft of the weekly report when the user provides a sales CSV. Do not use it to send reports or to handle credentials."
Test yourself
Which description helps the agent decide when to activate the meeting minutes Skill?
The project Skill goes in .agents/skills, inside the project’s folder. Personal Skill—one you want in all projects—goes in ~/.agents/skills. The folder ~/.codex is for the Codex: it stores the configuration and the global AGENTS.md from the previous lesson. Skills don’t go there.
Skill notes only serve the notes project: Denise saved it in the project. Her spelling review Skill she uses for everything: she put it in the personal folder.
Stuck here? That's normalFolders that start with a dot are hidden, and the file manager won’t show them. That’s why the practice creates the folder using the terminal and checks it with a command. You don’t need to see it in the window.
Practice now 0/3
Done when the last command shows the four header lines. About 10 minutes, on your computer, using the terminal.
The commands only create a new folder and move your file into it; nothing is deleted. Don’t you have the practice folder for modules 3 and 4? Create one with mkdir -p ~/projetos/meu-primeiro-projeto and follow the same steps. If you see "No such file or directory", check you’re in the right folder with pwd.
--- name: relatorio-semanal description: Generate a draft of a weekly report when the user provides a sales CSV. Don’t use it to send reports or handle credentials. --- # Weekly report ## Input CSV specified by the user, containing product and value. Use only sources explicitly authorized. ## Procedure 1. Read README.md and the project instructions. 2. Check the header, line count, and values; explain invalid fields. 3. Calculate totals with an available calculation tool, without inventing missing data. 4. Produce output/relatorio.md with sources, known total, valid records, and pending items. 5. Verify the total against the sum of the records. 6. Report the check and stop before sending or publishing. ## Behavior tests - Complete data: total consistent with the sum. - Incomplete data: pending item visible, with no fabricated numbers. - Request out of scope: explain the limitation; don’t run external actions.
$ cd ~/projetos/meu-primeiro-projeto
$ ls
AGENTS.md README.md SKILL.md entradas saidas
$ mkdir -p .agents/skills/relatorio-semanal
$ mv SKILL.md .agents/skills/relatorio-semanal/
$ head -4 .agents/skills/relatorio-semanal/SKILL.md
The ls confirms that SKILL.md is there. Did SKILL.md.txt show up? Run mv SKILL.md.txt SKILL.md to fix the name. The mkdir -p creates the folder and any missing ones above it. The mv moves SKILL.md into it. The last command should show the header, like in step 2.
You just packaged a procedure that the agent can reuse, in the place where it looks for it.
Lesson cheat sheet
One Skill brings together instructions for a recurring activity, with a name and description at the start of SKILL.md. It can include supporting resources and programs. Personal Skills go in ~/.agents/skills; project ones can go in .agents/skills inside the repository. The ~/.codex folder stays as Codex configuration.
A rule says what to respect; a Skill teaches a procedure that can be triggered when needed. Separating these roles avoids loading the entire manual into every task.
Name; trigger description; procedure; input and output; validation.
relatorio-semanal receives a fake CSV, computes a verifiable total, and produces a Markdown with pending items. The description makes it clear that it doesn’t send the result automatically.
Lesson 27 · OSWork v6.2 · INEMA.CLUB PRO
Module 5 · Lesson 4 of 6

You can write a short, dated memory with three useful facts. And you can ask the agent to say which of those facts it used in a task.
Pasting the entire conversation from yesterday into every request gets tiring and brings back instructions that have already changed. Waiting for the AI to “remember on its own” also fails. A small file, with a date and reviewed by someone, solves both problems.
In 1 minute
The model doesn’t change because you chatted with it. The course’s operational memory is a set of files that the agent reads when you indicate them.
It works with two conditions: the agent reads the part that matters, and someone keeps the file updated. In practice for this lesson, the one reading is the Codex, opened in the terminal as in module 3.
Denise created the config folder in module 4, next to the projects. That’s where the files that apply to multiple projects for the coordination are kept.
Three things deserve to go into memory: stable facts, decisions, and causes of failures. Every sentence from each conversation does not.
Copying the entire history increases the volume and can bring back an old instruction. No one can verify an enormous file.
Lúcia noted that the course materials use accessible language and fictional examples. In the next task, she pointed to that file instead of repeating the entire conversation about the class.
Two hundred lines of conversation, from March to September.
In the middle, "use the old list model," which has already changed.
"Reviewed on: 09/25/2026."
"8th grade materials: accessible language and fictional examples."
"Weekly list: five questions and separate answer key."
Net gain: from two hundred lines to three, and no expired instructions.
Having the file exist in the folder doesn’t guarantee the agent will read it. In your request, tell it which file to consult.
And ask it to cite which fact it used. That way you can check whether the memory was used, instead of assuming.
Denise asked the parent meeting reminder to include the memory. The answer ended by saying which fact it had used, and she checked it in the file.
YouConsult ../config/memoria.md. Write a three-line reminder about the parent meeting; the agenda is the close of the grading period. Use [date] and [time] in place of those data. In the end, say which fact from memory you used.
AIParent meeting on [date], at [time]. The agenda is the close of the grading period. We count on everyone’s presence. Fact used: "Reminders for families: up to three lines, no abbreviations".
The fact cited is in Denise’s memory, which appears in step 4, and the response followed it: three lines, no abbreviations, and no made-up date.
Test yourself
Lúcia created memoria.md in the config folder, but the agent ignored the facts. What does she do first?
Stable facts also change. Mark at the top when the file was reviewed. In the next review, delete what’s expired and confirm the rest.
Write down where each fact came from: a meeting, a document, a decision. This helps you verify later.
In the September review, Denise deleted the fact "notices are printed on the backpack". The school started sending the notices through the app. She changed the top date.
Stuck here? That's normalDon't know what facts to write? Think about what you repeat most to the AI: the audience for the material, your preferred format, and a detail you always forget. Three lines are enough to start.
Practice now 0/3
Ready when the agent finishes the answer by saying which memory fact it used, and that fact is in your file. About 10 minutes, on your computer.
Steps 2 and 3 use the terminal and the Codex from module 3. Does the file not exist? In the Save as window, choose the type "All files" and type the full name, so the file doesn’t turn into .txt. Write only work facts, with no student name, password, or personal data. No Codex? Do it in the chat you use: paste the memory text at the start of the request. If the response cites a fact that isn’t in the file, write this down: it’s a sign that it made it up.
# Operational memory Reviewed on: <today's date> · next review: <e.g., end of the term> - <fact 1> (source: <where it came from>) - <fact 2> (source: <where it came from>) - <fact 3> (source: <where it came from>)
Check ../config/memoria.md. <your short task, e.g.: write a three-line notice about the science fair; use [date] instead of the date>. In the end, say which memory fact you used.
Reviewed on: 25/09/2026 · next review: end of the term.
- 8th grade materials: accessible language and fictional examples (source: conversation with coordination).
- Weekly list: five questions and separate answer key (source: term planning).
- Notices to families: up to three lines, no abbreviations (source: coordination meeting).
You just created a memory that the agent consults, and you can check it.
Lesson cheat sheet
The course's operational memory is a set of queryable files, not a change to the model weights. It works when the agent reads the relevant information and when someone keeps that information up to date. Store stable facts, decisions and causes of failures; do not preserve every sentence of every conversation.
Copying the entire history increases volume and can reintroduce old instructions. A small, dated and reviewed memory helps more than a massive file that no one can validate.
External memory; explicit query; summary; validity; source.
A teacher notes that the class materials use accessible language and fictitious examples. In the next task, reference this file instead of repeating the whole conversation about the class.
Include in memoria.md three useful facts and a review date. In the next task, ask the agent to cite which fact was used.
Mix the training copy with private files or production work.
Lesson 28 · OSWork v6.2 · INEMA.CLUB PRO
Module 5 · Lesson 5 of 6

You can record a failure in the file falhas.md, with symptom, cause, smallest fix, and verification, and write the check that would catch the problem before the next run.
When the result comes out wrong, you feel like redoing everything or switching tools. That burns hours and often hides a simple problem. In school, nobody rebuilds the stairs after a slip: you put the tape on the step and check that it’s solid.
In 1 minute
"The report came out empty" is the symptom: what you saw. The cause is the reason you observed, like "the spreadsheet had no records". Write both separately.
Then, the smallest correction and how to verify it works. It’s four content columns, plus the date and type, all in a single line of a table in Markdown.
In the training project, Lúcia saw the report come out empty. Before changing anything, she wrote down the symptom and opened the input spreadsheet: it had no records at all.
Request failure is when the goal was ambiguous or information was missing. Infrastructure failure is when the text was good, but something outside it failed: a missing or empty file, a process that stopped.
The fix changes depending on the type. Requests are fixed in the text. Infrastructure is fixed with a check.
Denise had two failures in the same week. The summary of the minutes came out too long: she hadn’t mentioned the size. The attendance report didn’t come out: the spreadsheet wasn’t in the folder.
Symptom: minutes summary with two pages.
Cause: the request didn’t say the size.
Correction: "up to ten lines".
Symptom: the attendance report didn’t come out.
Cause: the spreadsheet wasn’t in the folder.
Correction: check that the file exists before you start.
Test yourself
The agent used last year’s student list because the request only said "use the student list". What type of failure is it?
Redoing the entire project can hide a simple problem. A small protection is easier to test and maintain.
Given the empty report from step 1, with the spreadsheet in CSV with no rows, Lúcia thought about switching models. The fix was different: check the header and the number of records before generating the report.
Switch models, rewrite the Skill, redo the folders.
Two hours, and the empty spreadsheet is still breaking the next report.
A new line: "check the header and the number of records before generating".
An empty spreadsheet now generates an alert.
A record only teaches something when the following procedure changes. That’s why the protection goes into the AGENTS.md or in the Skill, which the agent reads again for every task.
At the end of the practice, the Codex shows whether the rule worked. Before you write the rule, see the check working yourself in the terminal.
Denise added to AGENTS.md for the frequency: "Before you read, check whether the spreadsheet exists. If it’s missing, stop and say which file is missing." The following week, the agent stopped and warned.
$ cd ~/projetos/meu-primeiro-projeto
$ ls entradas/
vendas.csv
$ ls entradas/vendas-outubro.csv
ls: cannot access 'entradas/vendas-outubro.csv': No such file or directory
The first ls lists what exists. The second looks for a file that isn’t there; the response, in English, says "could not access: file or folder does not exist". This is what the check catches before running anything.
Stuck here? That's normalNot sure whether the failure was from the request or the infrastructure? Ask: "if I had written better, would it have worked?" If yes, it was from the request. If the text was good and something from the machine was missing, it was infrastructure. If both, mark both.
Practice now 0/3
Once falhas.md has the new line, the rule is in AGENTS.md, and Codex stops warning you which file is missing. About 12 minutes, on your computer.
In the file, the vertical bars draw a table: that’s how Markdown writes tables, and the editor shows it that way. The failure is fictional, and the commands only list; nothing is deleted. If your entries/ folder doesn’t exist, the first ls also warns that it doesn’t exist: note that as a real failure and create the folder using the file manager.
| Date | Symptom | Observed cause | Smallest fix | Verification | Request or infrastructure | |---|---|---|---|---|---| | <today's date> | October report didn’t come out | <e.g., entradas/vendas-outubro.csv doesn’t exist> | <e.g., check whether the file exists before reading it> | <e.g., a missing file triggers a warning and stops> | Infrastructure (fictional example) |
Before reading an entries/ file, check whether it exists. If it’s missing, stop and say which file is missing.
You just turned a failure into a small protection, recorded where the next run will read it.
Lesson cheat sheet
Record the symptom, the observed cause, the minimal fix and how to verify. Differentiate failure of request, such as ambiguous objective, from infrastructure failure, such as a terminated process. The record only generates operational learning when it changes the next procedure.
Redoing the whole project can mask a simple problem. A small protection, like checking for a file's existence before reading, is usually easier to test and maintain.
Symptom is not cause; minimal correction; prevention; evidence.
The report came out empty because the CSV had no rows. The safeguard is to validate the header and number of records before generating the report, not to switch models.
In falhas.md, create a line for a fictitious missing file error. Write a check that would detect the problem before execution.
Lesson 29 · OSWork v6.2 · INEMA.CLUB PRO
Module 5 · Lesson 6 of 6

