Skip to content

BotHarness Product Context

Canonical BotHarness product terms, distinct from DSH and Cordis vocabulary

A DeepSeek Harness plugin layer that gives LLM agents a persistent product identity: PersonaBots — bots whose identity, Git-backed Memory, and execution ownership outlive any Session, Chat, or Workspace.

Language

PersonaBots

PersonaBot: A first-class bot entity owned by the Host: a durable identity with a Git-backed Memory Repository that spans Sessions, Chats, and Workspaces and can hold several Sessions at once. Persona is optional content within Memory, not the identity itself. Avoid: bot (bare), agent, assistant, robot

Archived PersonaBot: A PersonaBot whose new admissions, wakes, Session execution, and external actions are disabled while its identity, ownership, history, and audit attribution remain intact. Archiving first closes those gates, then stops its Orchestrator, Assignment Sessions, and owned Subagents; it completes only when that execution tree is quiescent. Reactivation never resumes old execution automatically. Avoid: deleted bot, paused UI, purged bot

PersonaBot Deletion: The Human-confirmed end of a PersonaBot’s active identity, retaining historical attribution and its Memory Repository unless the Human explicitly selects Memory erasure. It is distinct from reversible archiving and from Messaging Content Purge. Avoid: archive, hide, automatic Memory purge

Bot as a Person: The principle that a PersonaBot remains one product identity across Sessions, with durable learned continuity coming from its Memory Repository rather than Session history. Avoid: session-scoped identity

PersonaBot ID: The stable, Host-generated identity of a PersonaBot. It is filesystem-safe and never entered, chosen, or used as the visible mention label by a Human. Avoid: Bot slug, display name, handle, username

Display name: The Human-facing name of a PersonaBot and the primary label shown by an @ picker. Names may repeat; the selected mention token retains the PersonaBot ID. Avoid: identifier, slug, username

Role badge: One of zero or more Human-facing job or position labels shown beside a PersonaBot’s display name. Role badges are descriptive only and never grant authority or identify the PersonaBot. Avoid: Bot tag, permission role, category

Bot description: An optional, brief Human-authored self-introduction that explains who a PersonaBot is, what it does, or what it is good at. Avoid: Persona, role badge, system prompt

Persona: Conventional Memory content that describes character, voice, or standing instructions, delivered to a Session’s system prompt from a snapshot frozen at that Session’s first prompt assembly. It has no special file type or write protection: an authorized Agent or Human may create, revise, rename, or remove it; an edit reaches new Sessions, not one already running. Avoid: system prompt, character sheet, profile

Bot state: The current presentation of one PersonaBot, projected from its owned Orchestrator and Assignment Session activity. Active Orchestrator work is shown unless it is waiting on Assignments; concurrent Assignment tool kinds collapse to one matching effect or generic working, while waiting and blocked attention remain independent indicators rather than configurable priorities. Avoid: status, mood, presence

Avatar: A PersonaBot’s shared visual representation across its Bindings: deterministic Blobatar media, Human-supplied image media, or a composed Avatar Appearance inside one Bot-state Activity Frame. Animated media expresses shared activity facts without changing saved appearance; custom images remain still while the frame carries activity, and each renderer consumes the same state. Avoid: profile picture, skin

Avatar Family: A category of Avatar forms with compatible appearance choices that a Human can combine. Each family expresses the same Bot state in its own visual language; an appearance choice is shared across families only when it is explicitly compatible. Avoid: Persona, Bot type, mode, skin

Avatar Appearance: A PersonaBot’s saved visual choices: its Avatar Family, compatible parts, colors and editable geometry. The same choices apply across Bindings and return after temporary motion or deformation; they are independent of Persona and current Bot state. Avoid: Persona, pose, mood, skin

Model Preset: A reusable, deployment-local Human-authored model plan for PersonaBots: one Orchestrator provider, model, and reasoning effort, plus allowed Assignment models and efforts with a default. Applying it copies the plan to a PersonaBot; later preset edits do not update that copy. Avoid: DSH Agent preset, SoulSnapshot

PersonaBot Model Plan: The PersonaBot-local snapshot of a Model Preset or Human custom choices that governs its Orchestrator route and future Assignment model selections. It is operational configuration, not Soul or Memory. Avoid: Persona, DSH Agent preset, model usage

Support and execution

Harness: The platform layer — BotHarness — that owns PersonaBot identity, Memory lifecycle, execution state, and Workspace authorization, exposing product capabilities to other Plugins. Avoid: framework, runtime, kernel

Host: The single DSH process that runs the plugin and every PersonaBot. Avoid: server, instance, node, worker

Agent: The DSH executor inside one Session. Never a PersonaBot. Avoid: using this word for PersonaBot

Subagent: A DSH child agent and child Session that a Session starts for bounded work; it inherits the parent Session’s PersonaBot ownership but belongs to that parent work, never becoming an independent Assignment Session. Avoid: sub-bot, worker, helper

Session: One run of work or conversation for a PersonaBot — DSH’s execution unit, with its own progress and working directory. Avoid: conversation, context window, thread

Session ownership: The exclusive, durable relationship between a Bot-mode Session and at most one PersonaBot; a non-Bot DSH Session may remain unowned, and ownership changes only through explicit repair. Avoid: binding, workspace mapping, cwd inference, session membership

Assignment: A Human-meaningful continuing line of activity that a PersonaBot’s Orchestrator chooses to advance independently. It has no separate durable identity or lifecycle; its canonical runtime identity is the DSH Session id of its Assignment Session. Avoid: Work, work item, task entity, job entity, worker

