Module V — Role Engineering & Capability Scoping
Phase 3 · ROLES — Module V
Status: Authored & Empirically Verified.
Lecture Components: 6 FHD 1080p master videos + Lab L5.
Canonical Core Axiom:
ROLE ≠ MODEL ≠ HARNESS ≠ PROVIDER
1. The Fundamental Separation of Concerns
A foundation model is a probabilistic completion engine; it does not possess intrinsic roles, permissions, or security boundaries. In industrial harness engineering:
- Role: An authoritative, closed operational seat defined by hard typed contracts, permissible state transitions, and an immutable action envelope.
- Model: An ephemeral, interchangeable cognitive commodity executing inference within the seat.
- Harness: The deterministic control plane compiling contracts, sandboxing executions, and enforcing policy boundaries.
- Provider: The external computational infrastructure hosting the tensor weights.
Authority, permissions, and tools attach strictly to the role seat, never to the underlying model or conversational persona.
┌────────────────────────────────────────────────────────┐
│ ROLE SEAT │
│ (Closed Contract · Scoped Capabilities · Typed FSM) │
└──────────────────────────┬─────────────────────────────┘
│ Dispatches
▼
┌────────────────────────────────────────────────────────┐
│ DETERMINISTIC HARNESS │
│ (Bitmask Kernel · AST Oracles · Ephemeral Tokens) │
└──────────────────────────┬─────────────────────────────┘
│ Routes Inference
▼
┌────────────────────────────────────────────────────────┐
│ FOUNDATION MODEL / PROVIDER │
│ (Interchangeable Probabilistic Commodity) │
└────────────────────────────────────────────────────────┘
2. Canonical Closed Role Taxonomy
HEFESTO rejects unconstrained, open-ended agent hierarchies in favor of an explicit closed taxonomy:
1. Planner: Decomposes complex objectives into verifiable DAGs; strictly read-only tools; zero mutation rights. 2. Implementer (Maker): Generates candidate code diffs within an isolated worktree; bounded file write capabilities. 3. Reviewer (Checker): Adversarial evaluation of candidate diffs against independent specs; strictly barred from authoring fixes. 4. Challenger: Active mutation testing and edge-case fuzzing; injects synthetic defects to prove test suite robustness. 5. Researcher: Gathers external documentation and codebase context; read-only tools with strict admission firewalls. 6. Auditor: Immutable verification of cryptographically linked event ledgers and provenance hashes. 7. Operator: Executes deterministic deployments and Git commits only when presented with unexpired attestation tickets. 8. Human Authority: Ultimate out-of-band circuit breaker for high-blast-radius state transitions.
Zero Self-Review Axiom:
The entity that generates a deliverable is mathematically forbidden from holding the authority to approve, merge, or deploy it.
3. The Principle of Least Capability (PoLC)
While the Principle of Least Privilege (PoLP) governs OS users, the Principle of Least Capability (PoLC) governs the cognitive action space of an LLM:
- Ambient Authority Elimination: Agents are never provisioned with broad credentials "just in case."
- Monotonic Privilege Attenuation: As a workflow transitions from exploration toward execution and deployment, operational capabilities can only shrink or remain constant, never expand silently.
- Path & Verb Sandboxing: Tools are restricted to explicit directory paths and whitelisted mutation verbs.
4. Curricular Components
- 05-01 — Role Definition as Hard Architectural Constraint: De-aliasing Role, Model, Harness, and Provider; closed role seats; structural prevention of self-review.
- 05-02 — The Principle of Least Capability (PoLC) in Agent Systems: Scoped capabilities vs ambient permissions; blast radius minimization; monotonic attenuation.
- 05-03 — Tool Exposure Scoping & Dynamic Capability Negotiation: Defending against registry bloat (30–50 tool ceiling); dynamic tool projection; HMAC-signed ephemeral capability tokens.
- 05-04 — Privilege Escalation & Lateral Movement in Agent Swarms: Confused Deputy vulnerabilities; non-transitive authority; capability tainting across agent boundaries.
- 05-05 — Persona Drift & Constraint Decay Over Extended Runs: Transformer attention dispersion; failure of emphatic prompting ("Zero-Pleading Policy"); ephemeral subagent recycling.
- 05-06 — Role Contracts as Verifiable Types: Compiling role contracts into algebraic Go interfaces; static AST oracles; kernel non-circumvention enforcement.
5. Associated Capstone Lab
- Lab L5:
../labs/L5-role-capability-matrix.md— Pure Go implementation of an O(1) Bitmask Capability Matrix, HMAC-SHA256 Tool Scoping Engine, Static AST Interceptor, and Ephemeral Subagent Recycler.