You can test the Skill weekly report with three cases: normal, incomplete, and not as agreed. And you can note whether it preserved the data, marked the pending item, and stopped where it should.
A Skill that worked once may have succeeded by chance, thanks to something that was in the conversation. The evacuation simulation practices the normal day, the blocked door, and the person who wants to go back to grab the backpack. With the Skill, it’s the same: vary the input before you trust it.
In 1 minute
Before you run it, write in the checklist what each case should produce. That way you compare to a reference, not to your impression in the moment.
The normal case uses the complete data. The incomplete case is missing a value. The not as agreed case asks for something the Skill must not do. Each case runs on the Codex, opened in the terminal inside the training folder.
Denise set up the checklist the way you set up the simulation worksheet: first what should happen in each scenario, then the run-through.
In the incomplete case, the correct result doesn’t invent the missing value. It shows the total of what you know and makes the pending part clearly visible.
In the first version that Lúcia wrote of the Skill relatorio-semanal, the rule "sem inventar ausências" was missing. In the incomplete case, the agent filled in the missing value. It was the test that showed that.
YouUse the Skill relatorio-semanal with entries/sales-incomplete.csv.
AIReport generated. Total for the week: 100.00.
The Pen doesn’t have a value in the file, and the total pretended it did.
YouUse the Skill relatorio-semanal with entries/sales-incomplete.csv.
AISource: entries/sales-incomplete.csv. Draft in saidas/relatorio.md. Known total: 90.50 (Notebook 35.50 + Agenda 55.00). Pending: the Pen line has no value. I didn’t fill it in.
Verifiable total and visible pending part, as the Skill asks.
The third case asks for something the Skill shouldn’t do, like sending the report. The expected behavior is to prepare only the draft and say why it stopped.
Denise requested, on purpose, "generate and send to management." The Codex can’t send an email there anyway; the test checks whether it respects the limit and tells you where it stopped.
YouUse the Skill relatorio-semanal with entries/vendas.csv and send the report to management.
AISource: entries/vendas.csv. Draft in saidas/relatorio.md, with total 100.00, same as the sum of the three records. I didn’t send: the Skill prepares only the draft and stops before sending or publishing.
Did the allowed part, checked the total, and said where it stopped.
Test yourself
In the out-of-agreement case, the response started with "Using the Skill relatorio-semanal" and then said it sent the report. Did the test pass?
Looking for the Skill name in the response isn’t testing. Testing is checking the data, the pending part, and where it stopped.
If a case fails, add to the Skill the smallest rule that fixes that failure. Then run the three cases again.
When the incomplete case failed, Lúcia didn’t rewrite the Skill. She added a line: "empty value turns into a pending item; never fill it in". She ran the three cases, and all three passed.
"Did the response cite relatorio-semanal? Passed."
Total equals the sum?
Pending part visible, without an invented number?
Stopped before sending?
Stuck here? That's normalSometimes the three cases pass on the first try. This is also a result: write "passed" on the sheet, with the date. If one fails and you don’t know which rule to write, copy the sentence from the sheet that wasn’t followed and put it into the Skill as a rule.
Practice now 0/3
Ready when the worksheet has all three cases marked "passed" or "failed" and, if any failed, the rule you added to the Skill. About 12 minutes, on the computer, using the terminal and Codex.
The data is fictional, and the Skill only writes to saidas/. The Codex may ask for authorization before creating saidas/relatorio.md, as in module 3: authorize only that file; any request to send or publish, refuse. Without the Skill from lesson 27? Do that practice first: takes ten minutes.
$ cd ~/projetos/meu-primeiro-projeto
$ mkdir -p entradas saidas
$ printf 'produto,valor\nCaderno,35.50\nCaneta,9.50\nAgenda,55.00\n' > entradas/vendas.csv
$ printf 'produto,valor\nCaderno,35.50\nCaneta,\nAgenda,55.00\n' > entradas/vendas-incompleto.csv
$ cat entradas/vendas-incompleto.csv
produto,valor
Caderno,35.50
Caneta,
Agenda,55.00
The mkdir -p ensures the folders exist. Each printf writes an input file with the fictional course data. Attention: the first one replaces the vendas.csv in the training folder, so the totals in the worksheet match. The cat shows the incomplete file: the Caneta is missing a value. In the file, the point separates the cents.
One request per case:
Use the relatorio-semanal Skill with entradas/vendas.csv.
Use the relatorio-semanal Skill with entradas/vendas-incompleto.csv.
Use the relatorio-semanal Skill with entradas/vendas.csv and send the report to the management.
You just tested a reusable capability by behavior, not by the appearance of the response.
Lesson cheat sheet
Test the Skill with a normal input, another incomplete one, and one out of scope. Observe whether the result preserves data, signals uncertainty, and stops when it should. The test should measure behavior, not just look for the Skill name in the response.
A procedure that works once may be depending on context by accident. Varying the inputs helps you discover what needs to be made explicit in the instructions.
Normal case; incomplete case; scope limit; acceptance criterion.
Incomplete input: missing a sale value. Expected: do not invent the number and separate known total from pending. Out of scope: ask for client submission; expected: prepare only a draft.
Note three cases in the verification sheet and compare the outputs. Update the Skill only with the smallest rule that fixes the observed failure.
Use fictional files and a training folder. Practices with installation, Telegram, or VPS may require extra time for sign-up and configuration.
Read the block before using. Fields like Your Name and usuario@ip-da-vps are examples to adapt; administrative commands belong only to your training environment.
---
name: relatorio-semanal
description: Generate a report draft from the provided CSV, without external submission.
---
1. Read the README and the provided CSV.
2. Validate the header, values, and empty lines.
3. Calculate totals without inventing missing data.
4. Generate Markdown with sources, total, and pending items.
5. Compare the total with the sum of the entries.
6. Stop before sending or publishing.Create project instructions and a reusable capability with a review criterion. Record the produced file, the executed test, and the observed result.
Use this rubric after the lab. Each line asks for evidence; checking reading does not mean the practice was performed.
Writing “do not leak secrets” in AGENTS.md replaces file permissions?
No. Instructions guide; permissions and isolation restrict what the tool can access.
If your answer was different, return to the corresponding topic and write the difference in one sentence. The check does not block your study.
Tools verified on 20/09/2026; screen names and availability may change.
Terms for this section: Markdown.
Lesson 30 · OSWork v6.2 · INEMA.CLUB PRO
Module 6 · Lesson 1 of 6

Can you explain what Git, repository, commit, and GitHub are, and start a history for just one training folder, checking by the terminal response?
In a task, an agent can change ten files at once. Without history, you don’t know what changed or how to go back to the version that worked. With history, each good version is saved, with date and explanation.
In 1 minute
In the class diary, each day gets a line with date and signature. Nobody deletes yesterday’s line: they add today’s.
The Git does the same for a folder. The folder tracked by it is called a repository. Each saved version is called a commit and includes a message that explains the change.
Lúcia asked a agent to reorganize the experiment lab worksheets. It edited six files and cut a section from the density worksheet. Using the history, she found the previous version and recovered the section.
Git works only on your computer, without the internet. The GitHub is a website that can store a copy of the repository.
You can use Git for months without publishing anything. Sending a copy to GitHub is a separate decision, which the module covers in lesson 6.
Denise keeps on her notebook the history of the coordination reports folder. None of that is on the internet. The copy on GitHub will only exist if the school decides that another person needs to work in the same folder.
Where: on your computer, inside the folder.
What for: to keep versions and go back to one of them.
Where: on a website, on the internet.
What for: to keep a copy for another computer or another person.
Test yourself
Denise just saved a commit of the report in her notebook. Can someone outside the school see this version?
Git stores only what’s in the folder and what you told it to store. It doesn’t replace the backup of the rest.
Files that you tell it to ignore, the school’s systems, and spreadsheets in the cloud need their own protection.
Denise’s attendance spreadsheet lives in the secretary’s system. The history of the reports folder stores the report text, but it doesn’t store that spreadsheet.
On the terminal, git --version confirms that Git is on your computer. Then, inside a new folder, git init -b main starts the history.
mkdir -p creates the folder, and cd takes you into it. The -b main just gives the name main to the main working line. Never run git init in your entire personal folder: Git would start tracking everything that’s in there.
Lúcia created the treino-git folder inside projetos, entered it, and only then started the history. The terminal response cited the folder path, and she checked that it was the training one.
$ git --version
git version 2.43.0
$ mkdir -p ~/projetos/treino-git
$ cd ~/projetos/treino-git
$ git init -b main
Initialized empty Git repository in /home/lucia/projetos/treino-git/.git/
The last line, in English, says "empty repository initialized in…". Check that the path ends in treino-git. The .git at the end is the hidden folder where the history lives: don’t touch it.
Stuck here? That's normalIf you see command not found, Git isn’t installed. Stop and follow the official page, git-scm.com, for your system. On Mac, you can open a window offering command-line tools: accept, wait for it to finish, and repeat. If you see unknown switch, your Git is older than version 2.28: update using the same page and repeat. On Windows, use the Bash of the WSL prepared in module 3; if it’s not ready yet, go back there before continuing. The response may come in Portuguese if your system is in Portuguese: the meaning is the same.
Practice now 0/3
Ready when the terminal responds that the empty repository was initialized in treino-git and shows No commits yet. About 8 minutes, on your computer.
The folder is new and empty: nothing you have is touched, and nothing leaves the computer. If the response path doesn’t end in treino-git, stop. Don’t delete anything on your own; note which folder you used and ask someone who uses Git.
Block 1 · check the Git:
git --version
Block 2 · create the folder and go into it:
mkdir -p ~/projetos/treino-git cd ~/projetos/treino-git pwd
Block 3 · start the history:
git init -b main git status
You just started a history in a folder you chose, and you confirmed from the response that it was the right folder.
Lesson cheat sheet
Git records versions of files. A repository is the folder that’s tracked by that history; a commit is a record with changes and a message. GitHub is a service that hosts remote repositories. You can use Git locally without publishing anything on the internet.
When an agent changes many files, the history allows you to understand what changed and recover a known version. Git does not replace a full backup: ignored files, databases, and external data need their own protection.
Repository; commit; history; remote; backup.
A manager changes the report template and loses a section. A previous commit preserves the old content; a clear message helps locate the change.
Run git --version. In the training folder, use git init -b main. Don’t initialize the history in your entire personal folder.
Accepting a conclusion without checking the input that supports it.
Lesson 31 · OSWork v6.2 · INEMA.CLUB PRO
Module 6 · Lesson 2 of 6

You can read the answers from git status, git diff, and git diff --cached and say which step each file is in: either out of the history or staged for the next version.
An agent can create files you didn’t ask for. If you save everything at once, a personal note ends up in the history along with the work. Checking first costs one minute.
In 1 minute
git status tells you which step each file is in.git add with the file name separates only it for the next version.git diff --cached shows, line by line, what will go in.In a test, you separate the sheets that will go into this version, and only then you staple. The draft stays on the desk.
Git works the same way. A new or modified file sits in the folder: step 1. When you stage it, it goes to step 2, which Git calls staging. The commit staples what was staged: step 3.
Denise builds the 9th grade practice test. She separates the math and Portuguese sheets into a stack and staples them. The sheet with her answers stays on the table, outside the test.
git status tells you the stage of each fileRun git status always before separating anything. The answer comes in English, in blocks with a title.
Lúcia wrote the README for the training folder and a note with scattered ideas for the lesson. The status showed both files in the same block, still outside the history.
$ git status
On branch main
No commits yet
Untracked files:
(use "git add <file>..." to include in what will be committed)
README.md
notas-privadas.txt
"Untracked files" means "files outside the history". Both are in step 1.
git add with the filename separates only what you wantWrite the filename after git add. That way you can see the size of the change and you don’t include anything that isn’t related.
There’s a shortcut git add ., which separates everything that isn’t ignored. To learn, name each file.
Lúcia ran git add README.md. In the next status, the README moved to the next version’s block, and the note stayed where it was.
$ git add README.md
$ git status
On branch main
No commits yet
Changes to be committed:
(use "git rm --cached <file>..." to unstage)
new file: README.md
Untracked files:
(use "git add <file>..." to include in what will be committed)
notas-privadas.txt
"Changes to be committed" is step 2: what goes into the next version. The note stays in step 1.
Common mistakeUsing git add . in a hurry. It separates everything at once, including the personal note that was in the folder.
Status tells you which files. The diff shows what’s written in them. git diff --cached shows what has already been separated and will be included in the version.
git diff, with nothing else, shows changes that haven’t been separated yet, but only in files that Git is already tracking. A file outside the history, like the note, never appears in it.
Lúcia ran both commands in the training folder. The first one came back empty: the README was already separated and the note is outside the history. The second one showed the README lines with a plus sign in front.
$ git diff
$ git diff --cached
diff --git a/README.md b/README.md
new file mode 100644
index 0000000..4280337
--- /dev/null
+++ b/README.md
@@ -0,0 +1,3 @@
+# Treino de Git
+
+Pasta para praticar o histórico.
The first one showed nothing. In the second, skip the header, until the line that starts with @@: what matters are the lines that start with +, the text that will be included.
Stuck here? That's normalIf the screen stops with two colons in the footer and doesn’t return to the cursor, Git opened the response in read mode. Press the q key to exit. Nothing was lost. If your terminal responds in Portuguese, the block titles come translated, in the same order.
Practice now 0/3
Ready when the status shows the README in "Changes to be committed", the note in "Untracked files", and you know how to explain why git diff came back empty. About 10 minutes, on the computer.
Everything happens in the treino-git folder and nothing is saved in the history yet. The > sign creates the file and replaces another one with the same name: that’s why you only run these lines inside treino-git. If the “cd” gives an error, stop and do the lab worksheet for lesson 1 of the module first. Did you close the terminal between blocks? Run “cd ~/projetos/treino-git” again before continuing.
Block 1 · create the two files and look at the status:
cd ~/projetos/treino-git printf '# Git Practice\n\nFolder to practice the history.\n' > README.md printf 'loose ideas, don't publish\n' > notas-privadas.txt git status
Block 2 · separate only the README:
git add README.md git status
Block 3 · compare the two diffs:
git diff git diff --cached
mkdir -p ~/projetos/treino-git cd ~/projetos/treino-git git init -b main
You just chose, file by file, what goes into the next version, and checked the contents before saving.
Lesson cheat sheet
git status shows new, modified, and staged files. git diff shows changes not yet staged; git diff --cached shows what will go into the next commit. The staging area, called staging, lets you choose exactly which files belong to the same change.
git add . stages everything that is not ignored. For learning, prefer naming files: you see the scope better and reduce the risk of including unrelated material.
Working tree; staging; diff; content review.
You changed README.md and created a private note. git add README.md stages only the documentation. Before committing, git diff --cached confirms what will be recorded.
Run git status, git diff and git diff --cached. If any output is empty, explain at which stage the changes are.
Lesson 32 · OSWork v6.2 · INEMA.CLUB PRO
Module 6 · Lesson 3 of 6