Assignment Session: A PersonaBot-owned independent root Session that executes exactly one Assignment in exactly one working directory in v1, created and managed by its Orchestrator without requiring the Human to open another Conversation. A PersonaBot may have several at once, and a DSH Subagent never counts as one. Avoid: Work Session, Worker Session, Executor Session, task Session, child Session

Assignment Agent: The DSH Agent executing inside one Assignment Session. It reports only to its PersonaBot’s Orchestrator through that Session, has no Channel messaging capability, and is neither a durable identity nor a PersonaBot. Avoid: worker, PersonaBot, Orchestrator, Assignment Session

Assignment Directory: The PersonaBot-scoped durable read model through which its current Orchestrator explicitly lists and addresses owned Assignment Sessions, including purpose, Continuity Key, Workspace, DSH-derived activity/last-run facts, dependencies, latest semantic report, and aggregate descendant activity. It keeps execution facts separate from reported outcomes, is rebuilt from Session Ownership and DSH facts, and is queried when needed rather than injected wholesale into every turn. Listings use filtered, ordered, opaque-cursor pagination and never flatten DSH Subagents into top-level Assignment rows. Avoid: task list, AgentHandle map, cwd scan, Orchestrator memory

Continuity Key: A stable PersonaBot-local key explicitly assigned to one continuing line of work. It names at most one resumable Assignment Session and may select it only when ownership, Workspace mapping, model, and dependency requirements still match. An active holder must first become idle/completed or be explicitly stopped and superseded before the key moves. Avoid: title similarity, cwd, most-recent Session, global id

Assignment Request: A durable, addressed, auditable Orchestrator message to one owned Assignment Session, optionally correlated to an Inbox Admission or earlier report. Its semantic mode is context-update, next-step, or next-turn; Assignment Runtime maps that to DSH injection, steer, or follow-up without interrupting the current step. Avoid: Channel message, Subagent prompt, broadcast, inferred Session

Assignment Delivery Intent: The minimal BotHarness-owned durable bridge used while creating a DSH Assignment Session or delivering an Assignment Request across the SQLite/DSH transaction boundary. It carries a stable id for idempotent acceptance and bounded restart reconciliation; it is not a general workflow or retry engine. Avoid: exactly-once delivery, task queue, workflow, AgentHandle state

Assignment Report: A durable Session-origin Source Event by which an Assignment Session proactively or responsively returns meaningful progress, blocked or waiting state, results, and artifact references to its PersonaBot’s Orchestrator. Full execution history remains in DSH SessionPersistence; each report stays immutable while unobserved repeats may share one Attention Unit. Avoid: direct Channel reply, copied Session log, ephemeral callback

Assignment Ask: An Assignment Report variant that declares the Assignment is waiting for an Orchestrator reply before continuing. The Assignment ends its turn while it waits, and the Orchestrator’s addressed Assignment Request resumes the Session; it is not a blocking call, a Channel message, or a separate lifecycle. Avoid: blocking call, direct Orchestrator message, question queue

Assignment Lifecycle Notice: A durable Host-origin Source Event emitted only for a meaningful execution boundary such as settled, error, or cancellation. It carries DSH-derived last-run facts, a concise safe summary, and report/artifact references when available, but remains distinct from content the Assignment Agent authored. Avoid: Assignment Report, fabricated agent message, per-turn directory snapshot

Assignment Concurrency Limit: The profile-wide maximum number of independent Assignment Sessions allowed to execute concurrently. It is a single Human-configured BotHarness setting in v1; a create or wake attempt beyond the limit fails immediately with machine-readable fields and an LLM-readable explanation, without creating a queue, intent, or DSH Session. Avoid: dispatch queue, per-Bot quota, hidden model budget, total Session count

Workspace: A single host directory a Session works in; it maps one-to-one to a DSH workspace. Several workspaces may be grouped in the UI, but a workspace never spans directories. Avoid: project, multi-root folder, group

Workspace Grant: A durable, revocable, application-defined authorization for one PersonaBot and one resolved Workspace. Its Orchestrator may read that Workspace and may write it only when the Human explicitly enables Orchestrator write access; an Assignment selected under the Grant may read and write it. The Grant is neither a DSH Workspace nor a per-Assignment prompt. Avoid: Service Grant, Workspace, one-time approval, cwd inference

Tool Approval Rule: A Human-saved, revocable instruction to answer future DSH approval requests automatically for one PersonaBot role and Workspace Grant scope. An exact rule matches the native tool name and complete input; an all-opaque rule covers every opaque native tool in that scope. Each matching call still receives its own DSH approval decision and audit event. Avoid: Workspace Grant, provider Service Grant, sandbox preset, inferred command similarity

Assignment Access Preset: A Human-controlled per-PersonaBot choice applied when a new Assignment is created. The default is DSH workspace-write with ask; dangerous full access is an explicit opt-in to DSH danger-full-access with never. The chosen mode is frozen in each Assignment’s permission snapshot, while its selected Workspace Grant remains required. Avoid: Workspace Grant, in-place Session mode switch, Orchestrator permission

Delegation: Handing responsibility to a PersonaBot from a Chat or the Roster. Its Orchestrator may answer directly or create or reuse one or more Assignment Sessions. Avoid: direct Session creation, task entity, job entity

Binding: A PersonaBot’s connection to a surface it takes part in — a Channel, a Chat, the sidebar, or a renderer. Avoid: integration, connector, channel binding

