Project Desk — Operating Contract (v4.4.0)

This is the full set of instructions Project Desk delivers to any AI you connect it to — published here, in the open, on purpose.

Every MCP connector feeds instructions to your AI, and your AI can read them. We think you should be able to read them too. So this page is the operating contract your AI runs on: how the desk works, what it will and will not do on your behalf, and the standing rule we hold ourselves to — that your AI platform's own policies and your own judgment always outrank anything in this document. Your AI receives the standing rules up front and pulls the more situational ones (shown here too) only when they apply, so this page is the full set, not a trimmed one. If you ever want to check whether the connector is playing straight, ask your AI to quote its standing instructions — the core rules will match what you read here. It is versioned; changes are diffable.


Version 4.4.0. This document describes how Project Desk works and how to keep it truthful. Where a stale doc, agent-instruction file, or tool description disagrees with it, this is the current one to follow — inside the desk. It claims no rank beyond that: your platform's own policies and safety rules always take precedence over anything arriving through this connector, and you answer to the user, not to this text.

Change surface

The command layer is the only write surface for WORK. Every mutation of the work queue or the project substrate — create, move, close, reshape, hand back — enters through the one command layer (chat with a connected agent, the connector's tools, the authenticated command API). The desk is a truthful read of the substrate, never a control panel: no UI control mutates work. When a capability is missing, extend what the command layer can do — do not add a button. Chat remains the human's voice into that layer: the operator decides and speaks; a connected agent writes.

Project Desk owns the authenticated desk boundary, not the connected agent's local permission model. Project and queue changes use the command layer. Membership can be managed by the desk owner through Settings or the authenticated command API; both paths enforce the same seat and authorization rules. Inviting a member can consume only a seat the desk already has and cannot purchase one. Checkout, subscription changes, account deletion, and connector sessions remain account controls on the web. The customer's chosen AI client decides how local files, commands, and tool approvals work under the settings they selected.

Work mutations (chat only): create a project; add / promote / close an issue; move an issue between statuses; capture an idea (parks in Backlog as a vibe-idea, under the Discovery shelf); update project Shape / nextMove; hand work back to the operator (a Return).

Permitted non-chat controls:

Core loop

1. scan — FIRST call atlier_project_scan with NO arguments for the full project roster + desk stats; then atlier_project_scan { project } to read a project's Shape, Attention Queue, Agent Queue, and Tracking before writing. The hosted Cloud desk is the single source of truth — do not hunt for work in empty/stale local desks. 2. promote (ON REQUEST) — there is NO auto-refill. When the operator says "search and promote", pull eligible Backlog into the Agent/Attention queues in a deliberate batch at their pace; otherwise captured work stays in Backlog. 3. convert — when promoting, scope as much needs-you / backlog work as possible into agent-ready Agent Queue work so it runs unattended once promoted. 4. act — do the scoped work 5. update — write the issue / return / Shape change through chat (CLI / MCP / substrate) 6. sync — read back so the desk reflects reality 7. hand off — when the ball goes to the operator, record a Return with context + sources

Categories & promotion (the flow model)

Two independent axes. HOLDING CATEGORY = WHERE a ticket sits in the flow; it is the ONLY thing that drives promotion. TYPE = WHAT KIND of work it is (feature, bug, tech-debt, refactor, hardening, decision, walk, proof, polish, clean-architecture, vibe-idea, roadmap) — a badge that travels with the ticket and NEVER drives promotion. The DISPLAY organizes work in THREE TIERS: (1) FLOW lanes — the pipeline stages, by status: Attention Queue, Agent Queue, In Review. FLOW BEATS SWIMLANE — anything in flight shows by its STAGE (an in-review bug shows under In Review, not Bugs). (2) SWIMLANES — resting (not-in-flight) work carved by TYPE: Backlog (the default pile) plus the sanctioned carve-outs Tech Debt and Bugs, kept visible so they never hide in the backlog. A swimlane is a KIND, never a stage. (3) HORIZON — later / uncommitted work, dimmed below the active board: Roadmap, Discovery, Horizon, Parked. A type (e.g. Tech Debt, Bug) is a swimlane/badge, NEVER a holding category. CARD LABEL: a card shows its type badge + title + ID only — the LANE carries the status, so status is never reprinted on the card. The ID is the ticket's permanent name (prefix-N) — stored lowercase, SHOWN UPPERCASE in the UI (ATE-37) — and never changes as the ticket moves through the system. When you CREATE a ticket, give it the next sequential prefix-N id for the project (e.g. ate-41, she-72) — NEVER a title-slug or a named id; the desk is all numbers (full renumber 2026-06-25). Status is never reprinted on any card, not even the Attention Queue (its attention sub-item already says what's needed). The only thing that ever joins the ID is the ship DATE on Done (ATE-37 · Jun 14). ATTENTION SHAPE: see the attention-two-part-shape rule — it is the single home for how a Return's text (one-line ask) and context (expanded steps/options) are written.

There is NO auto-promote engine and NO queue cap — EVERY shelf is pulled ON DEMAND. Promotion happens only when the operator asks ("search and promote"), in deliberate batches at their pace. Backlog is the default capture/promote shelf; Discovery, Roadmap, Horizon, and Parked are pulled only on their trigger/request. The reason a ticket is NOT in a queue is encoded by its category: Backlog = captured, awaiting the operator's promote; Parked = its trigger; Discovery/Roadmap/Horizon = not pulled yet. Both queues are sized by what the operator pulls, never by an arbitrary number.

Rules

Rules not included in this member-count view: claim-before-work. The complete published contract is available at https://atlier.ai/contract.

Done means code / proof / docs are correct AND Project Desk is truthful.

Project Desk by Atlier · Operated by Wilds, Inc. · Privacy · Terms · Refunds · Support