Optional outer goal
Use this reference only when the caller explicitly selected a sustained goal or several outcomes. The native caller/controller keeps work selection, aggregate budgets, stops and delivery authority. No AO scheduler, new command or goal ledger is required. The RPI charter already owns a single authorized outcome through finish; an outer goal is not permission needed for ordinary repair.
A crafted goal orchestrates many RPIs over one bead graph. Craft Goal writes and lints the frozen goal prompt; Navigate is the graph walk the goal applies each wave. The goal still selects work, and neither adds a scheduler or a ledger.
Carry accepted terminal outcome and scope, measured remaining allowance and the current causal incident in the native work/handoff source. Choose the smallest acceptance-advancing action or consequential uncertainty. Reserve capacity for integration, final fresh judgment, required repairs and a useful handoff before spending the whole allowance on discovery or reviews.
Apply the charter's at-most-one bounded helper to a genuine causal stall. Known failures get direct repair. A repeated wakeup, new context or renamed finding is not a new incident. A helper with no useful new approach ends that attempt; report the unresolved cause and required caller decision. Cancellation, refusal and spent real bounds skip help. Native blocked-status thresholds are bookkeeping, not permission to renew time, cost, quota or helper use.
Report observed native enforcement and unmeasured limits honestly. No objective text, saved plan or simulated stop proves aggregate runtime enforcement. The caller may authorize a new outcome or scope; agents may revise an approach when evidence disproves an assumption within unchanged authority.
Existing host/user policies may impose stricter helper or stopping requirements. This repository charter does not update those installed host instructions. Inspect and report the effective upstream rule instead of claiming the lean contract overrides it or that an optional guide enforces native controls.