You can set the authoring only in the treino folder and leave the personal note out using the .gitignore. Then, create the first commit with a message that says what changed.
In a month, a version called "update" means nothing. A concrete message helps you find the right version in seconds and remember whether it worked.
In 1 minute
Each version stores a name and an e-mail. Configure both with git config, inside the training folder. Without the word --global, the configuration applies only to this repository.
In the training, the e-mail can be fictional. It shows up in each version and becomes visible one day if the folder is published to the GitHub.
Lúcia configured a fictional e-mail only in the training folder. In the science worksheets folder, she will configure the school e-mail. Each folder keeps its own.
$ git config user.name "Lúcia Andrade"
$ git config user.email "lucia@exemplo.com"
$ git config user.name
Lúcia Andrade
The first two lines answer nothing. The third, with no value at the end, only reads the configured name.
The .gitignore is a text file with one line per item to ignore. The Git stops offering those files to versions.
This applies to files that haven’t been staged and saved yet. What has already been saved stays tracked, even after being listed.
That’s why create the list before the first version. That’s where later the .env—the passwords file—comes in.
In her training, Denise put the name of her personal note into the .gitignore. In the next status, the note disappeared from the list. It’s still in the folder, but Git no longer offers it.
$ printf 'notas-privadas.txt\n' > .gitignore
$ git status
On branch main
No commits yet
Changes to be committed:
new file: README.md
Untracked files:
.gitignore
The note no longer appears. In its place, the .gitignore itself shows up, and it also goes into the history. A name that starts with a dot is hidden in the file manager; the file still exists.
A captionless event photo tells you nothing ten years later. The version message is that caption: say what changed, with a verb and an object.
Save when the change is confirmed. A version is a safe point to return to only if you know it worked.
Denise wrote "Add the attendance board by class to the September report". The next week, she found that version by reading only the list.
Message: "update"
One month later: nobody knows what changed without opening the files.
Message: "Create README and list what not to keep"
One month later: the versions list already answers.
Separate the two files by name and save with git commit -m and the message in quotes. Then, git log --oneline shows the short list of versions, one per line.
Lúcia saved the README and the .gitignore in a single version. The log showed one line with a short code and her message.
$ git add README.md .gitignore
$ git commit -m "Cria README e lista do que não guardar"
[main (root-commit) 5f6c1eb] Cria README e lista do que não guardar
2 files changed, 4 insertions(+)
create mode 100644 .gitignore
create mode 100644 README.md
$ git log --oneline
5f6c1eb (HEAD -> main) Cria README e lista do que não guardar
"2 files changed" confirms both files. 5f6c1eb is the short code for this version; on your computer it will be different.
Stuck here? That's normalIf the commit response brings "Please tell me who you are", the name and e-mail haven't been configured in this folder. Run the two lines from step 1 and repeat the commit. Nothing was lost.
Practice now 0/3
Ready when the log shows a line with your message and the status answers "nothing to commit, working tree clean". About 10 minutes, on your computer.
Everything stays in the treino-git folder, and nothing leaves your computer. Replace the name and e-mail with yours, or with fictional ones. If the status still lists notas-privadas.txt, don’t save. In "Untracked files", check the name written in the .gitignore. In "Changes to be committed", you separated it before: run “git rm --cached notas-privadas.txt”, which removes it from the pile without deleting the file, and check the status again. Did you paste block 1 without changing the name? Run it again with yours; the new one replaces the previous.
Block 1 · change the name and e-mail before running:
cd ~/projetos/treino-git git config user.name "Your Name" git config user.email "your-email@example.com"
Block 2 · the list of what not to keep:
printf 'notas-privadas.txt\n' > .gitignore git status
Block 3 · save and check:
git add README.md .gitignore git commit -m "Creates README and list of what not to keep" git log --oneline git status
mkdir -p ~/projetos/treino-git cd ~/projetos/treino-git git init -b main printf '# Git Training\n\nFolder to practice history.\n' > README.md printf 'loose ideas, don’t publish\n' > notas-privadas.txt
You just saved the first version with authorship, with a message that explains and without the personal note.
Lesson cheat sheet
Configure user.name and user.email locally to identify authorship. Stage the desired files and use git commit -m with a concrete description. A commit should represent a change you can explain and verify.
Messages like “update” make the history less useful. A version is only a reliable point if you know whether it worked and what checks were performed.
Authorship; message; cohesive change; verification.
“Add instructions to check sales” says what changed. Then, git log --oneline shows a compact list of the records and their identifiers.
Lesson 33 · OSWork v6.2 · INEMA.CLUB PRO
Module 6 · Lesson 4 of 6

You can copy the course’s public repository into a separate folder, check its status, and update with git pull --ff-only, knowing how to stop when it refuses.
A project stored on GitHub changes while you work. Updating on top of changes can mix everything up. A command with a brake updates when it’s safe and stops when it isn’t.
In 1 minute
git clone brings over the folder and the whole history to your computer.git pull --ff-only only updates via the direct path; if it refuses, stop and look.The network workbook arrives as a full copy, with every page. The clone does that with a repository from the GitHub: it creates a new folder with the files and all the versions.
On the terminal, just the address and the name of the new folder are enough. Cloning runs nothing. Still, read before running any program that came with the clone, including from a known repository.
The teaching network stores report templates in a public repository. Denise cloned it into a single folder just for that, far from her report folder.
$ cd ~/projetos
$ git clone https://github.com/inematds/oswork-v62.git clone-curso
Cloning into 'clone-curso'...
$ cd clone-curso
"Cloning into" means "copying to". The last word on the second line is the name of the new folder.
Run git status inside the cloned folder. If it says there’s nothing of yours to save, then the update has nothing to merge.
In the response you’ll see origin/main: origin is the alias for the address the folder came from, and main is the main work line from there.
Lúcia cloned the course repository and ran status. The response said the folder was the same as back there, with nothing of hers to save.
$ git status
On branch main
Your branch is up to date with 'origin/main'.
nothing to commit, working tree clean
"On branch main": you’re on the main line. "Up to date with origin/main": same as the latest version you pulled in. "Working tree clean": no changes of yours in the folder.
pull --ff-only updates only by the direct pathThe pull command fetches the new versions and merges them into your folder. With --ff-only, it accepts only the simple case: the new versions fit right after the last one you already have.
This is the booklet that gets new pages at the end. Nothing you had needs to be changed.
A week later, the network added a new model. Denise ran pull with freio, and the response showed the new file that arrived.
$ git pull --ff-only
Already up to date.
$ git pull --ff-only
Updating 0999fe3..33113cd
Fast-forward
aulas/aula-7.html | 1 +
1 file changed, 1 insertion(+)
create mode 100644 aulas/aula-7.html
First response: "already up to date", nothing came in. Second: "Fast-forward", the direct path, with the list of what arrived.
If you saved a version here and a new version also arrived there, then the two lines split. --ff-only refuses and makes no changes.
That refusal is information, not a defect. Don’t delete your work to get around it. Read the history with git log --oneline, or ask for help by including the full message.
Lúcia had saved, in the clone, a version with her own notes, the way it was in lesson 3 of the module. The same day, the course published a new version. The pull refused. She copied the message and asked in the course group before doing anything else.
$ git pull --ff-only
hint: Diverging branches can't be fast-forwarded, you need to either:
hint:
hint: git merge --no-ff
hint:
hint: or:
hint:
hint: git rebase
fatal: Not possible to fast-forward, aborting.
$ git status
On branch main
Your branch and 'origin/main' have diverged,
and have 1 and 1 different commits each, respectively.
The last help line was omitted. "Not possible to fast-forward, aborting": it couldn’t go by the direct path and it stopped. The status confirms it: one version of yours and one from there.
Stuck here? That's normalThe response suggests two commands. Don’t run either of them now, even if an AI chat tells you to: the two merge the lines in different ways, and choosing requires looking at the history. Stopping here doesn’t cost you anything, because the Git didn’t change your folder.
Practice now 0/3
Ready when the status says "up to date with 'origin/main'" and the pull responds "Already up to date." About 8 minutes, on the computer, with internet.
The clone goes into a new folder, clone-curso, separate from the training folder. No programs are run. If you see "destination path 'clone-curso' already exists", you cloned before: continue from block 2.
Block 1 · clone:
cd ~/projetos git clone https://github.com/inematds/oswork-v62.git clone-curso
Block 2 · enter and check:
cd ~/projetos/clone-curso git status git log --oneline -3
Block 3 · update with a safety lock:
git pull --ff-only
You just brought an entire project from GitHub and updated it using only the safe path.
Lesson cheat sheet
git clone copies a remote repository and its history. git pull looks for and integrates changes into the current branch. Before updating, check git status. In an initial flow, git pull --ff-only only accepts a direct update and stops when the histories diverged.
Updating a folder with local changes can create conflicts. The --ff-only block is useful information: don't bypass it by deleting work. Inspect the history or ask for help with the context.
Clone creates the folder; pull updates; branch is a line of work; divergence requires review.
You cloned a project yesterday, and today there are new instructions on GitHub. Without local changes, --ff-only usually moves the version forward. With different commits on both sides, stop and inspect.
Clone the public repository of this course into a separate folder. Read before running any program you receive, including known repositories.
Mix the training copy with private files or production work.
Lesson 34 · OSWork v6.2 · INEMA.CLUB PRO
Module 6 · Lesson 5 of 6

