Skip to content

Architecture Decision Records

Immutable once accepted; superseding requires a new ADR that links back. Format: Context → Decision → Consequences → Alternatives considered.

Older records retain the package and type names used when accepted. ADR-0054 records the domain extraction and renaming; Modules is the current ownership and import reference.

#TitleStatus
0001On-device inference via MLX (mlx-swift-lm)Superseded by 0008
0002SwiftUI-first, @Observable MV, actor domainAccepted
0003GRDB/SQLite for persistenceAccepted
0004XcodeGen + xcodebuild CLI buildsAccepted
0005Pluggable memory: wiki default, Hindsight optionalAccepted · Hindsight runtime superseded by 0036; refined by 0031, 0033, 0035, and 0037
0006MCP via official Swift SDKAccepted
0007No App Sandbox; Hardened Runtime at shipAccepted · signing refined by 0078
0008Inference delegated to a local oMLX serverAccepted
0009~/.goat home; file-based Claude-Desktop-compatible MCP configAccepted
0010The Paddock: artifact previews; custom transcript reaffirmed over SwiftyChatAccepted
0011Liquid Glass primitives + AppKit hook for true window alphaAccepted
0012Engine API key in ~/.goat file (0600), not the KeychainAccepted
0013Themes are ThemeSpec data; custom themes from ~/.goatAccepted · refined by 0022 and 0030
0014Bottom panel is a read-only activity log, not a shellAccepted
0015Herd Guarantee split from preview network access; off-grid toggleAccepted
0016Chat pipeline: normalize at the engine, typed parts in the UIAccepted
0017Engine-agnostic OpenAI-dialect client; oMLX recommendedAccepted
0018Monorepo layout (apps/web/docs) + CI/release/Pages toolingAccepted · web/ refined by 0041
0019Pens (projects) are folders in ~/.goat/projects; OKLCH colour, AGENTS.mdAccepted
0020Engine presets (oMLX/vMLX/Ollama/LM Studio/llama.cpp) + Custom URL; engine-aware model managementAccepted · refined by 0021
0021Engines are a managed list (engines.json) sharing the MCP servers' UX; one active at a timeAccepted
0022GOAT Theme Format; community themes as folders; built-ins read-only; System → Light/MidnightAccepted · refines 0013, refined by 0030
0023One active turn app-wide; revisioned engine lifecycle commits; M6 gateAccepted
0024Deterministic prompt budget; capability-gated model setup and atomic trimmingAccepted
0025Progressive single-flight startup; local state before concurrent servicesAccepted
0026MainActor publishes Sendable worker results; generation and file I/O stay off-mainAccepted
0027Fail-closed local stores; bounded transports and generation-bound MCP authorityAccepted
0028Measured bounded rendering; transition-safe fullscreen backingAccepted
0029Chat/Image/Video workspaces; Tether is the capability-driven media inspectorProposed
0030Corporate System default; About-unlocked 1337 experience pack ships in KidAccepted · refines 0011, 0013, and 0022
0031Provider-aware LLM Wiki Pages/Map/Connections browser; desktop memory mapAccepted · refines 0005
0032Optional user-owned Pen workspaces; local Git status and opt-in initializationAccepted · refines 0019 and 0026
0033Exclusive Global and Pen memory scopes; non-destructive chat movesAccepted · refines 0005
0034Hindsight as a bank-scoped server providerSuperseded by 0036
0035Hindsight as one managed connection lifecycleAccepted · refines 0005 and 0034
0036GOATed extensions, native skills, and Hindsight lifecycleAccepted · supersedes Hindsight runtime and scope in 0034
0037App-wide memory provider and explicit Pen banksAccepted · refines provider routing in 0005, 0033, and 0036
0038Local presentation gate and professional interfaceAccepted · refines 0030
0039Preview and extension lifetime boundariesAccepted
0040Single-source release identityAccepted
0041Public website as a Vite + Vue SPA on GitHub PagesAccepted · refines 0018
0042GOATed Kid capability and lifetime contractAccepted
0043App-owned local Hitch and CLIAccepted
0044Docs site as VitePress over docs/, beside the landing pageAccepted · extends 0041
0045JUDAS central connection policy and security activityAccepted · refines 0015, 0024 and 0042
0046Scoped recent memory, Pen tabs and native Hindsight mapAccepted · refines 0031 and 0037
0047Native graph controls and session chartsAccepted · refines 0031 and 0046
0048Spatial memory and knowledge graphAccepted · refines 0046 and 0047
0049Native map input ownershipAccepted · refines 0047 and 0048
0050Map zoom and connector motionAccepted · refines 0047 and 0049
0051Typed memory relationship directionAccepted · refines 0048 and 0050
0052Pens overview and visible legend helpAccepted · refines 0051
0053Local reading font preferencesAccepted
0054First-class domain modulesAccepted
0055Local-network service authorityAccepted
0056Bounded rendering caches and responsive I/OAccepted
0057Foreground engine connection recoveryAccepted
0058Stable transcript reflow and scroll ownershipAccepted
0059Project context and tool execution guidanceAccepted
0060Bounded rich-list measurementAccepted
0061Native GOATed Pen file toolsAccepted
0062Declarative GOATed packagesAccepted
0063Chat and Pen scopes for native file permissionsAccepted · refines 0061
0064Composer and Pen file-permission controlsAccepted · refines 0063
0065Bounded recovery for unexecuted tool-call textAccepted
0066Lead, early titles, and continuous tool workAccepted · refines 0023; supersedes the round cap in 0006 and 0065
0067Lead waits for the current action and approvalAccepted · refines 0066
0068Honest edit feedback and visible interruption recoveryAccepted · refines 0003, 0061, and 0066
0069Coding navigation, context excerpts and accurate Stop resultsAccepted · refines 0024, 0061 and 0068
0070Confined Pen command jobs and separate owner whitelistAccepted · implements command direction in 0061
0071Optional built-ins and Herder settingsAccepted
0072Tool-generation telemetry and coder recoveryAccepted
0073Owner-managed command whitelistAccepted
0074Grouped transcript tool activityAccepted · refines 0058
0075Chat file attachments and inline artifact presentationAccepted · refines 0056 and 0074
0076Hindsight health and session ownershipAccepted · refines 0035
0077Host coordination and resource lifetimesAccepted · refines 0025, 0056 and 0076
0078Owner-approved release signingAccepted · refines 0007

New session? Start with ../../AGENT.md, then the roadmap.