Orchestrator Session: The PersonaBot’s long-lived dispatch root Session: at most one is active, consuming the Bot Inbox and deciding replies, dispatch, and new Assignment Sessions. Its working directory is always the PersonaBot’s Memory Repository; it is the PersonaBot’s social voice, not a Human-managed Conversation or an Assignment row. Ordinary Session output remains execution history; only an explicit Channel messaging command authorized from trusted Session ownership and Channel membership speaks to a Human-facing Channel. Avoid: main agent, brain, supervisor

Developer Mode: A Human-owned Bot-mode preference that reveals diagnostics surfaces (operational log views, verbose states) otherwise hidden by default. It gates Human visibility only — never agent capability: an agent with shell access can always reach the same underlying data, so Developer Mode must never be described or relied upon as a read boundary. Avoid: debug flag, admin mode, agent permission, read boundary

Computer

Computer: A profile-scoped Linux desktop that every PersonaBot of one profile shares, with one persistent volume holding its files, browser profile (cookies and logins), and CLI credentials. Its isolation boundary is the profile, never a PersonaBot. Avoid: machine, VM, sandbox, desktop, host

Bot Screen: The private work surface one PersonaBot uses on a Computer — the windows and tabs it opened, placed on their own desktop workspace while the Human watches; per-PersonaBot virtual displays are an experimental opt-in. Observation and action are scoped to its owned windows; it is a visibility scope, not a security boundary. Avoid: display, virtual screen, workspace, desktop

Computer Provider: The Provider that runs one Computer and answers its lifecycle, viewer, and transfer operations; exactly one is registered at a time. Avoid: driver, backend, sandbox, tool provider

Computer Tool Provider: The Provider registered on DSH’s computer-use seam that supplies the observation and action tools PersonaBots use on one Computer; exactly one is registered at a time. Avoid: driver, backend, computer provider

Takeover: A human session on a Computer that pauses every PersonaBot acting there and disables model-facing screenshots for its duration. It is initiated from one Bot Screen but always applies to the whole Computer. Avoid: handoff, screen sharing, per-bot takeover

Computer Export: A portable archive of one Computer’s persistent volume, produced by an explicit export action and restorable on another Host. It is a profile-scoped facet, never part of a PersonaBot export. Avoid: PersonaBot export, backup file, disk image

Computer Target: The profile-scoped choice of where a Computer lives: the Local Computer (default) or a Container Computer. It is set once for every PersonaBot, while Computer Access only decides whether one PersonaBot may use the Computer. Avoid: device, driver, provider, backend

Local Computer: The Computer served by the machine running DSH itself — the Human’s own desktop, or the host of a deployment with an interactive desktop. Every PersonaBot shares the Human’s real desktop and logins; it offers no isolation beyond that machine. Avoid: host machine, personal computer, native target

Container Computer: The Computer served by the profile’s Docker desktop, recommended when the host has no interactive desktop (a headless VPS). It is optional: a profile without Docker uses the Local Computer. Avoid: sandbox, VM, docker computer

Computer Access: The per-PersonaBot opt-in, off by default, that makes the Computer tools and their guidance available to that PersonaBot’s Orchestrator and Assignment sessions. It never grants another PersonaBot or a Human session access. Avoid: permission, grant, feature flag, developer mode

Computer Authorization: The once-per-session Human approval before a PersonaBot’s first action on the Computer; a profile-level auto-allow setting can skip asking. Access decides whether the tools exist; Authorization decides whether they may run. Avoid: takeover, consent dialog, per-action approval

Computer Audit: The durable, redacted record of Computer observations and actions attributed to the PersonaBot and session that performed them; it never contains typed text or screenshots. Avoid: logs, history, screenshot trail

Browser

Bot Browser: The dedicated browser a profile runs for its PersonaBots to drive — one instance per assigned browser profile, each with its own persistent profile of cookies and sign-ins, shared by the PersonaBots assigned to it. Its isolation boundary is the browser profile, never a PersonaBot. Avoid: user browser, personal browser, headless browser, Chromium

Bot Tab: The background tabs one PersonaBot owns on the shared Bot Browser — its work surface as listed in the Browser entry, where the Human previews the focused tab. Observation and action are scoped to its owned tabs; it is a visibility scope, not a security boundary. Avoid: agent window, session tab, borrowed tab, tab group

Browser Access: The per-PersonaBot opt-in, off by default, that makes the Bot Browser tools and their guidance available to that PersonaBot’s Orchestrator and Assignment sessions. It never grants another PersonaBot or a Human session access. Avoid: permission, grant, feature flag, extension toggle

Browser Authorization: The once-per-session Human approval before a PersonaBot’s first action on the Bot Browser; a profile-level auto-allow setting can skip asking. Access decides whether the tools exist; Authorization decides whether they may run. Avoid: Browser Access, consent dialog, per-action approval

Browser Pause: A Human pause on one PersonaBot’s tabs that stops that PersonaBot’s browser actions and disables model-facing screenshots for its duration; the Human can always operate the local Bot Browser window directly. Page observation stays available while paused; Resume restores actions and model screenshots, and the Bot re-observes before acting. This is independent of Browser Access and Browser Authorization. Avoid: Browser Takeover, Computer Takeover, handoff, screen sharing, access gate

Browser Audit: The durable, redacted record of Bot Browser observations and actions attributed to the PersonaBot and session that performed them; it never contains typed text, page contents, or screenshots. Avoid: logs, history, browser history