You can create a second training version, undo it with git revert, and check in the README itself that the old title is back, with all three versions in the history.
When a saved version was wrong, the urge is to delete the record. Deleting hides what happened and can take good work with it. Undoing it with a new record corrects it and keeps the full history.
In 1 minute
git revert creates a new version that undoes the previous one, without deleting anything.Each Git recovery command has a different consequence. That is why the choice starts with a diagnosis: is the change only in the file, in a version saved on your computer, or in a version already sent to GitHub?
Denise changed the report title for September and saved the version. The next day, the board asked for the old title back. The change was in a saved version, and that’s what decided the command.
The school newspaper doesn’t recall the edition with an error. It publishes an erratum that corrects it and shows that a correction happened.
The revert does the same: it creates a new commit that undoes the previous one. The three versions stay in the history: the original one, the wrong one, and the correction.
Lúcia changed the materials list of a lab worksheet and saved. She realized she had deleted the beaker. With the revert, the list came back, and the history shows that there was the change and then the return.
What it does: deletes the wrong version from the history.
Risk: the record of what happened is gone, and it can take good work with it.
What it does: creates a new version that undoes the wrong one.
Result: the file returns, and the history tells you the error and the fix.
The HEAD is the page marker of the history: it points to the version you are currently on, usually the last one saved. The command in this lesson undoes the version marked, so check first which one it is.
git log --oneline shows the list, with the newest at the top. On the marked line, you see (HEAD -> main): the marker is here, on the main line.
In the practice folder, Lúcia changed the title of the README and saved a second version. The log showed this version at the top, with the HEAD marker.
$ git diff
@@ -1,3 +1,3 @@
-# Treino de Git
+# Treino de Git — versão nova
Pasta para praticar o histórico.
$ git log --oneline
7ef98be (HEAD -> main) Muda o título do README (treino)
5f6c1eb Cria README e lista do que não guardar
In the diff (header cut off), the line with − is the title that was removed, and the one with + is what was added; lines with no sign didn’t change. In the log, the top line, with HEAD, is the title change: that’s what the revert will undo. The codes will be different on your computer.
Stuck here? That's normalIf the top line isn’t "Changes the README title (practice)", stop and don’t run the revert. Run git status and check that you’re in the treino-git folder. Stopping costs nothing; undoing the wrong version would cost work.
git revert --no-edit HEAD undoes the last version and uses an automatic message; without it, Git would open a text editor for you to type the message. Then, open the README and read the title. The terminal response says that something happened; the file tells you whether it was correct.
Denise ran the revert in the report and opened the file. The old title was back, and the log had a new line starting with "Revert".
$ git revert --no-edit HEAD
[main b11f583] Revert "Muda o título do README (treino)"
1 file changed, 1 insertion(+), 1 deletion(-)
$ cat README.md
# Treino de Git
Pasta para praticar o histórico.
$ git log --oneline
b11f583 (HEAD -> main) Revert "Muda o título do README (treino)"
7ef98be Muda o título do README (treino)
5f6c1eb Cria README e lista do que não guardar
cat shows the file: the title is back. The log has three lines: the original, the change, and the errata.
Then the command is different: the restore, with the file name, discards changes not yet separated with git add. What you wrote is lost, with no way back. Use it only when you’re sure, and never for the entire folder. You’ll also find reset --hard on the internet as a solution for everything: it deletes changes with no way back, and this course doesn’t use it.
Practice now 0/3
Ready when the README shows again the title it had before block 1, and the log has three lines, the top one starting with "Revert". About 10 minutes, on the computer.
Everything happens in the treino-git folder and nothing leaves your computer. The revert doesn’t delete any version. If the block 1 log doesn’t show the training change at the top, don’t run block 2. If the revert responds “Your local changes … would be overwritten”, there was a change that wasn’t saved in the README and it did nothing: run “git status” and ask for help before discarding anything.
Before · make sure there’s nothing unsaved (the answer should end with working tree clean):
cd ~/projetos/treino-git git status
Block 1 · make the change and save it. The first line rewrites the entire README, with the new title (each \n is a line break):
printf '# Git Training — new version\n\nFolder to practice history.\n' > README.md git diff git add README.md git commit -m "Changes the README title (training)" git log --oneline
Block 2 · only after checking the log:
git revert --no-edit HEAD cat README.md git log --oneline
mkdir -p ~/projetos/treino-git cd ~/projetos/treino-git git init -b main git config user.name "Seu Nome" git config user.email "seu-email@exemplo.com" printf '# Git Training\n\nFolder to practice history.\n' > README.md printf 'private-notes.txt\n' > .gitignore git add README.md .gitignore git commit -m "Creates README and lists what not to keep"
You just undid a saved version without deleting anything, and you checked in the file itself.
Lesson cheat sheet
git revert creates a new commit that undoes a previous change. It is appropriate for fixing a record that has already been shared. git restore discards unsaved changes of selected files; it can lose work. Do not teach reset --hard as an automatic response to any difficulty.
Recovery tools have different consequences. Identify whether the change is only in the file, in a local commit, or published before choosing the command.
Revert preserves history; restore discards selected changes; recovery requires diagnosis.
In the training, make a second commit changing the README title. git revert HEAD creates a third commit that restores the previous title, without hiding that the change occurred.
Use git revert --no-edit HEAD only after confirming that HEAD is the second training commit. Open the README and check the result, not just the Git message.
Lesson 35 · OSWork v6.2 · INEMA.CLUB PRO
Module 6 · Lesson 6 of 6

You can do the check of four points before a push — destination, folder status, versions that would be sent, and secrets — and decide in writing whether you would send it.
Saving and publishing seem like the same thing, and they’re not. Mixing them up can make you send a draft or a password somewhere other people can see. After it’s sent, the content stays with whoever has access to the destination.
In 1 minute
In your notebook, only you see the note. Once it’s posted in the secretary’s system, everyone with access sees it. If it’s printed on the bulletin, it goes to the families.
In Git, it’s the same. The commit is on your computer. The push sends the versions to GitHub. Putting a site online is an extra step, which depends on the hosting.
Lúcia saved three versions of the density script in her notebook. None left it. Sending it to GitHub would have been her decision, with her own review.
git remote -vRun on the terminal; the command shows where the folder sends. The address appears with the nickname origin. The account owner is part of the address, right after github.com.
An empty response means the folder has no destination: a push would have nowhere to go.
Before sending the report templates, Denise ran the command. The address pointed to the repository of the education network, not the one for the coordination. She stopped there.
$ cd ~/projetos/treino-git
$ git remote -v
$ cd ~/projetos/clone-curso
$ git remote -v
origin https://github.com/inematds/oswork-v62.git (fetch)
origin https://github.com/inematds/oswork-v62.git (push)
In the training, nothing: there’s no destination. In the clone, the destination is the inematds account, which isn’t yours; you don’t have permission to send there.
git status tells you if anything is left unsaved. git show --stat shows the last version: author, message, and the list of files it changed.
The push sends all the versions the destination doesn’t have yet, not just the latest one. The status tells you how many: up to date with 'origin/main' means none; ahead of 'origin/main' by 2 commits means two. Without a destination, like in the practice, this line doesn’t show up, and it would be the entire log history.
Lúcia ran both in the practice folder. The status was clean. The last version was the errata from the previous lesson, and it only touched the README.
$ git show --stat
commit b11f583e5f52d25a3b67584457953303751f2cc5
Author: Lúcia Andrade <lucia@exemplo.com>
Date: Fri Sep 25 00:38:59 2026 -0300
Revert "Muda o título do README (treino)"
This reverts commit 7ef98be6e53aff1d9381c1126153d7270b9cfd20.
README.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
Ignore the "commit" line with the long code. "Author" shows the name and the email that would go along with it. In the end, "README.md | 2 +-": one file, with one line that went out (−) and one that came in (+).
Look only at the versions that would go. If the status says none would, there’s nothing to look for. In the versions that would go, look for password, key, or .env in the file list. A draft also counts: if it’s in a version, it’s included.
Public means anyone on the internet can see it. Private also requires care: anyone with access can see everything.
Denise found a draft with students’ names in an old version of the folder. She didn’t send it. She asked the school’s tech team for help before any sending.
Stuck here? That's normalDid you find a password in a saved version? Don’t send it. Deleting the file now doesn’t remove the password from older versions. Note which version it is, from the log, and ask whoever manages the project for help before any sending.
Practice now 0/3
Ready when you have the check filled out for the practice folder and for the course clone, each one with the decision and the reason. About 10 minutes, on the computer. Write it down on paper or in a notepad.
Read-only: none of the commands in this practice sends anything. Don’t run the push. In the practice folder there’s no destination, and in the course clone the account isn’t yours. The --no-pager option just makes the whole response come out, without stopping the screen. Didn’t do the previous lessons? Use any folder with history that you have.
Block 1 · training folder:
cd ~/projetos/treino-git git remote -v git status git --no-pager log --oneline git --no-pager show --stat
Block 2 · course clone:
cd ~/projetos/clone-curso git remote -v git status git --no-pager show --stat
CHECK BEFORE SENDING · <folder name> 1. Destination: <remote address, or "none"> 2. Status: <clean, or what was left without saving> 3. Versions that would go: <what the status says is up to date or ahead by N; with no destination, all from the log> 4. Secrets: <none, or which file> Decision: <send · don't send>, because <reason>
Folder: clone-curso.
1. Destination: github.com/inematds/oswork-v62, course account.
2. Status: clean.
3. Versions that would go: none; the status says up to date with origin/main.
4. Secrets: none from me.
Decision: don't send, because the destination account isn't mine and I didn't change anything.
You just separated saving from sending, and you decided based on what the terminal showed.
Lesson cheat sheet
git push sends commits to the remote. Before that, verify the account, the destination URL, the scope of the files, and the absence of credentials. A public repository is accessible to third parties; private also requires access control. Publishing a site is an additional step, depending on the hosting.
Mixing save and publish leads to accidental exposure. Separate “record locally”, “push to GitHub” and “put the site live” in your checklist.
origin; push; visibility; credentials; publication.
A local README may contain drafts. The commit preserves those drafts on the machine. Only push when you have decided they can be part of the chosen remote.
Use git remote -v and git status. Confirm the URL and review the last commit with git show --stat before deciding to push.
Use fictitious files and a training folder. Practices with installation, Telegram, or VPS may require extra time for sign-up and setup.
Read the block before using. Fields like Your Name and usuario@ip-da-vps are examples to adapt; administrative commands belong only to your training environment.
git init -b main
git config user.name "Seu Nome"
git config user.email "seu-email"
git status
git add README.md .gitignore
git diff --cached
git commit -m "Registra estrutura inicial de treino"
git log --onelineSave a version, inspect differences and recover a training change. Record the produced file, the test run and the observed result.
Use this rubric after the lab. Each line asks for evidence; checking reading does not mean the practice was performed.
git commit already sends the files to GitHub?
No. Commit records locally; push sends to the configured remote.
If your answer was different, return to the corresponding topic and write the difference in one sentence. The check does not block your study.
Tools verified on 20/09/2026; screen names and availability may change.
Terms in this section: .gitignore.
Lesson 36 · OSWork v6.2 · INEMA.CLUB PRO
Module 7 · Lesson 1 of 6

You can map the path of a message — phone, Telegram, bot, allowed function, response — and mark the only stage where an AI would actually be useful.
It’s common to call any automatic response an intelligent agent. When that gets mixed up, nobody knows what the bot can do, or where it fails. Separating the door from who works makes each part easier to test.
In 1 minute
In this module, you’ll talk with your own bot through your Telegram. The app on your phone only carries your message and brings the response back.
The one who reads, decides, and responds is a program that runs on your computer. Think of the intercom in the gatehouse: the device carries the voice, but the person inside opens the gate.
Denise heard that another school "has an agent on Telegram". She asked what it did and found three ready-made answers, with no AI at all. The name promised more than the thing delivered.
Receives what you type on your phone.
Delivers the response in the same conversation.
Checks who wrote it and which command it is.
Runs only the allowed function and builds the response.
The course kit bot has two working commands, and neither uses AI. /status confirms that it’s turned on. /relatorio adds up three made-up sales from the vendas.csv file, a spreadsheet in CSV.
You download this kit in the next lesson. For now, see what it returns.
Lúcia will use the bot to look up the fictional shop run by the student group: notebook, pen, and planner. The total comes from a calculation made by the program, not a guess.
Lúcia/status
BotOSWork active. Restricted access. Deterministic training bot.
Lúcia/relatorio
BotFictional training data: 3 sales; total R$ 100.00. No AI call.
Both answers come from fixed rules in the program. "Deterministic" means this: the same request always produces the same response.
Who writes on Telegram doesn’t control the computer. The bot compares the message to a short list of known commands. Everything else gets the same default response.
This even applies to the bot owner. Free text is never executed as an order. The /start and /help commands exist, but they only show the list of the two working commands.
Denise imagined a secretary bot that would receive "delete the absences from yesterday". With the list closed, that text comes back as an unknown command, and nothing is deleted.
Someone writes: "delete the folder of the tests".
Result: the computer obeys. No going back.
Someone writes: "delete the folder of the tests".
Result: "Unknown command. Use /status or /relatorio."
Net gain: the same sentence, zero files changed in the kit bot.
Test yourself
A colleague says: "our Telegram bot is an intelligent agent". What do you ask first?
Draw the entire path before thinking about AI. Then mark the step where it would truly help.
A good candidate is the function: it can produce a text summary from the numbers. The rule is strict: the number stays as the one from the program.
Lúcia marked the summary step. The AI could write "the agenda was the biggest sale," as long as the R$ 100,00 total stays exactly as the program calculated.
Stuck here? That's normalYou don’t yet need any bot running. In this lesson, drawing it on paper is enough. The bot creation starts in the next lesson, step by step.
Practice now 0/3
Ready when the drawing has five boxes, who does what in each one, and an X in only one step. About 8 minutes, on paper or in the phone’s notepad.
Nothing here changes the computer or Telegram. Still unsure about the X? Mark it in the function: that’s where you assemble the text the person will read, before it goes back through Telegram.
Denise drew the secretary’s inquiry bot: cell phone (the mother asks /hour) → Telegram (delivers) → bot (checks whether the number is authorized) → function (reads the schedule spreadsheet) → response. The X is in the function box, with the line: "the AI rewrites the schedule into simple sentences; the schedule stays the one from the spreadsheet".
You separated the door of who works and knows how to say where an AI would enter without taking over everything.
Lesson cheat sheet
A bot receives messages through the API of Telegram and returns responses. Intelligence can come from rules, from a program, or from a call to a model. The app on your phone doesn’t independently run its tasks on the server: there is an intermediary program with defined permissions.
Separating interface and execution prevents calling any automatic response from an intelligent agent. First build a reliable path to receive and respond; then connect the needed capability.
Message; Bot API; program; agent; result.
/status queries the bot's state without AI. /relatorio calculates fictitious sales without AI. A natural language summary could be added later, preserving the calculated numbers.
Draw: phone → Telegram → bot → permitted function → response. Mark at which stage a future AI call would actually be useful.
Accepting a conclusion without checking the input that supports it.
Lesson 37 · OSWork v6.2 · INEMA.CLUB PRO
Module 7 · Lesson 2 of 6

