1. Keep Lex boring and dependable.
Lex remains the public memory and policy substrate: stable CLI behavior, useful MCP coverage, deterministic JSON, local SQLite, and better instructions generation.
Lex and AXF are usable today. LexThority is now public as the authority preview. LexSona and LexRunner remain controlled while the behavior and containment boundaries settle.
The near-term work is not another prompt pattern. It is the layer that lets agents remember, discover workspace capabilities, ask for authority, inherit behavior, and coordinate bounded work.
| Project | Status | Package | Source |
|---|---|---|---|
| Lex | Public MIT core for memory, policy, recall, instructions, CLI, MCP, and API. | npm latest | GitHub |
| Lex MCP | Public MCP wrapper for Lex surfaces. | npm latest | NPM package |
| AXF | Public source-available alpha for workspace capability contracts. | npm latest | GitHub |
| LexThority | Public source-available preview for authority envelopes and effect receipts. | Not published on npm yet. | GitHub |
| LexSona | Controlled-access behavioral constraint engine. | Not public npm. | Concept page |
| LexRunner | Controlled-access flow layer for gates, receipts, containment, and swarm-ready coordination. | Not public npm. | Concept page |
Lex remains the public memory and policy substrate: stable CLI behavior, useful MCP coverage, deterministic JSON, local SQLite, and better instructions generation.
AXF should make local repo know-how discoverable and runnable without turning every capability into raw shell improvisation. Expect more adapter examples and lifecycle hardening.
The authority layer should classify attempted effects, evaluate them against envelopes, and produce allow, escalate, or deny receipts without pretending to replace enterprise IAM.
LexSona should return deterministic behavioral constraints. LexRunner should consume those constraints, not become the persona engine.
Parallel agents need contained, worktree-like execution roots, per-agent envelopes, explicit mounts, and gated promotion back into canonical work.
Analyst, product, support, security, and operations workflows should use the same surfaces: memory, capability, authority, behavior, flow, and receipts.
The stack should cooperate with OAuth, cloud IAM, GitHub permissions, and enterprise security tooling. It should not invent a shadow identity provider.
When a credential, policy, or tool blocks work, the agent should be able to tell an operator what was attempted, what failed, and what permission or action is needed.
The goal is bounded agency, not bureaucracy. Agents should reason freely inside a workspace while effects are gated, receipted, and recoverable.