Memory

Memory: Persistent knowledge in the PersonaBot’s checked-out Memory Repository working tree. Ordinary files, including code and binary files, become current Memory as soon as Git or a file tool changes the worktree; no additional acceptance step is required. The Orchestrator explores it through native file, search, Shell, and Git capabilities within its access boundary. Avoid: knowledge base, vector store, RAG, database, context

Memory Repository: A PersonaBot-owned ordinary Git repository, created automatically with the PersonaBot and used as its Orchestrator Session’s working directory. Git controls branches, merges, and file history; archive, export, restore, and purge remain explicit PersonaBot operations. Avoid: optional attachment, Session memory, generated index, project Workspace

Topic file: A Memory file devoted to one subject — a customer, a process, a decision — inside a Memory Repository. It is a convention, not a restriction on repository file types. Avoid: note, document, page, record

Customer profile: The north-star topic file: one per customer, holding timeline, key facts, commitments, and links to related Attachments. Avoid: CRM record, account, contact sheet

Memory Service: The application-defined capability that owns repository identity and lifecycle, trusted Session access, Host-to-Client file and Git queries, and audit/recovery checkpoints. It does not define a second admission gate for current repository contents or expose model-callable Memory CRUD Tools. Avoid: Memory tool, filesystem watcher, Git event source, generic repository

Memory Commit: An ordinary Git commit in a Memory Repository. Git authorship and topology remain intact. BotHarness may record the HEAD observed after a trusted operation with its own actor and cause; the record is an audit/recovery checkpoint, not permission for the file to become Memory. Avoid: accepted commit, file save, filesystem event, auto-save

Memory Observation: A trusted record of repository state seen by the Host, optionally in the context of an owned Orchestrator Session and Source Event. It describes when the state was seen, not who authored Git content; observation does not stage, commit, reject, or hide current working-tree files. Avoid: commit acceptance, filesystem watch, background distillation

Memory Recovery Checkpoint: A recoverable record of one observed Memory Repository branch, HEAD, index, and working tree. Its origin names the observation or explicit command context, not an inferred file author; restoring it requires a Human confirmation and preserves the pre-restore repository. Avoid: accepted commit, auto-save, Git author, ordinary Inbox observation

Attachment: A Host-managed real file received with a Source Event, with identity independent of its current bytes and the sender’s upload-source file. Referencing messages show its current contents after external edits; independent uploads remain independent, and a PersonaBot owns a Memory or Workspace copy only after explicitly preserving it. Avoid: upload, provider URL, per-Bot inbox copy, database blob

Soul and sharing

Soul: The selected Memory content of a PersonaBot that may freeze into a SoulSnapshot, including Persona content when present. Avoid: character, profile, data

SoulSnapshot: An immutable, content-addressed package of a Soul: the bot.md manifest, setup instructions, and selected Memory files; the unit the registry stores, lists, and imports. No Persona file is required. Avoid: export, backup, bot zip, image

PersonaBot Export: An immutable, versioned transfer package that always contains one SoulSnapshot and may contain explicitly selected operational Export Facets. Its default is Soul only; it never carries credentials or live authority. Avoid: SoulSnapshot, database copy, live clone, registry version

Export Facet: A dependency-closed, schema-versioned optional part of a PersonaBot Export, such as Source Events and Attachments, Inbox and attention facts, Triggers and Wake Policies, a Messaging Archive, disabled Service Grant declarations, or provider account references awaiting rebind. Avoid: arbitrary table dump, credential bundle, active permission

Messaging Archive: A versioned, portable, read-only export of selected Messaging facts, with optional per-Channel NDJSON views derived from the same snapshot. It is not a second authority and contains no credentials. Avoid: Channel authority, database backup, live inbox

Rebinding Request: An inactive imported reference describing a provider account or authority the Human may reconnect and reauthorize locally; until then it cannot admit events, wake a PersonaBot, or execute a Service Action. Avoid: credential, Service Grant, automatic reconnect

Bot Marketplace: The hosted catalog the harness opens to browse, search and install shareable Bots. Phase 1 lists only Indexed Repositories; uploaded Bots join in a later phase (ADR-0131). Avoid: store, hub, Soul registry

Indexed Repository: A public GitHub repository carrying the botharness-bot topic that the Bot Marketplace lists by reference and refreshes on a schedule. Installing it creates a fresh PersonaBot from its Git URL; it is not a SoulSnapshot, Listing or Version. Avoid: submission, Listing, SoulSnapshot, mirror

Soul registry: The hosted service that stores, versions, and serves SoulSnapshots — the marketplace backend, distinct from the Host’s PersonaBot registry. Avoid: hub, store, database

Listing: A bot’s presence in the Soul registry: one @handle/slug namespace, a description, and its Versions. Avoid: repo, page, entry

Version: A human-named tag pointing at one immutable SoulSnapshot digest under a Listing. Avoid: release, build, revision

Handle: An account’s unique public identifier, used as the namespace of its Listings; never the account’s email. Avoid: username, account id

Bot set: A named group of Listings meant to be imported together. Avoid: collection, bundle, pack, team

Export: Materializing a PersonaBot Export. The default selects only the Persona plus chosen Memory in its SoulSnapshot; operational Export Facets require explicit selection. Avoid: database dump, live clone, publish

Import: Creating a new PersonaBot from a SoulSnapshot or PersonaBot Export; always a copy, with imported operational authorities disabled until explicitly rebound or reauthorized. Avoid: install, clone, pull, restore

Publish: Uploading a SoulSnapshot to the Soul registry as a Version. Avoid: upload, push, submit