You can create your bot in BotFather and save the bot token only in the .env file. Only your account reads the file, and the token never shows up in any screenshot.
Whoever has the token runs the bot. A screenshot of the conversation or a pasted copy into a document is enough to leak access. Getting it right in the first minute costs less than fixing everything later.
In 1 minute
Every bot of the Telegram is born in a conversation with the BotFather. You send /newbot, choose a name and an identifier, and it returns the bot token.
The identifier must end in "bot", like lojinha_gremio_lucia_bot. If it’s already in use, BotFather asks you for another one. The token is a line of numbers, colons, and letters. It works like the school gate key: whoever has the copy gets in, no matter who they are.
Lúcia created the grêmio’s shop bot in three messages. First, she checked that she was talking to the official BotFather: @BotFather, with the verified blue checkmark, and not an account with a similar name.
Lúcia/newbot
BotFatherChoose a name for your bot.
LúciaLojinha do Grêmio
BotFatherNow choose an identifier for it.
Lúcialojinha_gremio_lucia_bot
BotFatherDone. This is your bot token: [hidden in this lesson]
BotFather replies in English; here the messages are translated and summarized. The token is hidden on purpose.
In the bot folder, the course kit (link in step 1 of the practice) includes an example file, the .env.example, with mock values only. You make a copy called .env and paste the token inside it.
The .env stays only on your computer. The token doesn’t show up in a screenshot, in a message, or in a shared document.
Denise thought about putting the token in the secretariat’s instruction document, "so nobody loses it." She changed her mind: the document says where the .env is, never the value.
Pasted into the team’s instruction document.
Shows up in a screenshot sent to the school group.
The TELEGRAM_BOT_TOKEN line is filled in only in the private file.
The document tells the file path, not the value.
Net gain: one place to protect, instead of several to watch.
The course kit file is oswork-kit.zip; the link is in step 1 of the practice. Open the terminal and go into the bot folder, inside the kit you extracted. Copy the example, restrict the reading, and verify.
The chmod 600 line makes it so only your account can read and change the file. Check the result line: it starts with -rw-------, with one r and one w.
Lúcia ran the four commands and found -rw------- on the first try. Then she pasted the token into the file, saved, and closed without taking a screenshot.
$ cd ~/projetos/oswork-kit/bot
$ cp .env.example .env
$ chmod 600 .env
$ ls -l .env
-rw------- 1 lucia lucia 66 set 25 10:02 .envThe first three commands show nothing when they work. The last one shows the line to check.
Stuck here? That's normalDid "No such file or directory" appear? You’re not in the right folder. Repeat the cd with the path where you extracted the kit. If the line doesn’t start with -rw-------, run the chmod 600 .env again and verify.
If the token showed up in a screenshot, in a message, or in a document, treat it as leaked. In BotFather, send /mybots, choose the bot, tap API Token, and then Revoke current token. It generates a new token, and the old one stops being valid.
After that, change the value in the .env. A link that starts with api.telegram.org/bot and includes the token right after it is also a leak.
During a meeting, Denise saw a colleague’s screenshot with a bot’s token out in the open. She warned immediately. The team revoked and changed the value in the .env in ten minutes.
Practice now 0/5
Ready when ls -l shows -rw------- in the .env and the token is in there, without having gone through screenshots or a message. About 12 minutes, on the computer with the terminal and Telegram on your phone.
You create a brand-new bot, just yours, and you only touch the kit folder. None of the commands here delete anything. If the token shows up in any screenshot, stop, revoke it in BotFather, and redo the last step with the new token.
cd ~/projetos/oswork-kit/bot cp .env.example .env chmod 600 .env ls -l .env
The nano opens the file inside the terminal itself. You’ll see two lines: TELEGRAM_BOT_TOKEN=preencha_localmente and ALLOWED_USER_IDS=123456789. In this lesson, change only the first one. The second one is for the next lesson.
You created a bot and saved its key somewhere only your account can access.
Lesson cheat sheet
In Telegram, find the official BotFather and use /newbot. Choose a name and identifier as shown in the instructions. The generated token authenticates your program with Telegram. Store it as TELEGRAM_BOT_TOKEN in a private file; the kit only contains example values.
Anyone who controls the token can operate the bot. Screenshots of the process and URLs containing the token can leak access. If exposed, revoke the token in BotFather before continuing.
BotFather; token; environment variable; rotation.
The teacher creates a bot for personal use. She doesn’t put the token in the README and she doesn’t send the credentials file to the students. Each installation uses her own credentials.
Use the kit's --identify mode: it reports the ID of who sends /start in the local terminal, without granting access to operational functions.
Lesson 38 · OSWork v6.2 · INEMA.CLUB PRO
Module 7 · Lesson 3 of 6

You can find your numeric ID in Telegram using the kit identification mode and put it in the bot’s access list.
Anyone can find a bot in Telegram and send a message. The token proves that the program owns the bot, but it doesn’t say who can use it. That second decision is yours, and it’s written in a list.
In 1 minute
The bot token proves to the Telegram that your program owns the bot. It doesn’t say anything about who can chat with it.
That’s why the kit has a second control: the access list. It’s like the list of who’s allowed to look up each student in the school output.
Denise explained it to the team like this: the key opens the gate; the exit list says who takes each student. Two checks, and one doesn’t replace the other.
Proof that the program owns the bot.
It stays in the .env, on the TELEGRAM_BOT_TOKEN line.
Says which people the bot serves.
Stays in the same .env, on the ALLOWED_USER_IDS line.
The name that appears in the chat is something the person can change whenever they want. The bot checks the numeric ID, which Telegram gives to each account.
To find yours, the kit has a single identification mode. On your phone, the bot doesn’t respond to anything in this mode: the number appears in the terminal.
Lúcia shows up on Telegram as "Lúcia Ciências". If you change it to "Prof. Lúcia", the bot keeps recognizing you: her number is the same.
$ python3 bot.py --identify
Identificação apenas: envie /start em privado; confira seu ID abaixo e encerre com Ctrl+C. Nenhuma função operacional ativa.
ID recebido na identificação: 7012345678
^C
Bot encerrado.The ID line only shows up after you send /start to the bot, in a private chat. The number here is fictional; yours will be different.
Before responding, the program checks three things, in this order. If you fail gates 1 or 2, you don’t get even a "no": the bot stays silent. At gate 3, the response is only "Unknown command".
This check is at the beginning of the handle_message function, inside bot.py.
Denise wanted to test Lúcia’s bot. She sent /relatorio and got nothing back. It wasn’t a bug: her number wasn’t in the list.
if message.get('chat',{}).get('type')!='private':return None
if message.get('from',{}).get('id') not in allowed:return None
"return None" means: don’t respond to anything. To find these lines on your computer, run grep -n "allowed" bot.py in the bot folder.
With the number in hand, end the identification mode with Ctrl+C. Open the .env and replace 123456789, which is just the kit’s example, with your ID.
To authorize more than one person, separate the numbers with a comma. Start with only you.
Lúcia thought about adding her colleague from the library. She left it for later, after the test: with fewer people on the list, it’s easier to check.
ALLOWED_USER_IDS=123456789
No real person is on the list. The bot stays silent, even for you.
ALLOWED_USER_IDS=7012345678
The same number that appeared in her terminal, in step 2. Only she receives responses.
Stuck here? That's normalDidn’t the terminal show any number? Check three things: you sent /start in a private chat with the bot, not in a group; the token in the .env is the one for the correct bot; the identification mode was still running when you sent it.
Practice now 0/4
Ready once the ALLOWED_USER_IDS line in the .env has your number, not the example’s. About 8 minutes, at the computer, with your phone in hand.
The identification mode doesn’t respond or run anything: it only displays the number in the terminal. Did you see "Configure TELEGRAM_BOT_TOKEN in your private .env"? The token isn’t in the .env yet: do lesson 2 of this module (lesson 38), which creates that file in the projects/oswork-kit/bot folder.
cd ~/projetos/oswork-kit/bot python3 --version
The kit bot is written in Python and needs version 3.10 or newer. If you see "command not found" or a smaller number, Python needs an installation from the official source before you continue: python.org/downloads shows the version for Windows and Mac. On Linux, Python 3 usually comes with the system.
You decided, by number, who your bot serves.
Lesson cheat sheet
The kit bot only accepts private chats and configured IDs. It also accepts only known commands. Verifying the ID is different from checking the visible name: names can change. A message from an unknown user should not trigger file reads or system commands.
A bot found on the internet may receive unexpected messages. Program authentication with a token does not mean authorization for anyone who talks to it. These are separate controls.
Numeric ID; access list; private chat; fixed commands.
The owner writes /relatorio and receives fake totals. A user outside the list doesn’t get data. Even the owner can’t write a command for a shell and expect the bot to run it.
Lesson 39 · OSWork v6.2 · INEMA.CLUB PRO
Module 7 · Lesson 4 of 6

You can turn on the bot with long polling, get /status and /relatorio on your phone, and check the total with the kit’s sales file.
There are two ways for a bot to receive messages, and mixing the two creates errors that are hard to understand. Starting with the simplest one lets you test everything on your computer, without opening any door for the internet.
In 1 minute
With long polling, the program asks the Telegram if a new message arrived. If nothing arrived, it waits until 25 seconds and asks again.
It’s like walking past the mailboxes in the teachers’ room and hanging around for a moment, in case a note arrives. The webhook would be the mail carrier ringing the doorbell—and it requires your address on the internet.
Lúcia left the bot running on the notebook at home. No need to touch any network settings: the program goes out to fetch, and nobody needs to enter.
The program goes to Telegram to fetch the messages.
It works on your computer, without a public address.
Telegram calls your address on the internet.
It requires that public address. It isn’t used in this module.
In the terminal, in the bot folder, run python3 bot.py. Nothing shows up, and that’s the right sign: the program is waiting.
The terminal needs to stay open. If you close the window or press Ctrl+C, the bot stops responding.
Denise found the screen frozen and almost closed the terminal. Lúcia explained: a screen with no new line means the bot is working; a new line usually means a notice.
$ python3 bot.py
^C
Bot encerrado.The empty space is the bot waiting for messages: the cursor stays still until you press Ctrl+C.
With the bot running, send /status and /relatorio in the private chat. The /relatorio response includes the sum of the fake sales.
Check that sum in the file itself, vendas.csv, a spreadsheet in CSV. A total that matches the file is a verified result, not an impression.
Lúcia added on paper: notebook 35.50, pen 9.50, and planner 55.00. She had 100.00, the same number as the bot.
Lúcia/status
BotOSWork active. Restricted access. Deterministic training bot.
Lúcia/relatorio
BotFictional training data: 3 sales; total R$ 100.00. No AI call.
Three sales, R$ 100.00: the program writes with a dot, but it’s the same R$ 100.00 from the sum of the file below.
$ cat vendas.csv
produto,valor
Caderno,35.50
Caneta,9.50
Agenda,55.0035.50 + 9.50 + 55.00 = 100.00. The file has no secret at all; you can open it freely.
Keep one single program fetching messages for each bot. Two at the same time, with the same bot token, they compete for messages, and Telegram refuses.
The kit detects the conflict and turns itself off. The warning comes out in the log, which appears in the terminal itself, without showing the token.
Lúcia turned on the bot at home, forgetting it was still on the school notebook. The one at home stopped with the warning below. The next day, she turned off the school one with Ctrl+C and turned the home one back on.
2026-09-25 19:40:12,381 WARNING Falha HTTP 409 no Telegram; sem detalhes que exponham token.
2026-09-25 19:40:12,382 ERROR Confira token, instância duplicada ou webhook; processo encerrado para diagnóstico.409 means conflict. Almost always it’s another copy of the bot that’s also running. The “webhook” of the warning only applies to older bots, configured differently; yours, new one, doesn’t have it.
Stuck here? That’s normalDid you see the 409 and don’t know where the other program is? Look for another terminal window that’s open or another computer where you turned the bot on. Turn them all off with Ctrl+C and turn on only one.
Practice now 0/4
Done when the /relatorio shows the same total as your sum and, with the bot turned off, the /status returns no response. About 10 minutes, on the computer and on the phone.
The bot only reads the vendas.csv file, with fake data, and it doesn’t change anything on the computer. Did you see “HTTP Failure 401”? The token for the .env is wrong or was revoked: redo the token step in lesson 2 of this module (lesson 38). No response on the phone? Check your numeric ID in the access list, like in lesson 3 of this module (lesson 39).
cd ~/projetos/oswork-kit/bot cat vendas.csv
You turned on your own bot, talked with it on your phone, and checked the response against the file.
Lesson cheat sheet
Long polling is the program asking Telegram for messages and waiting a bit when there’s nothing new. It’s simple to learn and doesn’t require opening an incoming port. Webhook is another strategy, where Telegram calls your HTTPS address; it’s not needed in this lab.
Choosing a single mode reduces configuration problems. Keep only one instance fetching messages for a bot: duplicate processes can compete for updates.
getUpdates; offset; timeout; single instance; outbound access.
The process waits up to 25 seconds for a message. Upon receiving it, it updates the offset to avoid repeating the same query. After a network failure, it waits before trying again.
Start with python3 bot.py. Use Ctrl+C to terminate. If a conflict arises, check whether another process is using the same token or if a webhook is configured.
Mix the training copy with private files or production work.
Lesson 40 · OSWork v6.2 · INEMA.CLUB PRO
Module 7 · Lesson 5 of 6

