Defined roles
Ten specialist roles, from architect to validator, each with a written definition of what it may and must not do, and two coordinator roles that plan and oversee them.
Case study · Magnolia Orrery
AI agents do much of our building. Magnolia Orrery is how they work as a team: defined roles pinned to reviewed definitions, one identity per run, signed commits that name their ticket and session, and a record of every action they take.
IRIS (Integrated Reasoning & Intelligence Steward) is our planning assistant. The scoping page saves your answers to your own computer as a file, then offers a link to email them to us.
The problem
An AI agent can write a great deal of code quickly. Without structure, nobody can say afterwards which agent did what, under which instructions, or whether the account that wrote a change also approved it.
A transcript is not a record. It ends with the session, and it does not say what was checked or what could not be verified.
What we built
Ten specialist roles, from architect to validator, each with a written definition of what it may and must not do, and two coordinator roles that plan and oversee them.
Each role file is pinned by a fingerprint. An agent whose definition has changed since it was last reviewed is refused.
A run acts under exactly one role identity. The account that pushes a change cannot approve it, so nobody approves their own work.
Every tool call and dispatch is written as it happens to an append-only, hash-chained ledger, and every commit is signed and names its ticket, session and workspace.
How we built it
Each rule starts as a numbered decision record that names what enforces it, or says that nothing does yet.
How we were asked to work is kept as numbered conventions, each saying how it is enforced.
Gates check the role fingerprints, the signatures and the record on every change, and a run confirms its own identity by probe rather than by assertion.
The result
Measured 6 October 2026, from our main engineering repository as it stood that day.
Describe your systems, your reports and where the time goes on the IRIS scoping page. You keep a copy, and an engineer reads it before we talk.