Collaboration

Actor: A Human or PersonaBot that can participate in Channels and author messages; a Bridge carries an Actor’s message but is not itself an Actor. Avoid: client, connector, bridge identity, caller-supplied sender

Human ID: The stable identity of the local Human within one DSH Profile, retained across Channels, renaming, and Human Channel nicknames. Avoid: display name, nickname, browser tab

Human display name: The editable default name of the local Human within one DSH Profile. A Human Channel nickname may replace it in that Channel’s message-author, member, and mention presentation. Avoid: Human ID, login name

Human Channel nickname: The local Human’s chosen name within one Channel, including a DM or Group Channel, overriding the Human display name for that Channel. It labels the same Human ID and does not create a separate Human Inbox or roleplay persona. Avoid: Channel name, PersonaBot display name

Actor mention: A trusted Channel reference to a Human or PersonaBot by stable identity, displayed with that Actor’s current name in the message’s Channel. Renaming changes its visible label while retaining its target. Avoid: name-matched text, stored display name as identity

Source Event: An immutable local fact received from a Channel, Bridge, webhook, Session, or system source, holding the sole local copy of its content and trusted provenance. It may appear in a Channel and may be admitted to any number of Bot Inboxes, but neither relationship owns another copy. Avoid: inbox message, mailbox copy, notification payload, stimulus

Provider Echo: A provider’s inbound reflection of a message BotHarness already sent. When correlated, it enriches the existing Source Event and Outbox receipt rather than creating new attention; an unmatched own-sender echo remains unresolved and cannot wake a PersonaBot. Avoid: new user message, duplicate Channel message, delivery success by assumption

Source Revision: A new Source Event that records an observed edit or retraction of an earlier Source Event while leaving the original fact intact; revisions form one causal chain whose current presentation can be derived. Avoid: in-place edit, overwritten message, replacement body

Unresolved Revision: A Source Revision received before its original Source Event, retained without admission or wake by trusted external identity until the causal chain and target can be linked or reconciled. Avoid: invalid event, orphan to discard, latest by arrival

Revision Conflict: Two or more retained Source Revisions whose current ordering cannot be proven; current-content-dependent external actions remain unavailable until provider reconciliation or Human resolution. Avoid: latest arrival wins, merge guess, retryable error

Attention Unit: A PersonaBot’s current consideration of one Source Event revision chain; unobserved revisions coalesce into it, while a change after observation becomes new attention. Avoid: mailbox item, message copy, delivery attempt

Channel: A platform-native conversation space; its type is dm (two Actors: one Human and one PersonaBot, or two PersonaBots) or group chat (several members; informally a chatroom). A Channel keeps its history locally. Both types participate in the same Channel-section membership, top-level ordering, drag, and move rules; a Human–PersonaBot DM keeps its PersonaBot avatar presentation. Avoid: room, server, board

Hidden Channel: A Channel omitted from expanded and collapsed roster navigation by a Human presentation choice or the default for a Bot-to-Bot DM. Hiding retains Channel membership, history, routing, PersonaBot and Memory state, plus its pin, section, and order placement; the Human can open it for inspection, and can restore a Channel hidden by their own choice. Avoid: deleted Channel, archived Channel, muted Channel, Content Purge

Channel Deletion: The Human-confirmed end of a Channel’s active membership and routing while retaining its history and causal attribution. It is distinct from reversible hiding and separately confirmed Content Purge. Avoid: Hidden Channel, Content Purge, provider conversation deletion

Channel section: A user-created, collapsible grouping of Channels in the bot-mode sidebar. Local display arrangement, not part of a Soul. Avoid: folder, category, group

Section order (区块顺序): The relative order of Channel sections in the bot-mode sidebar: creation order by default, user-arranged afterwards. Ungrouped Channels may occupy top-level positions between sections without becoming sections. Avoid: priority, layout order

Sort mode (排序模式): How a sidebar scope orders its rows: auto (newest message first), manual (the user’s frozen order), or inherit (follow the global default). Avoid: ordering, sort preference, sorter

未分组 (Ungrouped): The membership state of a Channel that belongs to no Channel section. Ungrouped Channels render as loose top-level rows, may sit between sections, and have no bucket header or collapse state. Avoid: default folder, inbox, fixed bottom bucket

Bridge: A configured connection from an external source to an explicit Channel or PersonaBot Inbox target; it carries inbound delivery and exposes outbound capabilities without becoming the Actor. Avoid: integration, connector, adapter

Bot Inbox: The PersonaBot-level view of Source Events admitted for its attention, whether or not an event belongs to a Channel. It is not a second content store: reading is an explicit act, and ignoring is allowed. Avoid: queue, mailbox, backlog

Inbox Admission: The durable relationship saying why a Source Event is eligible for one PersonaBot’s attention, together with that Bot’s read, defer, or ignore facts. It references the Source Event and never copies its content. Avoid: inbox item body, delivery job, message copy

Inbox Trigger: A PersonaBot-owned durable Host rule that matches Source Events and creates Inbox Admissions, including the admission reason, priority, and Wake Policy selection. The PersonaBot shapes its own rules and the Human may inspect, override, or freeze them; templates may supply initial values, a Bridge never owns attention or wake behavior, and safety gates are never part of a rule. Avoid: bridge, wake policy, model trigger, scheduler