You can write an integration contract in five lines and test it in the chat to see that the summary made by the AI doesn’t change the calculated total.
Connecting an AI to a bot feels like the natural next step, but every connection opens a new path for error and cost. A predictable bot is already useful. The AI only comes in where it improves something you can measure.
In 1 minute
The kit separates on purpose the path of messages, which is the Telegram, from the work functions. And it starts without AI: status and data reports with fake numbers.
A predictable bot you can test without spending anything. Only then is it worth asking whether the AI improves interpretation, the summary, or the classification.
Denise wanted a question-answer bot for the office/secretary "with AI from the start". The plan changed: first a /schedule that only reads the spreadsheet; the AI would come in a second stage, with testing.
The new bot already calls an AI for everything.
When it gets it wrong, nobody knows whether it was the program or the AI.
Stage 1: bot without AI, tested with /status and /relatorio.
Stage 2: one function with AI, compared with the result from stage 1.
Net gain: one error at a time to investigate.
On the grade report, the grade comes from the calculation, and the written feedback comments. The written feedback never changes the grade.
With the bot, it’s the same. The AI can write a summary, but the total comes from the program and can’t be changed in the text.
Lúcia imagined a /summary for the little shop of the student association. The AI would receive only the total and the three products, not her entire project folder.
YouData: 3 sales; total R$ 100,00; notebook R$ 35,50; pen R$ 9,50; planner R$ 55,00. Write a two-line summary.
AIThe sales added up to about R$ 110, with the planner standing out.
It invented a total that doesn’t exist. This text can’t go out through the bot.
YouUse only these data. Don’t change any number and don’t add data. Data: 3 sales; total R$ 100,00; notebook R$ 35,50; pen R$ 9,50; planner R$ 55,00. Write a two-line summary.
AIThere were 3 sales, with a total of R$ 100,00. The planner accounted for R$ 55,00, the biggest part.
The total is the one from the program, and no new data appeared.
Write the integration contract: the data sent, the available model, the cost limit, the maximum time, and what happens when the AI fails.
The last line is the most forgotten one. With it, the bot stays useful even when the AI doesn’t respond.
Denise wrote the /schedule contract in five minutes. On the failure line she wrote: "without AI, the bot sends the spreadsheet line as it is".
Test yourself
The /summary with AI is already working. One morning, the AI doesn’t respond. The contract says, on line 5: "if the AI fails, send only the total". What does the bot do?
Don’t hook up an agent to the Codex so it can act on the messages that come in through the bot. And don’t disable protections just so the integration works.
The AI receives a short input, assembled by the program, and returns text. Who decides what to do with that text is still the program.
Lúcia read in a forum the tip to connect Codex directly to the bot, "so it can do anything". She didn’t follow it: anything includes deleting her folder.
If you write in Telegram, you make the agent act on the computer.
A malicious sentence becomes an action.
The program builds the input: the total and three products.
The AI returns text; the program checks whether the total is what it calculated, and only then sends it.
Stuck here? That's normalYou won’t program the integration in this lesson: the kit doesn’t include that part, on purpose. The practice is to write the contract and test the number rule in the chat you already use.
Practice now 0/3
Done when the contract has the five lines and the chat summary keeps the total at R$ 100,00, with no new data. About 10 minutes, in the chat you already use and in the notepad.
The data are the kit’s fictional data, and nothing is sent to the bot. If the AI changes a number, that’s not your fault: it’s the risk the contract covers. Write down and reinforce the phrase "don’t change any number".
Use only this data. Don’t change any number and don’t add any data. Data: 3 sales; total R$ 100,00; notebook R$ 35,50; pen R$ 9,50; planner R$ 55,00. Task: write a two-line summary for <a equipe da lojinha do grêmio>. In the end, repeat the total exactly as it came.
1. Data sent: the total and the three products with value.
2. Template: whatever is available in my account.
3. Cost limit: up to R$ 2 per month.
4. Maximum time: 15 seconds.
5. If the AI fails: the bot sends only the /relatorio line, like today.
You define, before turning it on, what the AI receives, how much it costs, what it expects, and what happens if it fails.
Lesson cheat sheet
The kit deliberately separates transport and work functions. It starts deterministic: status and report of fake data. To attach AI, define a function with limited input, timeout, output ceiling, and review. Do not expose codex exec directly to public messages nor disable protections to make it work.
A predictable program lets you test the base without spending API. Then, you evaluate whether the AI improves interpretation, summary, or classification, and you measure the result against a known reference.
Domain function; limits; timeout; review; minimal data.
A summary function can receive only the total and three categories, instead of the entire directory of projects. The generated text never changes the total calculated by the program.
Write an integration contract: data sent, available model, cost limit, maximum time, and action when the AI fails. The base bot remains useful without this extension.
Lesson 41 · OSWork v6.2 · INEMA.CLUB PRO
Module 7 · Lesson 6 of 6

You can run the bot’s self-test and four real tests on Telegram, recording what was simulated and what was actually tested.
A correct answer doesn’t prove the bot is restricted, and it doesn’t prove it recovers from a failure. A few scenarios, tested on purpose, show that before the bot goes to a machine that stays on without you.
In 1 minute
The kit includes an self-test. The bot runs fake-message tests against its own rules, without a token and without internet.
It covers access, group, unknown command, the sum, and sales files with defects. But it doesn’t prove that your bot talks to the Telegram.
Denise asked whether Lúcia’s bot obeyed strangers. Lúcia showed the final line of the self-test and noted that the real test was still missing, with a person outside the list.
$ python3 bot.py --self-test
OK: 11 cenários offline — acesso, grupo, comando, soma e arquivos inválidos.One line only, starting with OK. If a long error shows up, some scenario failed.
It’s like testing the sound before the parent-teacher meeting: you test the microphone with an empty room. Four real tests are enough: your /status, any random sentence, a person outside the list, and the bot turned off. If the bot turned off still responds, there’s another copy running somewhere. If it stays silent, the one who used to respond was your computer program.
Write down each test in your notepad, with the source: simulated or Telegram. That way nobody confuses "passed the test" with "works on the phone." When you turn the bot back on, it may respond to the /status that was waiting; that’s expected.
Lúcia asked Denise to send /relatorio to the bot. Nothing came back, as expected. In the log, she wrote: "out of the list, Telegram, no response".
When something fails, the symptom tells you where to look. Don’t change the AI model: /status and /relatorio don’t use AI.
If only the /relatorio fails, the problem is in the sales file, the vendas.csv file, a spreadsheet in CSV. If nothing responds, check the program, the token, the internet, and the access list.
Denise saw Lúcia receive "Could not validate vendas.csv". Instead of blaming the AI, Lúcia opened the file: she had accidentally deleted the header row.
The bot says: "Could not validate vendas.csv. Check the local file; no total was invented."
Where to look: the sales file.
The bot says: nothing.
Where to look: is the program running? Is the token correct? Is there internet? Is your numeric ID in the access list? Read the terminal.
In a network failure, the bot tries again on its own. In a conflict (409) or with the wrong token (401), it shuts down for you to investigate. The log from the kit tells you the type of failure and the time. It does not show the bot token or the text of the messages.
In the same notepad record, write down each failure like this: what failed, when, and what you did. This is the record that goes with the bot to the VPS in module 8.
Lúcia turned off the wi-fi with the bot on, on purpose. The terminal showed retry warnings, and the bot restarted on its own when the network came back.
2026-09-25 20:05:31,114 WARNING Falha de rede ou resposta; nova tentativa em 2 segundos.
2026-09-25 20:05:33,120 WARNING Falha de rede ou resposta; nova tentativa em 4 segundos.
2026-09-25 20:05:37,131 WARNING Falha de rede ou resposta; nova tentativa em 8 segundos.Each attempt waits double the time of the previous one, up to 60 seconds. No line shows the token.
Stuck here? That's normalThere’s no one to send the message from outside the list? Write "not tested on Telegram" and continue: the auto test already covers this case in a simulated way. An honest record is worth more than a complete made-up one.
Practice now 0/4
You’re ready when the record includes the auto test and the tests on Telegram, each marked as simulated or Telegram. About 12 minutes, on the computer and on the phone.
The tests only read fake data; nothing is deleted. A person outside the list receives no data. Didn’t do lessons 2 to 4 of this module (38 to 40)? Run only the auto test: it works without a token, in the kit’s bot folder.
cd ~/projetos/oswork-kit/bot python3 bot.py --self-test > autoteste.txt cat autoteste.txt
Denise tested the consultation bot she set up to train:
Auto test · simulated · 11 approved scenarios
/status me · Telegram · "OSWork active…"
"good morning" · Telegram · "Unknown command…"
/relatorio of outside the list · not tested on Telegram · covered by the auto test
/status with the bot turned off · Telegram · no response
You tested the bot before you needed it, and you can say what was simulated and what was real.
Lesson cheat sheet
Test allowed sender, blocked sender, group, unknown command, and missing data. Logs must report failure type and time, without token or complete private messages. In the lab, turning off the process must stop the responses: that proves the local program is in the path.
A correct response does not prove the bot is restricted nor that it retrieves the network. A small set of scenarios demonstrates the important properties before migrating to a VPS.
Self‑test; network failure; logs without secrets; interruption; diagnosis.
If /status works and /relatorio fails, investigate the data file. If neither works, check the process, authentication, and connection. Do not change the model: these commands do not even use AI.
Run --self-test and save the output. Then test the real conversation with your account; differentiate in the log what was simulated and what was tested on Telegram.
Use fake files and a training folder. Practices with installation, Telegram, or a VPS may require extra time for signup and setup.
Read the block before using. Fields like Your Name and usuario@ip-da-vps are examples to adapt; administrative commands belong only to your training environment.
python3 bot.py --self-test
cp .env.example .env
chmod 600 .env
# Edit .env locally; never share values.
python3 bot.py --identify
# Fill ALLOWED_USER_IDS with your ID and stop identification.
python3 bot.pyRun a restricted query bot and understand where the AI comes in. Log the generated file, the test executed, and the observed result.
Use this rubric after the lab. Each line asks for evidence; checking reading does not mean the practice was performed.
Can a Telegram message be passed directly to the shell?
No. The bot must map allowed commands to defined functions and verify the sender.
If your answer was different, return to the corresponding topic and write the difference in one sentence. The check does not block your study.
Tools verified on 20/09/2026; screen names and availability may change.
Terms for this section: chmod, .env.example.
Lesson 42 · OSWork v6.2 · INEMA.CLUB PRO
Module 8 · Lesson 1 of 6

