Ownership and guardrails
Declared paths, action grants, check, and the shared-checkout contract every crew carries.
Crew share one checkout. Nothing locks a file, so the whole safety story is declared ownership, action grants, and a contract every captain and crew carries in its instructions.
Declaring ownership#
--owns PATH records a path as belonging to one assignment. Repeat it per path. Overlapping active ownership between crew is refused, which is what keeps two simultaneous writers off the same file.
captain crew Gibbs --task "Rewrite the docs content" \
--owns src/content --owns src/app/docs --allow editAction grants#
read and search are always granted. Everything else is opt-in with --allow ACTION, repeated as needed.
| Action | Notes |
|---|---|
read | Always granted. |
search | Always granted. |
edit | Requires owned paths. |
test | |
build | |
format | Never repo-wide. Own files only. |
commit | Only when you explicitly asked for a commit. |
version | Only when you explicitly asked for a bump. |
delete | Requires owned paths. |
Checking a grant#
check answers whether an action on given paths is permitted. It executes nothing — it is a question, not a gate in front of a tool.
captain check Jack edit src/example.py{"assignment_id": "fb7fd383...", "allowed": true}A mutation action is refused when the assignment declares no owned paths covering them. Protocol commands validate themselves, so only filesystem and work actions need a check.
The shared-checkout contract#
Both captain and crew instructions carry the same rules, because a shared checkout fails in the same way from either side.
- Edit only files in your own assignment. Give simultaneous writers disjoint files, and serialise same-file work.
- Re-read a file right before editing it, and keep others' unexpected changes in place.
- Stage and commit only your own files and hunks. Never
git add -A, never repo-wide formatting. - Never overwrite, rewrite from scratch, or discard existing or uncommitted work. Edit in place, and ask the user first if an assignment implies replacing content.
- Finish, or record a handoff, before anyone else edits your file.
- Never commit or bump the version unless the user explicitly asks. Otherwise leave the work in the tree and report the diff.
What this is not#
Bounded inspection is the safe read path. See when to recruit for captain inspect and its limits.