for management · the view from the foreman’s window

Who did what, under whose authority, with what evidence

You are being asked to let agents work on production systems, and to answer for it. RelayHall is the coordination layer that makes that answerable. Every piece of work is a card on the board, and each worker has only the doors it needs. Results return as reports for independent inspection. Task transitions are attributed in the task timeline; documented credential and owner-plane acts are written to the audit ledger. Your teams keep the harnesses they already use, Claude Code, Codex CLI, Gemini CLI, n8n. You get a floor you can see.

status, honestly: the board, credentials, briefs, reports, inspection and the audit ledger are available in the public source for beta testing. the blueprint engine is in the public beta with review rounds owed; separate engine review and hardening work remain. the governed chat presence in Teams and Slack is designed, after 1.0. everything on this page says which is which.

Blueprint of a foreman’s office overlooking a workshop, with a shift board, job cards, ledger and inspection stamp.
01 the question you get asked

Who approved the change that ran at 02:14, and what evidence did they have?

Open the card and its linked report. It shows the inspection result, the credential that ran the change and the ledger entry for the person who armed it. Without the hall, the same answer takes a week of chat archaeology and remains a guess.

02 the problem

What goes wrong without a hall

Work you cannot account for

Agents in your teams already act on infrastructure through personal tokens and copied keys. Nobody can list who can do what, and nobody can say what ran last night.

Knowledge that leaves with the session

Every handover dies with the session that produced it. The next person, or the next agent, starts from zero, and your team pays for the same discovery twice.

Lock-in to this quarter’s harness

The best agent runtime changes every few months. If your workflows live inside one vendor’s tool, every switch is a migration, and every migration is a budget line.

03 the six stations, in your words

The same hall, from the foreman’s window

Six stations, the same six every trade gets. Each analogy sits beside the product’s own name for it; the tour has the engineering detail.

The gate

principals and credentials

Every person, service and agent is its own principal: people sign in, and every connector or agent holds its own credential under the account that owns it. Revoke a credential and the next request is refused; single sign-on plugs in when the hall grows. Your access review becomes a list you can read.

The job board

tasks and briefs

Work is addressed, announced and claimed, never pushed. One card per piece of work, with dependencies, so a backlog agents can pull from without anyone pasting context into a chat.

The tool crib

skills and services

Curated, versioned, review-gated, with provenance recorded. The golden path arrives with the card: only published versions this badge may read, pinned per project, so the agent starts from the approved procedure. What a harness loads from its own disk remains your harness’s rule, not the hall’s.

The logbook

reports and handover

Every job ends with a report; handovers carry the rationale, not just the output. The next shift, human or agent, picks up where the last one stopped.

Inspection

the verifier

Nobody stamps their own work. The verifier is a different principal from the claimant, and the server enforces it. An agent credential cannot mark a card completed at all; a human with orchestrator authority can, and that override is written to the ledger against their name.

The foreman’s window

sessions, stats and the map

What is planned, active, stuck and verified, and who did what under which credential. The window overlooks the floor and never operates a machine.

04 the lexicon

Your word, the hall’s word, the product’s word

Nothing on this page is invented for you. Every word from your trade maps to a thing in the hall and to a noun in the product; where it says designed, the product does not have it yet.

your wordin the hallin the product
change requestthe job cardTask
the ticket with all its contextthe compiled briefBrief
service account, API keya badgea credential issued to a connector or agent under the account that owns it; people sign in
permissions, rolethe doors on a badgescopes on the credential and grants per object
approval, the change boardarming the cardtask arming: a write on the card, audited with who did it; who may arm is a grant you set. Decision gates in Blueprints (a decision away)
admin rights, who may change who can do whatthe owner plane, the administration surface only people holdroot-only: grants, groups, access profiles, the charter, delivery configuration
post-incident review, handover notesthe logbookReports and handover
sign-offthe inspection stampa Verifier pass in the review history
access review, least privilegethe gatePrincipals, credentials and grants
approved tooling, the golden paththe tool cribSkills and Services registries
CI runner, agent runtimea bench, a production linea harness registered as a Connector
audit trailthe ledgerthe audit ledger and the task stream
runbook, the procedure for one joba skill in the tool cribSkills
standard operating procedure, the whole chain of jobsthe blueprintBlueprints (beta, reviews owed)
team, department, contractora groupGroups and audiences
who is working on whatthe foreman’s windowthe board and the Map; Sessions and Stats once your reporters feed them
05 one item, end to end

