Architecture decision ยท Accepted
ADR-0001: Role agents live in the company repository, not in a platform
Context. The enterprise project builds its workforce in Microsoft Foundry because the organisation already runs on Microsoft and the data never leaves it. Blankitt has no such constraint, one engineer, and a monorepo of twenty-five sub-repositories. The operating team needed to read that code, those documents and those databases directly, and it needed to exist before the first customer, not after a platform rollout.
Decision. Each role is a markdown file committed to the monorepo: a system prompt, a tool allow-list and a model choice. Repeatable procedures are slash commands in the same repository. Shared facts live in one file every role reads first. Agents never commit, deploy, send or write to production; those actions are reserved for the founder and enforced by tool lists and a pre-command hook. Scheduled runs use the committed files, because the scheduler can only load what is in the repository.
Consequences. The workforce is versioned with the code it operates on, so a change to a role is a diff someone can read. The cost is a fixed subscription rather than metered tokens, which makes the cost line boring and the comparison with the enterprise project less direct. The founder remains the only actor with side effects, which is the governance model, and also the bottleneck the Monday page is designed to expose.