Yesterday's log is a good one, because it's the day the unattended runner and the "never send without a human" rule collided head-on, and the rule won.
A while back I wrote a directive for a recurring, unattended Claude run on the estate Mac — I call it the Foreman. Its whole job is one unit of revenue-producing work per run, done completely, no partial credit. Rev 2 of that directive removed me from the loop entirely: no "should I do this," just do it. That's a scary sentence to write down, so most of yesterday was spent making sure "do it" still has guardrails baked into the pipeline itself rather than into my judgment at 3am.
The guardrail that mattered: drafts are cheap, sends are not. Every skill that touches a guest, a crew member, or a captain — schedule texts, follow-ups, proposals — writes its output to a drafts folder and stops. Nothing dials out on its own. That's not a Claude preference, it's structural: the send step lives in a separate script I run by hand.
jada-ops/drafts/2026-08-31-crew-sms.txt # written ~/bin/send-sms # never called by the skill
Three things came off the belt: a crew schedule text pulled live from the DynamoDB dispatch table (confirmed charters plus open slots for one role), a captains' status update for the two skippers showing who's covered and who's still open, and a batch of post-charter follow-ups selected out of the guest ledger with review-request timing nudged by the photo pipeline. All three are the same shape underneath — deterministic script does the data pull and the templating, the model writes the two or three sentences that need judgment, nothing leaves the Mac unreviewed.
Separately, JADA's own content — the boat's voice, her naval-history column, her daily social slot — runs through a "publish executor" pattern: a headless, plan-billed turn gets a slot name (pulse, tee, archive, es) up top and instructions below, and it has to figure out which slot it's standing in before touching anything. That's a small thing that bit us once already: a prompt that doesn't pin its own identity clearly enough will happily execute the wrong slot's instructions. The fix was boring and correct — first line of every prompt is the slot, every command in the body echoes it back, so a misfire is loud instead of silent.
The interesting failure mode with an unattended agent isn't that it does nothing — it's that it does something, confidently, in the wrong direction, and nobody's watching. The defense isn't "make the model more careful." It's remove its ability to cause damage in the first place: drafts instead of sends, deterministic scripts for anything with a data contract, and the model boxed into the narrow slice of the task that actually needs language judgment. Rev 2 of the Foreman directive reads like I trust it more. What actually changed is I trust the pipeline more, and the pipeline doesn't need me to trust the model at all.