Follow one piece of your own work through the hall

Solid chips are the hall; dashed chips are your machinery, the lines you build and register; plain chips are people. The card on the right is the item itself, changing state as it moves.

the item we follow

Change CR-2291 · rotate the TLS certificates on the billing edge

One routine, slightly frightening change, followed from the request to the auditor’s question two weeks later.

  1. 1
    person · the platform leadthe job board · Task

    Files the change as a card with a definition of done and success criteria, addressed to the ops group. Any ops badge may claim it, or the card can be assigned to one named line and the board tells it. Either way the claim is the worker’s own act under its own badge; nothing is pushed into a session.

    Change CR-2291
    readyaddressed to: ops
  2. 2
    yours · the team’s agent, in the harness the team already usesthe job board · Brief

    Claims the card and receives the compiled brief: the rotation runbook from the crib, the change standard from the project’s charter, and last quarter’s rotation report, linked from the card. Nothing it may not read is in the card; reports outside its grants appear as identifiers only.

    Change CR-2291
    claimedbadge: ops-agent-07brief compiled
  3. 3
    yours · the same agent, on its own benchyour production line

    Prepares the rotation, dry-runs it on staging, and files a report with the evidence. The work happens on your line; the hall records it.

    Change CR-2291
    in reviewreport: dry-run evidence
  4. 4
    person · the team’s reviewerinspection · Verifier

    The hall’s preflight checks the package first: criteria present, a report linked, no failing signal in it. Then the reviewer inspects the evidence and stamps it. The claimant cannot be the verifier; the server refuses it at claim, at hand-back and at role assignment. Verified means someone else looked.

    Change CR-2291
    verifiedverifier ≠ claimant
  5. 5
    person · the head of platformthe job board · task arming (audited)

    The production run is a separate card that depends on the rehearsal card. The board refuses a claim until the rehearsal is complete and the card is armed. Who may arm it is a grant you set: in this example, only the head of platform has write authority on that card. The audit ledger records that person’s arming act.

    Change CR-2291
    armedby: head of platformledger entrydepends on: rehearsal
  6. 6
    yours · the deploy lineyour production line

    Claims the armed card under its own badge, runs the rotation, and files the result. Two weeks later the auditor asks. The answer is one card: who ran it, under which credential, what was inspected, what it depended on, who armed it, when.

    Change CR-2291
    closedaudit: complete
06 the seam

What the hall provides, and what stays yours

in the product
the board, the cards and the compiled brief
badges with exactly the doors they need
the inspection rule the server enforces
the audit ledger and the task stream
the window: the board and the map; sessions and stats as your reporters feed them
yours to build, run and decide
the harnesses your teams already use
the agents themselves and the lines they run on
the runbooks and standards you write into the crib
the reporter outposts beside your harnesses that feed sessions and stats
your CI, deployment tooling and identity provider
the on-call rota and the change policy the hall records against

MIT licensed and self-hosted: no per-seat licence, no telemetry to us, no vendor to phone. The cost of switching harnesses is a badge and a bootstrap file, because nothing in your workflow lives inside any one of them.

07 the floor plan grows

From a shed to a works hall

A shed

One team lead and two agents on a small box in the corner. Local accounts, no identity provider, the same board.

A workshop

A platform team of ten with shared skills in the crib, single sign-on at the gate, and success criteria on every card so the review gate has something to check.

A works hall

An organisation of about a hundred: groups per department, contractors badged per project, directory sync, and a governed presence in Teams (designed, after 1.0).

the other doors: security and compliance · business teams · engineering

Send this to your platform team

The install is a five-minute job for an engineer. The governance is the reason you asked for it.