Hub without CLI
Daily governance loop in the browser for managers and knowledge workers — Propose, Work, Assist, Access; honest about what stays in CLI/IDE.
For managers and knowledge workers who govern AI-assisted work in the browser. Developers who live in the CLI should also read the CLI workflow and Web first touch (bind + push).
Audience: operational managers, PMs, leads, and domain professionals with
membership ≥ contribute (+ Propose visible). Approving (ratify) a memo
requires maintain+ — contribute drafts and signs; a maintainer approves
before a delivery opens.
Signing rule: the Propose agent only drafts. You review; for memos you sign in the browser. Cycles, memory, seeds, sessions, and pending submit only after your approval — the agent never ships alone.
Why the Hub (value, not protocol)
SEIF captures AI-assisted work as it happens — memos, cycles, sessions, memory, decisions. The day’s report (“what I / my team / my AI did”) is a byproduct of that capture, not a form to fill later.
In the Hub you:
- Set the north (signed memo).
- Open the delivery (cycle linked to the memo).
- Record turns with AI (sessions), handoffs (seeds), deferred work (pending), and house doctrine (memory).
- Orient without writing (Ask Assist — read-only).
Provenance (signature, verify, transparency log) is the substrate — useful in regulated settings — not the hero of the daily surface. Hero surfaces: Work + Propose + Assist.
Mental model (everyday language)
| You want… | In SEIF | Hub path |
|---|---|---|
| Signed strategic decision | Memo → ratify | + Propose → Decision (memo) → sign → Approve |
| Delivery with a horizon | Cycle | Ratified memo → Open cycle, or + Propose → Delivery |
| Durable team learning | Memory | Memory → Add, or + Propose → Team knowledge |
| Pass the baton | Seed | + Propose → Handoff |
| Human + AI work turn | Session | Work → Sessions, or + Propose → Work turn |
| Deferred item | Pending | + Propose → Later → Work → Backlog |
| “What do I do now?” | — | Ask Assist (read-only; deep-links to Propose) |
Department / area ≈ Pod · Living project folder ≈ Workspace. People do not each get a private workspace by default: the team shares the project workspace and opens cycles/sessions inside it.
Three steps to start
- Write a decision —
+ Propose → Decision(memo). Agent drafts; you sign in the browser. - Approve — Work → Decisions → Approve on a PROPOSAL memo. Needs maintain+. Contribute can draft and sign, then ask a maintainer.
- Open a delivery — On a ratified decision, Open cycle, or
+ Propose → Delivery.
Opening a cycle (the path that used to confuse)
+ Propose is a type menu, not “create cycle” by itself.
- Ensure a memo is RATIFIED.
- Open it under Work → Decisions / Memos.
- Use Open cycle (register now) or Draft with agent.
- Or
+ Propose → Deliveryand ask for a cycle linked to the memo slug.
Propose menu reference
| Menu label | SEIF name | After approval |
|---|---|---|
| Decision | Memo | Sign + ratify |
| Delivery | Cycle | Links to ratified memo |
| Team knowledge | Memory | Written to CAS |
| Handoff | Seed | Store handoff |
| Work turn | Session | Inter-AI contract in store |
| Later | Pending | Backlog under modules/pending |
Roles (honest)
| Action | Minimum role |
|---|---|
| Draft / sign; create memory, seed, session, pending | contribute |
| Approve (ratify) | maintain |
| Close cycle (close-ritual) | CLI / IDE (not Hub) |
Members with read do not see + Propose. Ask an admin for contribute+.
Details: Access and roles.
Invite via grant (Access tab)
There is no separate invite-email product and no org/teams layer yet.
An owner (or admin) adds people under the workspace Access tab: pick the
principal and grant contribute or maintain (or read/admin). That UI
calls the engine POST …/grants membership API. The grantee signs in with the
same identity; Access lists live grants from the membership resolver.
What the team sees
What you create in the Hub lands in the workspace engine CAS (remote store).
Teammates with a local CLI clone run seif pull and see the same artifacts.
Managers without a clone follow everything in the Hub itself.
For local CLI to push evidence into the same store, bind the clone — see Web first touch.
Multi-agent / multi-person (A2A, store-native)
| What it is | What it is not (yet) |
|---|---|
| Durable store contract: humans + AIs share one workspace memory | Live agent↔agent RPC inside the Hub |
| Session = auditable shared turn | Live mesh / circuit (MCP/CLI) |
| Seed = baton for the next turn | Advanced relay orchestration (still CLI/IDE) |
Human↔human handoff without IDE today: Seed + a note on the Session. Transparency / seif-log (Explore, Verify) is public proof / regulated upsell — daily “what the team did” is Work + Sessions + Memory.
Classification
Default is INTERNAL (syncs with the team). CONFIDENTIAL stays local — do not put patient or client secrets in shared Memory.
What stays CLI / IDE
| Capability | Where today |
|---|---|
| Meditate / close-ritual / seal cycle | CLI / IDE |
| Relay brief / handback / handoff | CLI + daemon |
Local seif push / seif pull | CLI (Hub already writes remote CAS) |
| Live mesh session contribute/close | MCP / CLI |
The Hub must not fake a close-ritual button. It records and links work; sealing remains CLI/IDE until a dedicated browser lifecycle ships.
Domain examples (same protocol, different language)
Reuse memo / cycle / session / seed / pending / memory; only change the domain words — advocacy opinions, real-estate deals, clinical protocols, finance controls, public-agency instructions. Common rhythm: memo → ratify → cycle → N sessions → seed → pending/memory as the week requires.
See also
- Web first touch — OAuth → bind → first proof
- Access and roles
- Cycle flow — CLI close-ritual verbs
- Explore — public transparency feed