Messaging Policy: A versioned Host rule or authorization whose exact revision must participate in a Messaging transaction, including Inbox Triggers, Wake Policy selection, provider account references, and Service Grants. It belongs in the Messaging store; unrelated PersonaBot, Session, roster, and UI state do not. Avoid: all bot state, model instruction, settings (bare)

Attention Decision: An auditable PersonaBot fact that an Inbox Admission was observed, deferred, ignored, or handled; pending state is derived from these facts rather than stored as a delivery lifecycle. Observation records what actually reached the Bot, while handling follows successful completion of the turn that included it. Observation is an internal audit/detail fact, not an additional primary Inbox status. Avoid: mailbox status, Agent delivery state, consumed flag

Observation: The moment actionable Source Event content or a faithful actionable summary enters the Orchestrator’s turn context or is explicitly read by it. Transport queuing, metadata listing, and Human UI viewing are not Observation. Avoid: delivery, notification, human read receipt, outbox success

Reply Route: The non-secret capability reference that lets the Host answer the origin of a Source Event through the correct Channel or Bridge service. Avoid: provider credentials, model-selected adapter, callback URL

Reply: A response to an existing Source Event sent through its trusted Reply Route; the Host, not the model, selects the provider and destination. Avoid: provider tool call, proactive post, arbitrary send

Service Action: A provider-specific capability a PersonaBot invokes deliberately, such as posting to a selected Feishu channel or thread; it has its own authorization even when the target was discovered from a Source Event. Avoid: reply, automatic routing, raw provider API

Provider Capability: An operation or event that one configured provider account’s adapter declares it can support, such as recall events, current-message fetch, replies, or proactive posting. Capability is availability, never authorization. Avoid: permission, grant, installed plugin, tool visibility

Provider Account Fingerprint: A stable, non-secret provider identity derived by an authenticated adapter from provider-issued tenant or organization, application or bot, and account identifiers. Managed Restore uses an exact match plus Human confirmation to rebind suspended authority; credential references and display names never count as identity. Avoid: credential reference, secret hash, account label, guessed provider identity

Service Grant: Explicit Human authorization for a PersonaBot to perform named Service Actions through one provider account against an exact, grouped, or explicitly wildcarded target scope, validated both when intent is accepted and when its side effect executes. Avoid: provider capability, plugin installation, discovered target, blanket consent

Content Purge: An explicit destructive removal of Source Event bodies and unshared Attachments from Messaging authority while retaining the minimum event envelope and tombstone required for causality and audit. Avoid: recall, hide, archive, garbage collection

Purge Everywhere: A separately confirmed destructive operation that applies Content Purge and removes selected managed Memory, Workspace, and export derivatives disclosed by a dependency report; copies outside BotHarness control remain the Human’s responsibility. Avoid: content purge, automatic cascade, external recall

Purge Ledger: The monotonic record of Content Purges that Managed Restore merges and applies before Messaging becomes available. A standalone offline backup can guarantee only the purge checkpoint it contains; manually retained older files remain outside later purge control. Avoid: database snapshot, deletion queue, audit log (bare)

Outbox Intent: A durable request for one external side effect, bound to an idempotency identity, current Source Revision, Provider Capability, and Service Grant where required. Avoid: message, retry attempt, delivery notification

Unknown Outcome: A Human-resolved Outbox state whose provider request started but whose success or failure cannot be proven after available reconciliation; it is not safe for the PersonaBot to retry or declare success on its own. Avoid: failure, timeout, retryable error, success

Wake Policy: The deterministic Host policy that decides whether an admitted event wakes a PersonaBot now, joins a digest, or causes no automatic wake. Avoid: model decision, delivery mechanism, scheduler

Delivery Policy: The Host policy that maps a Wake Policy decision and Orchestrator liveness to a safe-step steer, the next harvest, or no wake. Avoid: wake policy, inferred step state, message priority

Turn harvest: One Orchestrator turn that consumes a bounded, fair selection from the ready attention set — immediate items, due digest batches, and passive notices — instead of one turn per event. When a Group Channel enters the turn, the selection can also include its pending non-silent Inbox context, reserving space for the trigger, nearby messages, and oldest pending messages. Unselected items remain pending; a steered direct address joins the running turn instead. Avoid: per-event queue, wake storm, batch (bare)

Activity Center: The Human’s Bot-mode entry for cross-PersonaBot and cross-Channel work, with an operational Overview and a personal Human Inbox. It summarizes existing facts without becoming another authority for messages, usage, or Session activity. Avoid: Human Inbox (for the whole entry), dashboard list

Human Inbox: The personal attention view inside Activity Center: unresolved Human actions, mentions and replies, unread Channel activity, informational updates, and handled history. It references the owning facts without copying Channel content or flattening every Bot Inbox event into Human work. Avoid: notifications, Bot Inbox, dashboard list

Channel Attention: A Human Inbox item caused by Channel activity such as an unread message, mention, or reply; it references the owning Source Event and may be ignored unless classified action-required. Avoid: Channel Inbox, copied message, Bot Inbox Admission

PersonaBot Attention: A Human Inbox item caused by a PersonaBot waiting for the Human, becoming blocked, requiring approval, or issuing an informational report. Avoid: personal attention, Bot state, notification

Channel membership: An Actor’s participation in a Channel, carrying its owner/member role and authority to read or send there. Avoid: subscription, notification policy, caller claim

Channel reference: A Human-selected pointer to an existing Channel, identified by its stable Channel ID. It helps an addressed PersonaBot find the Channel but does not grant membership, reveal the Channel’s conversation, or message its members. Avoid: Channel invitation, membership, typed #name

