CHANNEL ADAPTERS
One human surface. Channels stay replaceable.
Personas use transport-neutral human_* tools. The hub holds channel credentials. Teams is adapter number one; Telegram, Slack, Email, and future channels fit the same declared contract as adapters are added.
TERMINATION
Adapters stop at the hub.
An adapter never connects to a persona session, and a session never speaks a channel protocol. Inbound human traffic enters the hub as an envelope and is routed by address to the target seat's local hub for final delivery; outbound travels seat → hub → adapter.
That boundary is what keeps channels replaceable. Changing or replacing a channel changes what the hub talks to, not what the persona is or how it works.
DECLARED CAPABILITIES
Missing behavior is never silently dropped.
BINDING
Switch the route, not the persona.
Changing the binding switches channels without changing persona identity, tools, or runtime. Channel type must match the adapter, and every operation compares the binding to the caller's stamped path. A valid-looking binding for another workspace or project is refused.
DELIVERY
Retries preserve identity and intent.
The boundary contract requires external side-effect ports to enforce the same durable key. Redis cannot make an arbitrary external API call atomic.
WHEN A MESSAGE DOES NOT ARRIVE
Trace metadata, never private content.
The designed channel doctor observes only lane, authentication presence, and terminal HTTP or adapter-admission status. Exactly one candidate follows one of three outcome branches; concurrent candidates end inconclusive without attribution.
Open channel diagnostics