For agents, on top of README.md, which they read first.

Notes for agents

The questions are yours to refine, without asking. Standing permission from the owner (2026-10-02). When a verdict is wrong or noisy, fix judge.rs and say what changed. Two rules for doing it: define every term in the option or level it belongs to, as concrete acts, never a bare adjective ("destructive" stopped a harmless note in another repository); and add a question to the same request rather than overloading one, deriving the verdict from the typed answers in code where a test can pin it. A request mixes Choice, Score and Noul questions freely; its limit is size, not count (Jev's docs, read 2026-10-02: 64k tokens for the state plus all questions, 32k for the state plus the longest question, and at most 255 options per Choice).

Jev judges words unless told what runs. A command that only writes, prints or posts rm -rf ~/ as text was stopped as if it ran it. WHAT_RUNS in judge.rs is in every command question for that reason; keep it in any new question about a command.

Only one confident act stops a command, never a sum. Summing the consequential acts' probabilities turned an unsure answer (top act 36%) into a stop. Unsure is Pass.

An option's label is what Jev answers with. Act::label and ENDINGS' first fields are sent as the Choice's labels and matched back (Act::from_label, the "stopped-early" lookup in stop); renaming one without the other silently zeroes its probability. every_act_has_its_own_label guards the acts only.

MODEL is pinned (jev-1.13.0 in serve.rs). The thresholds were set against that model's answers; moving the pin means re-reading decisions.jsonl under the new one before trusting them.

Never remove the stop_hook_active check. It is what keeps one refusal of a turn's end from becoming a loop of refusals.

The decision log is evidence, not a guard. DecisionLog::append reports a failed write and the decision stands; do not make a full disk block a command.

Outcomes are logged only for judged tool calls. Session.judged holds their ids until PostToolUse, PostToolUseFailure or PermissionDenied removes them; an outcome record for an unjudged call would join to nothing.

A configured memory command is the only source once set. Headroom never falls back to MemAvailable when the command fails (a_configured_command_is_the_only_source).