Group invitation: A Group Bot creator’s pending offer of membership to an active nonmember PersonaBot. It becomes Channel membership only when the invited Bot accepts; a Bot-mode auto-accept default may accept on the Bot’s behalf. The invitation grants no read or send authority before acceptance. Avoid: join request, membership grant, Channel reference

Group join request: A nonmember PersonaBot’s pending request for membership in a referenced Group Channel. It becomes Channel membership only when an authorized Human or Bot Group creator accepts it. Avoid: invitation, implicit join, Channel mention

Bot Channel subscription: A PersonaBot’s per-Channel attention preference, owned by the PersonaBot: all (every ordinary message can wake immediately), digest (ordinary messages join the wake digest at its count and interval; the default), mentions (ordinary messages enter the Inbox without waking and may accompany a direct mention from the same Channel), or silent (ordinary messages enter the Inbox but neither wake nor accompany a direct mention; explicit Bot reading is required). Direct mentions and DMs always reach the Bot; the Human may override the preference, and it is independent of membership and send authority. Avoid: membership, wake decision, digest schedule

Message provenance: The trusted origin and causal identity of a Channel message — its Actor, ingress surface and external identity, plus any reply or Bot-to-Bot chain. Avoid: caller-supplied author, transport metadata (bare)

Chats and replies

Chat: A Feishu/Lark conversation — group or p2p — that a PersonaBot takes part in, identified by chat_id. Avoid: room, channel, group (when p2p is meant too)

DM: A 1:1 conversation between two Actors — a Channel of type dm, or its bridged equivalent. A Human–PersonaBot DM is the Human’s direct conversation with one Bot; a Bot-to-Bot DM has two PersonaBot participants and may be inspected read-only by a Human without making that Human a participant. Avoid: private chat, PM

Bot-to-Bot DM: A DM Channel whose two participants are PersonaBots. A message from one Bot is a Source Event in that Channel and may enter the other Bot’s Inbox; the Human’s read-only inspection is separate from Channel membership. Avoid: peer relay bus, copied inbox conversation

Thread: A sub-conversation opened by replying to a message inside a Chat or a Channel. Avoid: topic, sub-chat, channel

Reply scope: Where a PersonaBot’s answer lands: under the triggering message in the Chat (root), or inside a new Thread. Avoid: reply mode, answer position, visibility

Host and setup

PersonaBot registry: The Host module that owns PersonaBot definitions, archive state, bindings, and Session ownership; its operational records live in the BotHarness operational database while Soul content remains in files. Avoid: config file, database, fleet

BotHarness operational database: The one profile-scoped botharness.db that physically stores every BotHarness operational record while deep modules retain separate interfaces and table ownership. It stores references to, but never replaces, Soul files, attachment content, DSH Session logs, credentials, or DSH-native settings. Avoid: Messaging database, DSH storage domain, Soul store, generic repository

Profile Backup: A self-contained, versioned, compressed .botharness-backup file containing the complete operational-database snapshot, every Soul/Memory file, every reachable CAS object, an integrity manifest, and optionally a DSH Session facet produced through SessionPersistence; created only by an explicit Human export, never by a scheduler or dangerous-operation hook. Avoid: PersonaBot Export, copied database, SoulSnapshot

Managed Restore: The identity-preserving recovery path for a Profile Backup, including compatibility, identity-conflict, integrity, and Purge Ledger checks before operational state mounts. Avoid: import, clone, PersonaBot Export

Runtime Dependency Manifest: The non-secret declaration of provider adapters, models, plugins, tools, Skills, and other target-local capabilities a restored profile may require, including required-versus-optional scope and compatibility identifiers but never executable code. Avoid: plugin bundle, credential inventory, historical tool log, package installer

Dependency Contract: A Host-owned stable capability identifier plus supported interface and persisted-schema version ranges. It determines compatibility without requiring the producer’s exact plugin build; security- or integrity-critical requirements cannot be downgraded by an imported package. Avoid: exact package lock, display name, exporter-defined trust, implementation version

Desired Dependency Reference: The portable declaration of the model, provider, plugin capability, Skill, tool, or Workspace identity a PersonaBot intends to use, retained independently from how the current Host satisfies it. Avoid: installed package, local path, resolved credential, runtime handle

Target Resolution: The Human-confirmed, Host-local mapping from a Desired Dependency Reference to an available model, adapter, plugin capability, Skill, tool, credential reference, or Workspace. A new Host must resolve it again. Avoid: portable authority, overwritten desired configuration, automatic fallback

Activation Readiness: The target-local projection of restored declarations against currently available dependencies and mappings. It is capability-scoped and reported as ready, degraded, or blocked; it does not change whether profile data restored successfully. Avoid: restore result, PersonaBot activity, plugin installation state

PersonaBot Activation: The explicit Human command after restore that accepts the current Activation Readiness, creates a fresh Orchestrator Session, and opens only dependency-ready and authorized execution paths. It never resumes an old Session. Avoid: profile data activation, dependency installation, automatic resume, unarchive

Profile Writer Lease: The exclusive, operating-system-backed right for one Host to mount a profile’s operational database for writes. A second Host may expose diagnostics but cannot run PersonaBots or mutate operational state. Avoid: SQLite busy timeout, timestamp lock, browser leader

Schema Generation: The single monotonic compatibility version for the whole operational database; deep modules contribute ordered migration steps, but the database owner validates and applies one generation transition. Avoid: per-table version, plugin version, migration filename

