What Runs Without You Asking
You describe the problem. Propel picks the mode, routes the skills, dispatches the subagents, and tells you what it did. The only thing it will not do on your behalf is decide.
The Automation Contract
A framework that requires you to remember /investigation before investigating, or a flag before wanting a second opinion, has moved the cognitive load it was supposed to remove. The trigger tables throughout these docs are instructions to the agent, not a menu for you.
Three rules follow from that, and they are the ones that decay first in a long session:
- Announce; don't ask permission for process. "Dispatching three investigators in parallel — call graph, config wiring, and the reward path." Not "would you like me to investigate?" Process belongs to the agent. Decisions belong to you, and those get a gate.
- Never wait to be told to dispatch. If the auto-dispatch table says an auditor applies, it runs. You find out from the narration, not from a permission prompt.
- If the agent catches itself writing "you can run X if you want" — it should stop, and run X.
Everything mechanical is Propel's job. Everything that decides what the experiment means is yours. That line is the product — see Who Decides What.
What Fires, and When
| Trigger | What fires automatically |
|---|---|
| Your first message | Mode selection, announced in one line with its reason |
| A new task | Gate 0 scoping questions, one at a time, then Q0 grounding |
| A question needing several files traced | Several investigator subagents in parallel, one question each |
| Findings assembled | Codex consult, then Gate 1 |
| Design complete | Codex consult, then Gate 2 |
| An approved plan | implementer, then spec-reviewer, one component at a time |
| Any source edit | A PostToolUse hook names the required auditors |
| An approved training command | trainer-operator, in its own context |
| A root cause identified | Codex consult, then Gate 4 |
| Three failed attempts | The 3-strike break: stop, and ask what assumption all three share |
| ~15 substantive turns | context-hygiene — update the README, suggest /clear |
| ~20 turns without one | retrospective suggestion |
Hooks: Mechanism, Not Memory
Propel used to say "auditors are auto-dispatched", which really meant "a skill file reminds the model to remember". Memory is not a mechanism, and it is the first thing to go thirty turns into a session.
Four hooks make the important parts deterministic, executed by the harness rather than recalled by a model:
| Hook | Event | What it does |
|---|---|---|
session-start.sh | SessionStart, PreCompact | Injects the core principles, the dual-model policy, the active mode, and any open investigations |
working-memory.sh | SessionStart, PreCompact | Injects past experiments and architectures so nothing gets re-proposed |
route.sh | UserPromptSubmit | Re-states the active mode, the Codex state, and six routing rules — every turn, so they don't decay as context fills |
auditor-dispatch.sh | PostToolUse on Edit|Write|MultiEdit|NotebookEdit | Looks at the file just written and states which auditors are now required |
The dispatch hook inspects the path and the file contents: silent-bug-detector for model / loss / data / training surfaces, jax-logic-auditor when JAX transforms are actually present in the file, env-researcher for environment wrappers, regression-guard for everything. It skips scratch/, .claude/, sessions/ and non-source files entirely.
Why Subagents, Not Just More Context
Every worker agent exists for the same reason: context is the scarce resource, and the work that consumes the most of it produces the least of the reasoning you actually need.
- An investigator reads forty files and returns eight lines with
file:lineevidence. The session gets the eight lines. - A trainer-operator absorbs thousands of near-identical log lines and returns a status card.
- A codex-bridge reads a long, confident, partly-wrong Codex reply, checks it against the repo, and returns only what survived.
The alternative — doing all of that in the main conversation — means that by the time you reach the design decision, the context is full of log tails and unverified claims, and the model is reasoning next to them. Hallucination risk grows with context. Spending someone else's context is the cheapest fix available.
What Never Automates
The list is short and it does not grow:
- Gate answers. Every gate question is disjunctive — "A or B, and here's what each costs" — and the pipeline does not advance until you answer. Never "shall I proceed?", which invites rubber-stamping.
- Q0 and Q1. These ask for reference implementations and binding implementation details. They are questions for you; a model answering them defeats their purpose. Codex is not consulted at either.
- Destructive or irreversible actions. Always explicit approval, in every mode.
- Anything that changes what an experiment measures. The
trainer-operatorboundary is the clearest case: it may fix a path or lower a batch size inside a range you approved; it may not touch the loss, the architecture, or the data pipeline. A run that dies in 30 seconds costs a restart. A run that trains for 18 hours on silently altered semantics costs the experiment — and produces a number someone might believe.
Overriding It
| Command | Effect |
|---|---|
/switch <mode> | Override the automatically selected mode. Marks it selected_by: user, which makes Propel ask before auto-switching away from it. |
/disable-codex | Single-model gates for this project. |
/intro | The full tour, including the four-mode menu, if you'd rather choose explicitly. |
/primer | Reload project context after a /clear. |
If you correct an auto-selected mode, Propel says so in one line — that's signal about where the inference went wrong, and it's worth seeing.