Reference experience · candidate

Say what the company needs. Keep every consequential step visible.

The intended experience is conversational at the edge and deterministic at the boundary. The founder explains the outcome; the system turns it into a plan, explicit authority, observed actions, and a recoverable operating state.

founder request / 09:14

Set up and run the software for my small company.

plan before action

The complete future journey

From intent to an owned operating environment.

The broad journey is the product north star. Plane Steward implements only its first one-application slice.

  1. 01understand

    Ask only what changes the system.

    The operator gathers company profile, required capabilities, jurisdiction, data classes, human authorities, recovery targets, external dependencies, and cost ceiling. It does not begin with an app marketplace.

  2. 02propose

    Show a right-sized plan.

    The founder sees applications, pinned versions, resources, expected recurring cost, license constraints, data flows, backup and recovery design, and explicit omissions before any deployment.

  3. 03approve

    Separate consent from enthusiasm.

    An approved profile authorizes only its declared boundaries. Production releases, external messages, financial commitments, destructive actions, and new data egress can retain their own human gates.

  4. 04manage

    Operate the applications over time.

    The system provisions or adopts each payload, observes effective state, repairs approved drift, backs up authoritative data, prepares upgrades, and proves recovery. A healthy container is not enough.

  5. 05customize

    Change the software around the work.

    The founder asks for a business outcome. Trellis produces a versioned app-specific proposal, validates it in isolation, previews the visible effect, applies it under authority, and retains rollback or compensation.

  6. 06operate

    Let people and agents work through the same rules.

    A customer message can link to work, code, preview, approval, release, and response without erasing which application owns each record. Local agents receive scoped capabilities and relevant context, not blanket credentials.

  7. 07leave

    Prove the company can recover or leave.

    A clean recovery exercise rebuilds identity, grants, secret access or reauthorization, domains, payload state, policies, and action evidence. Export declares what moves, in which format, and what still cannot.

What you can build first

Compress the journey around one Plane project.

For v0.1, `set up my company` becomes `adopt this Plane service and make this one project dependable`. That still exercises plan, authority, lifecycle, customization, daily agent use, recovery, and exit.

1Observeno writes
2Declareone project
3Reconcileapproved diff
4Useagent packet
5Recovertested exit
See the exact v0.1 boundary

What stays inspectable

Every changed thing leaves a useful receipt.

A receipt is not a model transcript. It is the durable record required to understand the actor, intent, target, authority, result, and causal chain of an operation.

example action receiptproposed
Illustrative · no Plane action occurred
intent
add customer priority to work
capability
work.configure_field
target
plane / studio-project
authority
candidate / reversible
acceptance target
observable · receipt generated only after live proof

Human altitude

The founder should decide policy and outcomes—not perform routine glue work.

System handles
  • Read-only discovery
  • Context assembly
  • Health and drift checks
  • Backup scheduling
  • Idempotent safe retries
  • Evidence collection
Founder decides
  • Company profile and omissions
  • New data egress
  • Production and external effects
  • Irreversible changes
  • Accepted cost and recovery
  • When to add the next payload

Reality check

The journey is designed.
The real payload proof is not.