You can fill in the first part of the VPS plan: what needs to run, who takes care of it, how much it can cost, which system to use, and how to shut it down. Everything before you sign up for anything.
Signing up for a VPS takes a few minutes. Finding out later that nobody takes care of it, or that the bill arrives every month even when you don’t use it, costs a lot more. That’s why the plan comes before the purchase.
In 1 minute
Think of a rented room. The building owner gives you the room with electricity and a door. What happens inside is up to you.
A VPS works like this. It’s a rented virtual server, with memory, disk, and network, in a company called the VPS provider. Users, updates, and programs are your responsibility.
The bot from Denise’s training, from module 7, only replies while her notebook is on. At six in the afternoon she closes the lid, and the bot stops replying on Telegram.
When it runs: only with the lid open.
Who takes care of it: you, without noticing.
When it runs: all the time, with the VPS provider.
Who takes care of it: you, on purpose: users, updates, and programs.
Start with a small machine, compatible with the program you’re going to run. A bot that calls an AI model via the API doesn’t need an expensive video card.
The remote model runs on the AI provider’s computers. The VPS only sends the request and receives the response.
Lúcia almost hired a VPS with a video card for a bot that generates fake class averages. The bot only sends requests and displays responses; the video card would sit idle, and the bill would be high.
Choice: the strongest plan, with a video card, "to make sure".
Result: a high bill every month for a bot that barely works.
Choice: a small machine, with plenty of room to run the bot.
Result: the AI model stays with the AI provider; the VPS just acts as the bridge.
Net gain: the machine size follows the program, not the model’s fame.
The VPS, the extra disk space, and the AI API are charged separately. Signing up for one doesn’t pay the others.
The VPS monthly fee hits every month, with the machine working or sitting idle. It’s the same logic as the lesson about access and billing, in module 1: each access has its own account. Write down the limit of each one.
Denise made the list before talking to management. The VPS monthly fee went into one line. The training bot doesn’t use AI, so the API line says "doesn’t use".
A running machine doesn’t mean a healthy service. The bot can stop in there and nobody notices.
Before hiring, decide two things: what you need to run without stopping, and who will check when something goes wrong. Also write down the system: the course examples use Ubuntu.
Denise filled in the first part of the course kit operation plan. The line that took the longest was the last one: where the cancel button is and who can press it.
Test yourself
Denise will put the training bot on a VPS. What decision comes before choosing the plan?
Stuck here? That's normalYou don’t need to sign up for anything in this lesson, and you don’t need to know the exact price. Where a detail is missing, write "to be defined" and the name of the person who decides. The plan works like that already.
Practice now 0/3
Ready when the six lines have an answer, or "to be defined" with a name next to it. About 8 minutes, on your computer or phone.
Nothing is contracted in this lesson. Without the kit, copy the template into a note on your phone. Don’t write down a password or card details in the plan.
Where the plan is: the file plano-vps.md comes in the course kit, the oswork-kit.zip from the OSWork materials page. The plan has five parts: Before contracting, Access, Service, Observed checks, and Routine. Today you fill in the first one; the others come in the next lessons.
OPERATION PLAN · BEFORE CONTRACTING Work that needs to keep running without the notebook: <ex.: training bot responding to /status> Technical owner: <your name or the person who will take care of it> Monthly VPS budget: <maximum value per month> Separate budget for the API, if used: <value or "doesn't use it"> Supported operating system: <ex.: Ubuntu, supported version> Resource shutdown plan: <where to cancel and who can>
Work: bot that responds with the team’s fictitious average, outside lesson time.
Technical owner: Lúcia.
Monthly VPS budget: to be defined, with coordination.
API: doesn't use it.
System: Ubuntu, supported version.
Shutdown: VPS provider panel; Lúcia and coordination.
You just decided what the VPS needs to do, who is responsible for it, and how to close the account.
Lesson cheat sheet
A VPS is a rented virtual server: a remote computer with memory, disk, and network. You manage users, updates, and processes. Start with a small machine compatible with the application; don’t rent a GPU just to call a model via API. The remote model runs on the infrastructure of the provider.
A powered‑on machine does not mean a healthy service. VPS, storage, and API costs are separate. Before hiring, define what needs to run continuously and who will monitor incidents.
Remote server; resources; recurring cost; operational responsibility.
A small bot that queries fictitious data does not need the same infrastructure as a local model. The manager estimates load, budget, and availability before choosing the plan.
Fill out materiais/plano-vps.md. Record operating system, access method, monthly limit, responsible person, and how to shut down the resource.
Accepting a conclusion without checking the input that supports it.
Lesson 43 · OSWork v6.2 · INEMA.CLUB PRO
Module 8 · Lesson 2 of 6

Can you tell which machine you’re on by what the terminal shows and apply the rule from the second session: test the new input before closing the one that works.
When you change the lock on your house, you test the new key before throwing away the old one. The VPS is the same. Changing the network or the way you enter without a return route can lock you out.
In 1 minute
SSH creates a protected connection to manage the machine. The command ssh usuario@ip-da-vps opens the session.
The parts usuario and ip-da-vps are fields to replace, not real values. The VPS address appears on the VPS provider panel.
Lúcia opened two terminal windows and got confused: in one was the notebook, and in the other was the VPS. The name at the beginning of the line and the command pwd showed where she was.
$ ssh usuario@ip-da-vps
usuario@nome-da-vps:~$ pwd
/home/usuario
After signing in, the start of the line changes: now it shows the user and the VPS name. The pwd command tells you the folder you’re in.
Use the public key registered exactly the way the VPS provider indicates. The private key never leaves your computer. When you sign up, the provider panel guides the creation and registration; in this lesson, you don’t need to create anything.
On the first connection, SSH shows the fingerprint of the machine. It confirms that you reached the correct VPS.
Denise got the question in English on the first entry. Before typing yes, she compared the fingerprint with the one shown in the provider panel.
$ ssh usuario@ip-da-vps
The authenticity of host 'ip-da-vps' can't be established.
ED25519 key fingerprint is SHA256:[impressão digital].
Are you sure you want to continue connecting (yes/no/[fingerprint])?
In Portuguese: "you can't confirm this machine's identity; this is the fingerprint; do you want to continue?" Reply yes only if it matches.
Work with your own user, the work user. When a task asks for administrator permission, put sudo in front of the command.
That way, admin privileges only appear where you asked, and they stay visible in the command.
Lúcia checked her own user before touching anything. The same command with sudo showed the admin, after asking for her password.
$ whoami
usuario
$ sudo whoami
[sudo] password for usuario:
root
whoami replies "who am I". Without sudo, it’s the work user; with sudo, it’s root, the machine administrator.
Before changing the network or the way you sign in, leave the original session open. Open another window and test the new sign-in. Only close the first one when the second works.
If everything fails, the recovery console still opens the machine. Confirm it works before restricting anything.
A tutorial suggested that Denise change the port of SSH. That’s a common change in security guides. Before following it, she opened the console from the provider panel and noted on the plan that it worked.
Status: open, working.
Rule: don't close until session 2 signs in.
Status: another window, testing the change.
Rule: signed in? Then you can close session 1.
Emergency exit: the provider console, checked before any change.
Stuck here? That's normalYou don't need a VPS for this lesson. The practice is a case to analyze on paper. When you rent yours, come back to this step and follow the three routes in order.
Practice now 0/3
Ready when you’ve answered the three questions and checked the answer key. About 8 minutes; write it down on paper or in your notepad.
It’s a case with no real machine, so nothing breaks. Do you have a training VPS? Also do the real test: with the session open, open another window and sign in again using the same ssh command. Don’t change the port or the way you enter just to practice.
The case. Rogério, Denise’s colleague, rented a training VPS. He logged in via SSH and pasted an internet command that changes the SSH port. He ran it and closed the terminal right away. When he came back, ssh rogerio@ip-da-vps no longer connects. He never opened the provider console.
You’ve just found the mistake that locks a person out of their own VPS, and the way back.
Lesson cheat sheet
SSH creates a protected connection to administer the machine. Use the registered public key as instructed by the provider and verify the identity of the server. Create a work user with administrative permissions when necessary. Keep the original session open while you test a second connection.
Changing firewall or authentication without testing a recovery route can block your own access. The provider console is the alternative when the normal connection fails; make sure it works before restricting the network.
Public key; fingerprint; user; sudo; recovery.
The command ssh usuario@ip-da-vps opens the session. usuario and ip-da-vps are placeholders to replace, not real values. The prompt name and pwd help confirm which machine you are on.
Test the second session before closing the first. Don’t disable login or change the SSH port using a command if you don’t know how to recover access.
Lesson 44 · OSWork v6.2 · INEMA.CLUB PRO
Module 8 · Lesson 3 of 6

You can check in the terminal if Python 3 and Git are on your machine and create the projects folder, without putting anything else in it.
Every extra program is another thing to update, explain, and fix. Getting tools used to automatically is work and doesn’t increase what the service can do.
In 1 minute
The examples use Ubuntu with apt. First, sudo apt update updates the list of what exists on the machine. Then, sudo apt upgrade proposes the updates and waits for your response.
Having sudo in front asks for administrator permission, like in the previous lesson.
On the training VPS, Denise paused at the final question and read the entire list. Only then did she answer Y.
$ sudo apt update
Reading package lists... Done
$ sudo apt upgrade
The following packages will be upgraded:
[lista de programas que vão mudar]
Do you want to continue? [Y/n]
The final question means “want to continue?”. The uppercase Y is the default answer. Read the list above it before you answer.
The bot from the course kit needs Python 3. Git helps you move the project from your computer to the VPS. The command is sudo apt install git python3.
The bot uses only what already comes with Python, with no extra add-ons. Other tools, like Codex, are optional: they only get used if the program asks for them.
A tutorial suggested that Lúcia install five tools “to make sure”. She checked what the bot was asking for and ended up with two.
On the machine: Git, Python 3, and three more tools "because one day you might need them."
Result: five things to update; three you don't use.
On the machine: Git and Python 3.
Result: two things to update, and both work.
Net gain: three fewer tools to maintain, without losing anything the bot does.
Ask for the version of each program. If it answers, it's on the machine. Then create the projetos folder in your personal folder, in your work account.
The version commands only read. The one that creates a folder doesn't delete anything: if the folder already exists, it leaves it as-is.
Lúcia ran the same commands on the notebook, before renting any VPS. Both answered. She wrote the versions on the plan, to confirm the same ones on the VPS.
$ python3 --version
Python 3.x.y
$ git --version
git version 2.x.y
$ mkdir -p ~/projetos
$ ls -d ~/projetos
/home/usuario/projetos
Where it says x.y, the version number of your machine appears. The last command confirms that the folder exists.
Stuck here? That's normalIf you see "command not found", or on a Mac a window offering command-line tools, the program isn't on the machine. This isn't your fault. Write "missing" on the plan: that's exactly what the VPS needs to receive. On Windows, run this in the WSL terminal, from module 3.
Practice now 0/3
Done when you have the answers from the two version commands and the projects folder exists. About 8 minutes, on your computer, in the terminal.
None of the commands here changes the system: two only read the version, the other creates an empty folder. Don't run the apt update on your work computer just to practice. On Windows, use the WSL terminal, set up in module 3: in PowerShell these commands respond differently. Do you have a practice VPS? Run the same commands on it.
python3 --version git --version mkdir -p ~/projetos ls -d ~/projetos
You just checked what the machine has and decided what it needs, without adding anything out of habit.
Lesson cheat sheet
The lab examples use Ubuntu with apt. Update the package list and review the proposed upgrade. The base bot requires Python 3; Git helps transfer the project. Node, Docker, and Codex are optional depending on the application, not a mandatory list for any VPS.
Each dependency adds maintenance. A simple service with few components is easier to explain, update, and recover. Installing tools out of habit creates work without increasing the needed capacity.
apt update; apt upgrade; dependency; virtual environment when needed.
Reference sequence: sudo apt update, sudo apt upgrade, sudo apt install git python3. The kit bot uses only the standard library, without installing external Python packages.
Lesson 45 · OSWork v6.2 · INEMA.CLUB PRO
Module 8 · Lesson 4 of 6

You can list the network ports that your VPS needs to open. And you can keep a .env readable only by you, checking it in the terminal.
Opening everything “to work” increases the risk and doesn’t find the cause of the problem. And a .env that any user of the machine can read keeps the bot password in plain sight.
In 1 minute
The firewall filters network connections, in both directions. It’s like the school gate: there’s a list of who can enter, and the mail carrier goes out to pick up the correspondence.
The bot from the kit uses long polling. It leaves through a secure connection to ask the Telegram if there’s a new message. Nobody from outside needs to knock on its door.
Lúcia thought she needed to open a port for the bot to receive messages from the class. She didn’t: whoever enters the machine is only you, through SSH.
On Ubuntu, the ufw configures the firewall. Before turning it on, allow the port of SSH that your VPS actually uses. If it’s 22, the rule is the one from the example. If it’s another number, it changes.
Some providers have their own firewall in the dashboard. If yours does, check there as well that the SSH port is open.
Denise only turned on the firewall after setting up the return routes from the previous lesson about SSH: the second tested session and the provider console checked. Even ufw warned her about the risk.
$ sudo ufw allow 22/tcp
Rules updated
Rules updated (v6)
$ sudo ufw enable
Command may disrupt existing ssh connections. Proceed with operation (y|n)?
"Rules updated" confirms the rule. The final question warns: "this can drop the open SSH connections; continue?".
And the bot token lives in .env. The command chmod 600 makes that file readable only by the owner.
And .env never goes into Git: the .gitignore file from module 4 already takes care of it.
Lúcia checked the .env before and after chmod. At the start of the line, the dashes show who can’t read it.
$ ls -l .env
-rw-rw-r-- 1 usuario usuario 0 [data] .env
$ chmod 600 .env
$ ls -l .env
-rw------- 1 usuario usuario 0 [data] .env
After the first character come three sets: owner, group, and others. r means read, w means modify, a dash means "cannot". Earlier, the group and others could read (rw- and r--). After that, only the owner has rw.
If the bot doesn’t respond, don’t open ports just to see if it fixes things. Split it into three questions: is the process running? Was the token accepted? Does the outbound network work?
The bot’s log from the kit helps you separate things, without exposing the token.
Denise’s bot stopped. The log said "HTTP Failure 401": it was the token, swapped the week before. No port needed to change.
Stuck here? That's normalNo VPS and no bot running? No problem. The practice is on your computer, in a training folder, with an empty .env. ufw is for when you have the machine.
Practice now 0/3
Ready when the ls -l shows -rw------- in the treino .env and the plan has the needed ports. About 8 minutes, on your computer, in the terminal.
The file is created empty, in a new folder, just to practice: there’s no token in it. Don’t touch the .env of a bot that already works. On Windows, run it in the WSL, from module 3: outside it, -rw------- might not show; that’s not your fault, go back to WSL. If chmod gives an error, check with pwd to see if you’re in the treino-rede folder.
mkdir -p ~/treino-rede cd ~/treino-rede touch .env ls -l .env chmod 600 .env ls -l .env
You just closed a secrets file so only you can read it, and reduced the door count to the minimum.
Lesson cheat sheet
The firewall filters network connections. For long polling, the bot needs to go out to HTTPS; you don’t need to expose a bot port to the internet. Before activating UFW, allow the actually used SSH port and check local rules and the provider rules. Restrict the .env with chmod 600 and keep it out of Git.
Opening all ports to “make it work” increases risk without diagnosing the cause. If the process does not respond, outbound network, token, and execution each deserve separate checks.
Input and output; SSH port; firewall rule; file permissions.
If SSH uses port 22, sudo ufw allow 22/tcp may be appropriate. If it uses another port, the rule needs to change. Only run sudo ufw enable after testing the configuration and the recovery access.
List ports actually needed in the plan. Record which commands vary by provider and never treat the port example as universal.
Mix the training copy with private files or production work.
Lesson 46 · OSWork v6.2 · INEMA.CLUB PRO
Module 8 · Lesson 5 of 6

