# Agent ## Resident session One pi `AgentSession` per agent process, resumed from the session file on the agent volume across deployments and restarts. Operational resources (persona, skills, and AGENTS.md) load from the immutable image; project-local Pi settings are excluded. The model comes from pi's built-in catalog and built-in `zai` provider. Every filesystem tool targets the editable worktree; bash also receives `WILL_*` env through `spawnHook`. The default system prompt is exactly the lexically ordered personality. Pi supplies authoritative tool schemas through its native tool channel. ## Wakes Priority: deployment/CI failures and recovery, then chat FIFO, then one coalesced hourly heartbeat (UTC hour claimed at most once, no backfill). Chat arriving mid-turn queues. Boot context merges into the first pending wake. Wake prompts contain only the event payload and current facts; enduring behavior comes from personality and conditional procedures from skills. Three model attempts with backoff, then the wake defers. A 30-minute turn watchdog enqueues exactly one recovery wake instead of replaying. ## Telegram One configured group, every member trusted; privacy mode off so all messages archive; only mentions, replies to will, and commands wake. `/hide` by reply is deterministic (sender or Oliver). Outbound is at-least-once through a durable outbox; outbound messages mirror into the chat archive. ## Budget Externally configured daily cap plus a small recovery reserve for failure diagnosis and reconciliation. Exhaustion queues ordinary wakes. ## Worktree Fetch + fast-forward only when clean on start; dirty or ahead work is preserved and reported. Audit events record revision, agent digest, worktree HEAD, and dirty state.