The CodeBook governance handoff
When a CodeBook workspace is linked, Madebook is where governance lives and CodeBook enforces its answers at the moment it acts — model checks before a run, one verdict on the pull request, ending a session from CodeBook, provisional CodeBook evidence, one audit trail, and who a run was started for.
This is Madebook's half of the contract in the application's docs/PEER-PROTOCOL.md, section 5. CodeBook's half is built separately against the same contract. An unlinked CodeBook workspace behaves exactly as it does without Madebook; nothing here applies to it.
Every call below uses the workspace credential a link issues (see Linked products).
Approved models: ask before, report after
Before a governed run's first model call, and whenever the model changes, CodeBook asks POST /supervision/api/agent/model-check with the session, provider and model. The answer is allowed, or refused with the reason.
- The answer applies the organization's approved providers and models and any policy allow-list exactly as Madebook's own AI calls are judged. The usage report after the call (
/agent/run) is judged by the same function, so the answer before and the judgement after cannot disagree. - A refusal is recorded as a violation and on the session timeline. An allowed answer records nothing.
- If governance cannot be read the answer is 503, never "allowed". CodeBook holds the run and asks again.
- If refused, CodeBook stops the run and says so on the card. It never swaps to another model silently.
/agent/runtakes an optionalrun_idso a retry after a lost answer is a no-op. The timeline logs only model changes and failures, so reporting every call does not bury the decisions a person reads it for.
One verdict on the pull request
CodeBook's own "CI checks passed" evaluators ignore every check whose name starts with madebook/. Whether a pull request may merge is Madebook's verdict; CodeBook receives it in a callback and shows it on the card. It does not re-derive it.
Ending a session from CodeBook
When a governed run ends in CodeBook for any reason other than finishing normally — cancelled, kill switch, card moved, failed, superseded, emergency revoke — CodeBook calls POST /supervision/api/agent/end with a reason code and an end_id that makes the call idempotent. Only the link's own credential may do this.
Madebook then ends the session as ended (a new status, with who ended it and why), withdraws its open decision gates so they leave Attention and Decisions, cancels callbacks still waiting for it, closes its collisions, writes session.ended_by_peer to the audit trail, re-evaluates its pull request and sweeps Attention. An ended session refuses status reports, model checks and re-registration under the same id.
Unlinking ends a link's live sessions the same way, recorded as session.ended_with_link. A factory pause is not an end; it is reported as blocked and resumed as working.
Workspace and organization Live agents list sessions ended by the product running them in the last 24 hours; the session page shows an ended callout with the reason.
Finishing: CodeBook's checks first, then Madebook
CodeBook runs its own station contract and evaluators first, and only then reports to Madebook — with the files, the dependencies the change added (read from the package manifests it touched, so dependency rules apply), and one evidence entry per contract check and evaluator.
Madebook records that evidence as reported by CodeBook — labelled CodeBook reports — provisional on the capsule, session, mission and pull request pages. Like any evidence a session reports about itself, it counts toward nothing until CI or a person confirms it. The two CodeBook evidence kinds are accepted only from a session registered with a CodeBook link's credential; anything else sending them is refused. The pull request page gains a What its session reported panel.
One audit trail
For a linked workspace, CodeBook sends its governance events — run approved or rejected, an override past a failed check, permission and policy changes, kill switch, emergency revoke, factory version published or rolled back — to Madebook's sealed audit trail. They are written like any other event, so they are sealed, streamed and exported with the rest, and show as CodeBook in the Audit page.
The link is checked, not trusted: a spoofed link or peer is refused and the event is retried rather than lost. The nine event names are allow-listed; unknown names are acknowledged and ignored. The actor is resolved to an account id and nothing else about them is stored.
Retention
CodeBook reads the organization's telemetry mode, prompt retention and code retention from Madebook (GET /supervision/api/agent/settings) when the credential is issued and daily after that, and applies them to the bodies its runs store. If the settings cannot be read the answer is 503, never the defaults, so CodeBook keeps applying the last settings it read. See Telemetry and retention.
Who started it
A run started by a person — moving the card, approving it — registers with acting_for, naming them. Madebook checks, live from Bookbag, that this person may register sessions and write in the workspace; otherwise the registration is refused. Only a CodeBook link's credential may send it; a person's own token acts for that person and nobody else.
The session is then started by that person, and the credential's owner is recorded as how it was registered — the session and pull request pages say started by X via CodeBook. This is what separation of duties is judged on: the person who started a session cannot review its capsule under strict review. A run with nobody behind it (a schedule, an inbound event) is started by the credential's owner.