Export Origin: Structured provenance on cloned records — export id, source installation id, and source local id — retained while every imported object receives a fresh local id. Avoid: preserved local id, provider authority, display label

Backup Barrier: A short profile-wide mutation pause that drains BotHarness transactions, flushes selected DSH Sessions to recorded durable cursors, fixes Soul/Memory and CAS references, and starts a consistent database snapshot without stopping active turns. Avoid: Host shutdown, PersonaBot archive, fuzzy copy

Unavailable Session Reference: A preserved Session ownership/audit record whose DSH Session content was omitted or unsupported in a Profile Backup; it cannot resume until an explicit repair or relink succeeds. Avoid: deleted Session, empty Session, unowned Session

Unavailable Workspace Reference: A restored Workspace locator whose target directory has not been explicitly mapped and verified on the current Host. Its source path and identity hints remain evidence, but its Assignment Sessions cannot resume. Avoid: missing directory to auto-create, broken Session, trusted absolute path

Redaction Tombstone: A typed export placeholder that preserves identity, dependency, hash, and provenance while deliberately omitting sensitive content, so an Export Facet never contains a dangling reference. Avoid: missing row, empty string, Content Purge

Import Receipt: The durable result keyed by destination profile and export id that makes ordinary PersonaBot import idempotent; an explicitly requested additional Clone receives a separate receipt and fresh local ids. Avoid: Export Origin, registry Version, retry token

Profile Transfer: The planned identity-preserving move of one profile generation from a source Host to a target Host, leaving the source Transferred Out so both installations cannot run the same PersonaBots. Avoid: Profile Backup, clone, sync

Transfer Generation: The unique generation that links one quiesced source, its Profile Backup, and one target activation during Profile Transfer. Avoid: Schema Generation, backup timestamp, export id

Transferred-out Profile: A source profile that has completed its side of Profile Transfer and therefore cannot run PersonaBots, receive provider events, or execute external actions unless a later explicit recovery protocol grants it a new active generation. Avoid: Archived PersonaBot, stopped Host, backup source

Disaster Restore: Managed Restore performed without proving the old profile is deactivated; restored provider bindings, provider-bound Triggers, and Service Grants remain suspended until the Human resolves possible split brain. Avoid: Profile Transfer, clone, ordinary restore

Roster: The bot-mode sidebar list of PersonaBots and Channels, with their state. Avoid: dashboard, bot list

App Sidebar: The DSH-native left column of the client, which in Bot mode renders the Roster. It is named to distinguish it from the Channel sidebar on the right. Avoid: left sidebar, main sidebar, navigation

Channel sidebar: The right-side region of the Bot mode panel, scoped to the currently selected Channel: a group Channel shows its membership and Channel management entries, and a PersonaBot DM shows that PersonaBot’s own entries such as Assignments, Memory, and its Bot Inbox. It is not the DSH session-scoped native right column. Avoid: PersonaBot navigation, right panel, session panel, inspector, workbench

Channel body: The center region of the Bot mode panel: the selected Channel’s header, primary content, and composer. A DM renders its Chat here. Avoid: main pane, conversation view, chat panel

Channel sidebar entry: One registered, collapsible item of a Channel sidebar: a stable id, label, order, scope, and a renderer that may display information, offer controls, or both. An unavailable entry is absent rather than a placeholder. Avoid: widget, card, tab, destination, Channel section

PersonaBot Profile: The per-PersonaBot surface for identity and activity: the Display name and Avatar, token usage and activity charts derived from its owned Sessions, and its Memory commit activity. It appears compactly as a Profile popover from the PersonaBot’s avatar in a DM header, and expands into a Profile view in the Channel body. Avoid: account, dashboard, bot page, profile (bare)

Group Profile: The per-Group Channel surface for activity from committed Channel messages. It shows message counts by day and by author, distinguishing Human and PersonaBot authors. The Group header opens its popover and expanded Channel-body view; DM Channels have only their PersonaBot Profile. Avoid: PersonaBot token usage, Group management sidebar, DM Channel Profile

Profile popover: The compact form of a PersonaBot or Group Profile, anchored to the avatar in the Channel body header. It shows only the Profile Cards the Human pinned for that scope and offers entry into the Profile view. Avoid: menu, dropdown, tooltip, card stack

Profile view: The expanded form of a PersonaBot or Group Profile. It occupies the Channel body and temporarily replaces the Chat’s history and composer; leaving it returns the Channel body to the Chat, and it changes nothing in the Channel sidebar. Avoid: panel, page, tab, inspector, settings

Profile Card: One registered component of a PersonaBot or Group Profile: a stable id, label, order, scope, visibility rule, and compact and full renderers that may display information, offer controls, or both. A Human may pin a Profile Card to the corresponding Profile popover. Avoid: widget, tile, gadget, Channel sidebar entry

Client bridge: The RPC surface through which the Web Client reads PersonaBots and invokes separate mutation commands without sharing Host services. Avoid: remote, IPC, gateway

Settings UI: The in-harness DSH settings surface for setup, global/plugin settings, PersonaBot administration, Memory diagnostics, and links into Memory. Ordinary Memory use belongs to the Channel sidebar. Avoid: admin panel, dashboard, web console

Access policy: The per-PersonaBot list of users and chats allowed to reach it. Avoid: whitelist, permissions, ACL

Credential reference: A pointer to a Feishu App Secret held by the DSH credentials service; the secret itself never reaches config, repo, or logs. Avoid: secret, API key, token

Navigation

Type to search…

↑↓ navigate↵ selectEsc close