Today's entry is about the plumbing behind the JADA ops stack — specifically, what happens when nobody's watching the terminal. Most of what we build for Sail JADA Charters runs on a schedule now: launchd timers on an estate Mac fire off headless Claude runs that draft follow-ups, check crew schedules, and decide what content gets published that day. The interesting part isn't the automation itself. It's the guardrails we had to write down explicitly once a human stopped being in the loop.
We formalized this as something we're calling the Mac Foreman: a recurring, unattended run with one job — do one meaningful unit of revenue-generating work per invocation, and do it completely. Not "start a draft and leave it half-finished." Completely, including the sends. Except — and this is the rule that took a full revision to get right — "sends" for anything client-facing never actually send. They land as files in a drafts directory. A human reviews and fires them off later through a separate, deliberate step.
That distinction sounds pedantic until you think about what "executed completely" means for an unattended process. If the definition of done includes hitting send on an email to a real guest, you've built a system that will eventually email the wrong person at 3am with nobody to catch it. So "done" got redefined: the deterministic parts of the pipeline (who to contact, what template, what timing) run all the way through, and the only thing that stays gated behind a human is the actual transmission.
The same pattern shows up in the publishing pipeline for daily content drops. We separated it into two pieces on purpose. A deterministic script — plain Python, no model calls — decides *what* gets published and *when*, based on rules anyone could read and audit. A separate headless Claude turn then acts as the executor: it reads that plan, calls the publishing tools, and records the result. Its instructions are explicit that it has no creative latitude. It's not there to have opinions about the plan; it's there to carry it out and report back honestly if a step failed.
This took a rewrite to get right too. Our first version let the "publish" step reason about the content on the way out the door, which sounds harmless but means every run is a new roll of the dice on tone and judgment calls that should have been fixed upstream. Moving all the judgment into a deterministic core and leaving the model with a narrow, mechanical job made the whole thing boring in the best way — which is what you want from something that runs on a timer while everyone's asleep.
Unattended agents earn trust by having less discretion, not more. Every time we've had a near-miss in this stack, it traced back to a step where a model was allowed to decide *and* act in the same breath, with no seam for a human or a script to check the work in between. The fix is always the same shape: push the risky decision into something deterministic and inspectable, and let the model's job be narrow — draft, don't send; execute a plan, don't write one.
Even JADA herself — the persona wrapped around guest-facing chat, an 88-year-old wooden yawl with strong opinions about being called a ketch — only gets to talk. She doesn't get to book anything. That boundary turns out to be the whole game.