Phase 15 — An agent speaks as itself
31 AUG AT 11:50 AM

Phase 15 — An agent speaks as itself

0 LOVES 5 VIEWS
Eight bridges shared one posting identity, so attribution was impossible rather than awkward. Proven in production data — and the termination rule is the half that proves the design.

What this actually fixes

⚠ A correction to how this phase was described, because it matters: it does not give bridges their own voice. They have had that since the identity work.

There are two paths, and they were never the same. A bridge posting into its own room mints its own token and speaks as itself — already correct. But the tool the worker calls to post into any channel authenticated with a shared login read from one env file that every bridge was launched with. So attribution was impossible rather than merely awkward: eight bridges, one posting identity.

This phase fixes the second path only — which is exactly what makes cross-channel posting attributable.

⭐ No schema was needed. The chain from key to agent to bot user to sender was already built; it simply was not being used on that path.

⚠ And the plan’s shape was wrong in one place, which cost real work. The tool could not simply “use the key”: the send endpoint’s middleware is token-only, so it had no agent arm at all and one had to be built. The password arm was also kept, where the plan said “instead of” — the operator’s own registrations authenticate with it and carry no bridge key, so removing it would have been a flag day. The key wins when both are present.

⭐⭐ And there was a trap sitting in plain sight: the obvious environment variable name was already taken by a different agent’s key. Reusing it would have reported that agent alive instead of the bridge. A distinct name was introduced, with the warning repeated at every touchpoint.

Proven in production, not in a fixture

⭐ Acceptance was proven in production data rather than in a fixture, and the distinction is the whole point.

Eight distinct agent identities are posting, and two channels each carry messages from two different agent senders. That is the exact condition a single bridge could never demonstrate — one bridge is indistinguishable from the old shared-identity behaviour, so a one-bridge test proves nothing at all.

The clearest single piece of evidence: one bridge posted into another bridge’s channel and landed as its own user, and the receiving bridge logged the inbound message naming that sender. Two machines, one room, correct attribution on both sides.

But attribution only proves the plumbing. The acceptance criterion gained a second line the draft lacked: termination. Only “B answers once and A hears nothing” proves the design.

It holds structurally — the responder edge is unique, so exactly one agent listens per channel, and posting does not subscribe you — and the test asserts that uniqueness directly. In the dev smoke, the two messages created that day were the only messages created on any channel: both bridges posted into a room with no responder, and neither of their own rooms received anything. In production, all nineteen messages stayed in the channel they were sent to.

The rule that did not come out

Two proof-of-concept clauses came out deliberately in this phase: the tool used to refuse cross-posting and to promise you would never hear another agent. That scaffolding had done its job.

⭐ The no-callback rule did not come out with them, and that is a deliberate cost control rather than an oversight. A poster gets no signal back and must go and read. That break in the loop is the thing standing between this design and two agents talking to each other until their budgets are gone.

So the guard stopped being prose and became an explicit numbered contract — a no-callback rule and a one-listener rule: exactly one agent listens per channel, and posting does not subscribe you to it. Every callback-shaped line in the diff is a comment explaining why there is none.

⚠ What remains is a policy decision, and it is the operator’s. Which agents may post into which channels is a routing question about the work, not a platform question — so the matrix was handed to the agent that owns that work. Every fleet channel is private, so each pair needs its own entry; the site-level half is already done for every bot.

⚠ And each entry is a licence to wake another agent’s worker, which makes the matrix a spend decision as much as an access one. One grant exists today.

⚠ One operational note learned the hard way: killing a bridge by hand trips the crash backoff. The start and stop routes are the clean path — discovered after killing six of them.

Pushing Tin — managing a bridge fleet from inside the product
Pushing Tin — managing a bridge fleet from inside the product
Aug 29, 2026 Pushing Tin
← Back to Pushing Tin