## 10\.&#32;Protect context and recover

### A tangent is not a privacy boundary

A tan can inherit conversation content that has nothing to do with its narrow assignment\:

- Prior user and assistant messages\.
- Tool results and file contents\.
- Previously attached images\.
- Instructions or memory\-derived content already present in the inherited context\.

It can also access the shared workspace through its available tools\.

Before launching\,&#32;consider whether the inherited content is appropriate for the model\/provider and tool access involved\.&#32;A narrow task prompt does not remove unrelated inherited information\.

Do not assume that Main’s extension\-based safeguards or interactive approval prompts are reproduced identically\.&#32;Verify protections that matter before unattended work\.

This public workbook never needs your real transcripts\,&#32;credentials\,&#32;or private instructions\.

### Cost\:&#32;concurrent does not mean free

A tan can add model requests\,&#32;tool work\,&#32;retries\,&#32;and auxiliary model activity while Main is also active\.

The initial controller copies Main’s effective prompt\-cache routing key while giving the child a separate provider request lineage\.&#32;That creates&#32;**eligibility for provider cache reuse**\,&#32;not a cache\-hit or savings guarantee\.

The supplied mock\-provider proof reported zero usage by design\.&#32;Those zeros are not pricing evidence\.

Also be careful with transcript\-derived totals\:&#32;a fork includes historical messages and their usage records\.&#32;Such totals are not necessarily the tan’s incremental new spend\.

### Shared scratch space and artifact boundaries

During its initial run\,&#32;the tan uses a captured mapping to Main’s&#32;`local://`&#32;scratch root\.&#32;A file such as&#32;`local://lantern-label-audit.md`&#32;can therefore be shared with Main\.

The Tan transcript is nested in the parent session’s artifact tree\,&#32;and the launch does not recursively copy that tree\.

But sharing&#32;`local://`&#32;does&#32;**not**&#32;mean every artifact allocator is identical\.&#32;The initial controller does not adopt Main’s&#32;`ArtifactManager`\;&#32;tools can create child\-session artifacts\.&#32;The cold reviver\,&#32;in contrast\,&#32;adopts the current Main artifact manager\.

Use paths and links actually returned by the tools\.&#32;Do not construct guessed artifact IDs or assume that all resources keep the same mapping after Main moves or a tan is cold\-revived\.

### Compaction preserves intent only within its actual wiring

During the initial background run\,&#32;the Tan controller reasserts the fork boundary after successful reported compaction\.

That is a useful guard\,&#32;not a guarantee that every later revived conversation carries the same live reminder machinery\.&#32;After compaction or revival\,&#32;a concise restatement of scope and ownership is a sensible operating practice\.

### Recovery guide

| Symptom | Check | Recovery |
| --- | --- | --- |
| “I cannot find it in&#32;`/jobs`\.” | Did the job expire\?&#32;Is it owned by another agent\?&#32;Is this a revived\,&#32;jobless prompt\? | Check the live and parked roster and&#32;`history://`\;&#32;do not guess a new job ID\. |
| “Hub list says no actionable peers\.” | Are there parked peers\?&#32;Is the list truncated\? | Request the parked filter and inspect counts\;&#32;use the runtime Hub for further inspection\. |
| “The row says running\,&#32;but nothing seems active\.” | Is startup still wiring up\?&#32;Does live session activity corroborate the status\? | Inspect current state and history before treating it as a stale registration\. |
| “My correction did not affect the answer\.” | Was the right Tan focused\?&#32;Was it queued\,&#32;processed\,&#32;or submitted after auto\-return\? | Locate the message in the correct transcript before resending\. |
| “I got returned to Main unexpectedly\.” | Did the focused tan park\,&#32;become aborted\,&#32;or disappear\? | Recheck both state tracks and the draft recipient\. |
| “The command was refused in tan chat\.” | Did the draft begin with slash\,&#32;shell\,&#32;or Python command syntax\? | Preserve it if needed\,&#32;return to Main\,&#32;and perform only the intended Main action there\. |
| “An image was missing\.” | Was it staged beside&#32;`/tan`\,&#32;or sent later as an actual focused attachment\?&#32;Was image input allowed\? | Attach explicitly to the verified tan\,&#32;or provide an authorized accessible file\. |
| “The report disappeared from later job snapshots\.” | Was it already auto\-delivered or recovered\? | Read the earlier result\,&#32;actual artifact link\,&#32;or transcript\. |
| “Revival failed\.” | Transcript\,&#32;saved contract\,&#32;workspace\,&#32;runtime factory\,&#32;model\/auth\,&#32;and tool dependencies | Repair the actual dependency\;&#32;otherwise use retained history to prepare a new tangent\. |
| “I cancelled it\,&#32;but a parked row appeared later\.” | Was this job cancellation or plain release rather than explicit tombstoned kill\? | Reconcile the transcript and lifecycle\.&#32;Use explicit kill if terminal intent is still required\. |
| “Stopping it did not stop a server\.” | Was the server a separately supervised or external process\? | Discover and control that process separately\;&#32;verify ownership first\. |
| “A test failed during concurrent edits\.” | Did another worker change the tested files or dependencies\? | Establish a stable input point and one writer\,&#32;then rerun the relevant check\. |

### Restart and retention are not the same as live control

Source supports discovering retained child transcripts under a session’s artifact tree and rebuilding eligible parked agents\.&#32;It does not mean a running Tan keeps executing through an OMP process exit\.

Discovery also has boundaries\:

- It is tied to reachable session roots\,&#32;not an unlimited search of every file on the computer\.
- Saved\-agent scans and metadata hydration can fail or be incomplete\.
- A long inherited transcript can place Tan\-specific initialization beyond the small prefix used for roster metadata\.
- A row’s preview may therefore be missing or insufficient to identify its assignment\.
- File existence alone does not prove a live\,&#32;controllable agent\.

The supplied runtime proof exercised cold revival&#32;**without proving restart rediscovery**\.

Transcripts remained on disk at the proof’s observation points\.&#32;That is not permanent retention\.&#32;Session deletion\,&#32;artifact cleanup\,&#32;archive\/GC policy\,&#32;storage errors\,&#32;and loss of image\/blob dependencies can change later availability\.&#32;The supplied evidence does not establish a guaranteed retention period\.

Completed journal entries and in\-flight streaming text also have different durability\.&#32;Do not assume an abrupt exit preserves every partial token\.

### Optional detail\:&#32;do not borrow ordinary\-task recovery settings blindly

The initial Tan controller does not run through the ordinary task executor’s full driver\.

In particular\,&#32;do not present these as established controls for the initial Tan\:

- `task.maxRuntimeMs`&#32;as its automatic wall\-clock stop\.
- `task.softRequestBudget`&#32;as its run budget\.
- `task.agentIdleTtlMs`&#32;as a way to prevent its immediate completion parking\.
- `task.isolation.*`&#32;as automatic&#32;`/tan`&#32;isolation\.
- Agent\-definition model overrides as a live Tan model selector\.

Those settings have uses elsewhere\.&#32;Their existence does not establish the same behavior in&#32;`TanCommandController.start()`\.

---
