The attention queue
The one list of things that need a person, every rule that can put something on it, how it is ordered, and what clears an item.
The attention queue is one list of things that need a person, ordered by what it costs to ignore them. It is not a feed. Every item on it is computed from something recorded — a symbol that moved, a clause that was broken, a session briefed before a decision existed.
You reach it in two places:
- Workspace → Attention (
/workspaces/<id>/control) — one workspace's queue. - Organization → Attention (
/organizations/<id>/attention) — every workspace you can reach, grouped by workspace, with filters for workspace and disposition.
Why it works the way it does
The failure mode of an attention system is not missing an item. It is crying wolf until people stop reading it. A queue that is wrong a fifth of the time is worse than no queue at all: it costs the same attention it was built to save, and adds the insult of having promised otherwise.
Three rules hold throughout.
- Five dispositions, and most things are not the top three. A system that only knows "notify" ends up notifying about everything.
- Nothing reaches review, decide or intervene on a guess. Those three are for facts Madebook computed — a collision found by a join, a clause the verifier found violated, a deviation matched against a package list. A model's suspicion can produce an
inform, and the item says so. - Every item names the thing and the next move. "Agent 04 created a second authorization pattern" is actionable. "Review needed" is a notification, and notifications are what people already drown in.
The five dispositions
| Disposition | Meaning | Order |
|---|---|---|
intervene |
Something is wrong now and a person has to step in. | 1st |
decide |
A question is waiting on a person's answer. | 2nd |
review |
Worth a person's eyes before it goes further. | 3rd |
inform |
True and relevant. Nobody has to act. | 4th |
ignore |
Recorded and deliberately not surfaced. | 5th |
The queue sorts by disposition first — intervene always first — then by the item's urgency score.
Every rule that can raise an item
Each item carries the name of the rule that produced it, so a noisy queue is diagnosable rather than merely annoying. These are all of them.
| Rule | Disposition | Urgency | Fires when |
|---|---|---|---|
source_done |
review | 62 | The tracker moved a source item to done or cancelled while the mission here is still open. |
architecture_conflict |
decide (confident) / inform | 78 / 40 | A change introduced something that departs from an architecture rule. decide only when the rule is confident. |
cross_agent_collision |
(see below) | 95 high / 65 | One session changed a symbol another session is standing on. |
ready_to_ship |
review | 55 | A mission's contract is satisfied and its evidence gate is met. |
contract_violation |
intervene / decide | 90 / 72 | Verification found violated contract clauses. intervene when a forbidden clause is among them. |
context_stale |
intervene | 88 | A live session's context health has fallen far enough that it is working from a stale picture. |
high_risk_change |
review | 85 critical / 68 | A change set's risk assessment landed in a high or critical band. |
constitution_unapproved |
decide / inform | 70 / 30 | The current architecture rules are a draft nobody has approved. decide when sessions are live against them. |
policy_violation |
intervene / decide | 92 / 75 | An open policy violation. intervene at critical severity. |
session_failed |
inform | 30 | A session stopped without finishing. |
agent_question |
decide | 80 | A session is blocked and waiting on a person. |
decision_required |
decide | 86 / 74 | An open decision gate. 74 when the agent still has allowed scope to work on; 86 when it has nothing left. |
remediation_outstanding |
inform / review | 35 / 60 | A remediation request is outstanding. review once the session is no longer live to act on it. |
evidence_missing |
review / inform | 55 / 35 | The contract is satisfied but evidence requirements are not. review when a requirement needs a person. |
provider_refused |
inform | 30 | A session tried a model the organization has not approved. |
decision_proposed |
decide | 45 | A decision proposed through the MCP is waiting for a lead. |
source_changed |
decide / inform | 60 / 30 | The source item behind a mission changed or was deleted after the contract was written. |
mission_questions |
decide | 45 | A mission has open product questions that must be answered before its contract can be approved. |
plan_proposed |
decide | 70 | An agent proposed an execution plan for a high-risk mission. |
A collision's disposition depends on its severity: a high severity collision carries urgency 95, everything else 65.
What an item contains
| Field | What it holds |
|---|---|
headline |
The thing, named. For example: "DEC-002: which expiry applies to invitation tokens?" |
body |
Why it fired and what the next move is. |
disposition |
One of the five. |
urgency |
0–100. Defaults to 50 when a rule does not set one. |
kind |
The rule's category, for filtering. |
rule |
The rule's name, exactly as in the table above. |
determined_by |
computed for a fact. Anything a model suggested says so. |
subject_type / subject_id |
What it is about — a Mission, a Session, a ChangeSet. |
occurrences |
How many sweeps have seen it. |
fingerprint |
The identity that makes repeat detections one row instead of many. |
Sweeps, fingerprints and supersession
The engine runs as a sweep over one workspace. Rules are pure functions of state, so running the engine twice changes nothing.
- Every candidate item carries a fingerprint derived from what it is about. A collision detected on six consecutive sweeps is one row with
occurrences = 6, not six rows. - The sweep is a reconciliation, not an insertion. An item whose rule no longer fires is marked
supersededrather than left to rot. A queue that only ever grows is a queue people stop opening, and stale items are worse than none because they make the reader distrust the fresh ones. - Escalation is allowed; de-escalation of an open item is not. If a rule fires again with a more severe disposition, the item is raised and its headline and body are replaced. If it fires with a less severe one, nothing changes — something a person has already been told is serious must not quietly become less serious underneath them.
- One broken rule cannot take the queue down. A rule that throws is logged and skipped. A queue missing one class of item is degraded; a queue that throws is absent, and absent is what people plan around.
Clearing an item
Resolving an item in Madebook does not only hide the row. Where resolving should change the underlying fact, it changes the fact — otherwise the next sweep raises the same item again. A resolution that cannot change the fact leaves the item until the fact changes.
The honest way to clear most items is to deal with the thing they name:
| Item | What actually clears it |
|---|---|
decision_required |
Answer the decision gate with a resolution and an instruction. |
plan_proposed |
Approve or reject the execution plan. |
constitution_unapproved |
Approve the architecture rules. |
decision_proposed |
Record or reject the proposed decision. |
policy_violation |
Resolve or waive the violation. |
evidence_missing |
Supply the missing evidence. |
source_done |
Ship or abandon the mission. |
ready_to_ship |
Ship it. |
Related
- The execution protocol — what an agent is told while an item sits open.
- Changes and review capsules — where a
high_risk_changeitem sends you. - Violations — where a
policy_violationitem sends you.