* OpenErrand 0.1: an errand on a website with no API, with the human steps kept human
docs/openerrand.md mints OpenErrand: one JSON file per errand (register an
account, download a transcript) naming the site, the inputs with a
sensitivity class and ordered sources (document, vault, prompt, generate,
derive, candidate, literal), field rules matched by id then label, page and
wait steps, five human gates a runner never performs (declare,
identity-proofing, code, mail, captcha), outcomes, the never-retried shared
secret, vault and download outputs, hand-off cards that may name only public
inputs, the publisher index at /.well-known/openerrand.json, and thirteen
runner rules. The worked example is the MyFTB business registration that
cli-tools `ftb` performs (profullstack/cli-tools#125), with no personal data.
- @logicsrc/schemas: openerrand + openerrand-index schemas and fixtures
- @logicsrc/validators: semantic checks (references, templates, no personal
or secret input on a card) and tests that validate the spec's own examples
- logicsrc-web: registry entry (process family), /openerrand landing page,
the example and the index served as static files, contract tests
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* OpenErrand: hand-off cards stay on the surface that owns the data
Anthony's ruling: tax and finance data never touches a social or promotion
tool, and nothing is sent to a CPA or preparer.
- Hand-off cards are delivered only on the surface that owns the errand's
data (for a tax or finance errand, the principal's finance app through its
CLI, PWA, MCP server or API, such as CoinPay, or the runner's terminal),
never a social, promotion or third-party posting service, and never to
anyone but the principal. A card for an errand with personal or secret
inputs does not leave that surface. Runner rule 9 says the same.
- The run record and the sample run name the card by an opaque id
(pin-letter/7f3k2q) instead of a mynaposter.com URL; the myna mention is gone.
- `principal: represented` no longer cites a preparer with a power of attorney.
- The FTB card's last step no longer suggests sending the PIN to someone else.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* OpenErrand: user-agent rule, captcha solver policy, reference runner note
Anthony's answers on #227 ("go with your recommendations"):
- Rule 11: a runner may run headless with a normal desktop browser user agent
(dropping HeadlessChrome) and nothing more: no fingerprint spoofing beyond
the UA string, no stealth plugins, no solving or evading a bot challenge.
A challenge the browser completes itself is a wait step; any other is a
captcha gate.
- Captcha solvers: new site.sector and captcha step `solver`
(forbidden by default | allowed). Never allowed on government, tax,
financial, healthcare or identity-provider sites, nor on any errand with a
declare or identity-proofing step or a secret input; elsewhere only when the
file says so, with every use logged. The validator rejects `allowed` in the
forbidden set or without a stated sector; six new tests. The FTB example
states sector "tax".
- Reference runner: @logicsrc/openerrand / `logicsrc errand run`, marked in
progress; ftb stays the runner the example was taken from.
- Name stays OpenErrand; family stays Agents and process.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>