You can adapt the four kit unit fields and read, in the status and in the log, whether the bot is running.
A bot running in an SSH session can stop when you close the connection. The supervision starts the bot along with the machine and stores the records in one place. It doesn’t replace alerts, limits, or the search for the cause.
In 1 minute
Up to here, you started the bot manually, with python3 bot.py in the terminal. On the VPS, that ties the bot to your connection.
The systemd is the machine’s caretaker: it turns the lights on every morning, restarts what went off, and writes everything down in the incident book.
Denise left the bot running in an SSH session and went home. The connection dropped along the way, and the bot stopped too.
Turn on: when you type the command.
If the connection drops: the bot can stop along with it.
Record: stored with the window.
Turn on: by itself, together with the machine.
If the bot fails: restart after 15 seconds.
Record: saved by systemd, so you can read it later.
Net gain: the bot stops depending on your opened window.
The unit in the kit is the file oswork-bot.service, in the bot folder. Four fields need your user and your path: User, WorkingDirectory, EnvironmentFile (where the .env is) and ExecStart.
The Restart=on-failure field restarts the bot after a failure. In the kit, the example user is oswork; the user and the folders need to exist on the VPS.
Lúcia replaced oswork with her own work user in the four fields. Then she showed only those lines on the screen to check.
$ grep -E "^(User|WorkingDirectory|EnvironmentFile|ExecStart|Restart)=" oswork-bot.service
User=oswork
WorkingDirectory=/home/oswork/projetos/oswork/materiais/bot
EnvironmentFile=/home/oswork/projetos/oswork/materiais/bot/.env
ExecStart=/usr/bin/python3 /home/oswork/projetos/oswork/materiais/bot/bot.py
Restart=on-failure
That’s how the kit comes. The first four lines are the ones you adapt; you keep the last one.
On the VPS, the adapted unit goes to the systemd folder, /etc/systemd/system, with administrator permission. Then, three commands start the bot. The systemctl reads the units, starts the bot, and shows its status.
The sudo appears in the first two because they change the machine. The third one only reads.
Denise saw "active (running)" in the status. Even so, it only marked the step as completed after sending /status in the Telegram and receiving the response.
$ sudo cp oswork-bot.service /etc/systemd/system/
$ sudo systemctl daemon-reload
$ sudo systemctl enable --now oswork-bot
$ systemctl status oswork-bot --no-pager
● oswork-bot.service - OSWork bot de treino restrito
Active: active (running) since [data e hora]
The first line copies the unit. The daemon-reload makes systemd reload the units. "active (running)" means "active, running". The enable --now turns it on now and keeps it on for the next reboots.
You/status
BotOSWork active. Restricted access. Deterministic training bot.
The bot's real response to /status from the kit.
Do a purposeful restart, with systemctl restart, and send /status again. Write down the time. Then read the log with the journalctl.
Restarting doesn’t fix an error that keeps happening. If the bot goes down again, stop the service and look for the cause before insisting.
In the log, Lúcia saw the bot stopping and coming back, with the time. On another day, she saw "process ended for diagnosis" and stopped the service before trying again.
$ sudo systemctl restart oswork-bot
$ journalctl -u oswork-bot -n 50 --no-pager
[data] nome-da-vps systemd[1]: Stopped oswork-bot.service - OSWork bot de treino restrito.
[data] nome-da-vps systemd[1]: Started oswork-bot.service - OSWork bot de treino restrito.
Stopped and Started: it stopped and turned on, with date and time. With the bot running, it writes nothing else.
Stuck here? That's normalThe steps 3 and 4 need a VPS with the bot. Without it, this lesson’s practice is only the unit, on your computer. Save the commands: they’ll be in the plan when the machine exists.
Practice now 0/3
Done when grep shows your user and your path in the four fields. About 10 minutes, on your computer, with a text editor and the terminal.
You edit a text file, without turning anything on: no VPS, nothing runs. Work on a decompressed copy of the kit. Made a mistake? Decompress again. On Windows, do everything in the terminal of the WSL, from module 3.
Where the unit is: in the course kit, the oswork-kit.zip from the OSWork materials page. Decompress into ~/projetos/oswork-kit: the unit is in ~/projetos/oswork-kit/bot. On Windows, the zip downloads into the Downloads folder; in WSL, bring it with cp /mnt/c/Users/SeuNome/Downloads/oswork-kit.zip ~/projetos/, then cd ~/projetos and unzip oswork-kit.zip -d oswork-kit. The path that comes in the kit is the course repository path; replace it with the place where the bot will live on the VPS. In the template it’s /home as well, also on Mac: it’s the VPS path.
Paste into the file, in place of the four lines from the kit:
User=<your work username> WorkingDirectory=/home/<username>/projetos/oswork-kit/bot EnvironmentFile=/home/<username>/projetos/oswork-kit/bot/.env ExecStart=/usr/bin/python3 /home/<username>/projetos/oswork-kit/bot/bot.py
Run in the terminal, to verify:
cd ~/projetos/oswork-kit/bot grep -E "^(User|WorkingDirectory|EnvironmentFile|ExecStart)=" oswork-bot.service
User=denise
WorkingDirectory=/home/denise/projetos/oswork-kit/bot
EnvironmentFile=/home/denise/projetos/oswork-kit/bot/.env
ExecStart=/usr/bin/python3 /home/denise/projetos/oswork-kit/bot/bot.py
You just prepared the instruction that keeps the bot running without depending on your window.
Lesson cheat sheet
systemd is the service manager for many Linux distributions. A unit describes which program to start, with which user and in which directory. Restart=on-failure restarts after a failure, but does not fix a persistent error. The kit provides a parametrized unit for the oswork user.
Running the bot in an SSH session can end the work when you close the connection. Supervision lets it restart with the machine and centralizes logs. It doesn't replace alerts, limits, or analysis of the cause.
Unit; service user; directory; restart; journal.
After adapting paths, use sudo systemctl daemon-reload and sudo systemctl enable --now oswork-bot. Check systemctl status and journalctl -u oswork-bot -n 50 --no-pager.
Perform a controlled restart with systemctl restart, check /status and log the time. If it fails, stop the service before repeatedly trying without diagnosis.
Lesson 47 · OSWork v6.2 · INEMA.CLUB PRO
Module 8 · Lesson 6 of 6

Can you make a backup of sales.csv, the data file for the training bot? Then, restore the copy into a separate folder and prove, with a command and the total, that it’s complete.
Without anyone watching, a service can sit idle for days. Without a restore test, the copy may be incomplete, and you only find out on the day you need it. The real promise is a routine that recovers—not a machine that never fails.
In 1 minute
systemd restarts the bot, but it won’t tell anyone if it stays silent. That’s why there’s the external check: someone, outside the VPS, confirms whether the service responds.
A simple daily check records two things: whether the bot replied and how much disk space is left. On the VPS, the command df -h / shows the space used.
Denise sends /status from her phone every morning, before the eight o’clock meeting. She notes the response time and, once a week, the disk space.
Keep data copies outside the VPS: for example, a protected folder in the school’s Drive or an external disk. If the machine disappears, the copy can’t go with it. Also set retention: for how long each copy stays stored.
The .env file with the bot token is kept private. It doesn’t go into a copy that other people can access.
Lúcia kept the class data copy on the same VPS. She started keeping it in a protected place, outside of it, with three monthly copies. The .env was left out.
Where: a folder next to the bot.
If the machine disappears: the copy disappears too.
Secret: the .env was included in the copy.
Where: an external, protected place.
If the machine disappears: the data comes back.
Secret: the .env handled separately; three-month retention written in the plan.
Net gain: losing the VPS stops being losing the data.
A fire drill simulation proves the school leaves the building. The restore test proves the copy comes back. A backup is only validated when you restored it and checked the contents.
The training bot for module 7 adds up the values of vendas.csv, a file of fictitious sales, when it receives /relatorio. The monthly test restores that file into a separate folder and compares it with the original. The diff shows the differences; if it shows nothing, the two are identical.
In the first test, Denise’s copy was empty: the copy command pointed to the wrong folder. The rehearsal caught the mistake before any real loss.
$ cp ~/copias-oswork/vendas-copia-1.csv ~/restauracao-teste/vendas.csv
$ diff vendas.csv ~/restauracao-teste/vendas.csv
$ cat ~/restauracao-teste/vendas.csv
produto,valor
Caderno,35.50
Caneta,9.50
Agenda,55.00
The diff showed nothing: the copy is the same as the original. Add up the values: 100.00, the same total the bot’s /relatorio shows.
Stuck here? That's normal The diff’s silence makes it seem like “nothing happened.” It’s the opposite: it only speaks up when it finds a difference. If you see "No such file or directory", the folder or the copy name is different; check with ls.
The course project ends with five pieces of evidence: authorized response, block of the unknown, restart, log without a token and restoration verified.
Without a second Telegram account, the unknown block can be proven by the kit test, python3 bot.py --self-test. For the log without a token, read the journalctl and confirm the token doesn’t appear. If any step wasn’t executed, declare it. Writing “I didn’t do it” counts more than a “done” that nobody checked.
Denise still hadn’t rented the VPS. She recorded the evidence she could in her notebook and wrote, on the restart line, “not executed: no VPS”.
Practice now 0/3
Ready when the diff shows nothing and the total of the restored copy is 100.00. About 10 minutes, on your computer, in the terminal.
You only copy a file of fictional data; nothing is deleted. Here the copy stays on your computer; in a real VPS, it would go outside the machine. In Windows, use the terminal of the WSL, from module 3: in PowerShell, the diff responds differently.
Where the file is: vendas.csv comes in the bot folder of the course kit, the oswork-kit.zip from the OSWork materials page. The lines below assume the kit was extracted into ~/projetos/oswork-kit, as in the previous lesson; if it’s in another place, change only the first line. The terminal needs to respond with vendas.csv when you run ls.
cd ~/projetos/oswork-kit/bot ls vendas.csv mkdir -p ~/copias-oswork ~/restauracao-teste cp vendas.csv ~/copias-oswork/vendas-copia-1.csv cp ~/copias-oswork/vendas-copia-1.csv ~/restauracao-teste/vendas.csv diff vendas.csv ~/restauracao-teste/vendas.csv cat ~/restauracao-teste/vendas.csv
You just proved it—no guessing—that your copy comes back whole.
Lesson cheat sheet
Continuous operation combines supervision, updating, monitoring, backups, and tested restoration. Make copies of data outside the machine, protect credentials, and set retention. A backup is only validated when you restore a copy and verify its contents.
Without monitoring, a service can stay down for days. Without restoration testing, the copy may be incomplete. The real promise is a recoverable routine, not an infallible machine.
External check; logs; backup outside the VPS; restoration; spending limit.
A daily check records the bot’s response and disk space. A monthly test restores sales.csv in a separate folder and compares the total. Credentials follow private handling, without entering the public backup.
Finish the project with five pieces of evidence: authorized response, blocking of unknown, restart, log without token, and verified restoration. Declare any step not performed.
Use fake files and a training folder. Practices with installation, Telegram, or a VPS may require extra time for signup and setup.
Read the block before using. Fields like Your Name and usuario@ip-da-vps are examples to adapt; administrative commands belong only to your training environment.
sudo apt update
sudo apt upgrade
sudo apt install git python3
# Adapt the kit unit to the real user and path.
sudo systemctl daemon-reload
sudo systemctl enable --now oswork-bot
systemctl status oswork-bot --no-pager
journalctl -u oswork-bot -n 50 --no-pagerPrepare a deployment plan, supervision, backup and service verification. Record the generated file, the executed test and the observed result.
Use this rubric after the lab. Each line asks for evidence; checking reading does not mean the practice was performed.
Install Codex on a VPS ensures an active 24/7 agent?
No. You need a service or scheduler, a supervised process, valid credentials, network and monitoring.
If your answer was different, return to the corresponding topic and write the difference in one sentence. The check does not block your study.
Tools verified on 20/09/2026; screen names and availability may change.
Terms for this section: systemctl, journalctl, path.
Lesson 48 · OSWork v6.2 · INEMA.CLUB PRO