Genius-level protocol is what makes inexpensive inference good. A tell is the moment a failure starts to form, and each rule begins there. Wherever a rule can be a hook, an agent or a workflow, it is one. Where it can't, the table says so.
prosea paragraph someone has to remember
linta check on the plugin itself, before release
hooksruns on every matching tool call
workflowsthe script is the process
weakerstronger
Prose < lint < hooks < workflows. We try to put every rule as high on this ladder as it will go. Rules 2 and 7 are still prose only, and the table marks them.
The rules
The protocol, rule by rule.
Each rule, the tell that triggers it, the plugin that enforces it, and how strong that enforcement is.
Rule
The tell
Enforced by
Strength
01Right model, every dispatch.Set model on purpose: haiku to look things up, sonnet to build, opus to judge. Nothing inherits the top tier by accident.An omitted model inherits the most expensive session model, so set it on every subagent and workflow agent.
you're about to start a subagent or a workflow step.
dojo-router: warns on a dispatch that names no model, and blocks in block mode. Its mod fills in the model by role.dojo-protocol: its four role agents are pinned to haiku, sonnet and opus.
hook + mod
02Scout before you touch.Search, then read the slice. A small model maps the ground before a large one changes it.An orchestrator who hands off both scouting and building never learns the territory, so look at the riskiest code yourself first.
an edit to code you haven't read this session.
dojo-protocol: a scout agent on haiku and the scout-first skill teach it. No hook checks it.
prose
03Keep context small.Grep first and read excerpts. A fix under ten lines in one file stays in the main thread; don't spawn an agent for it.Check a file's size before you read it; reading a big one whole spends context the work needed.
a big file, a log, a whole directory.
dojo-gates: big-read refuses a whole-file read of a large file. Keeping a small fix in the main thread is prose.
hook + prose
04Contract before fan-out.Write the shared decisions to a file first, give each agent files no one else writes, and gate each wave on a clean build.Parallel tracks couple on decisions and derived facts, not just files, so freeze the shared decisions in a committed file before you fan out.
three or more files, or two or more agents.
dojo-flow: the Contract phase writes the shared decisions and refuses tracks that overlap, inside the workflow.dojo-protocol: the contract skill teaches disjoint ownership. Nothing outside the workflow enforces it.
workflow + prose
05Done means verified.Run the check in this session and show its result. A report, yours or an agent's, is a claim until a check backs it.An agent's final report is a hypothesis; verify the tree and run the gates yourself.
you're about to write "done", "fixed" or "tests pass".
dojo-verify: its Stop hook blocks a final message that claims success when no check has passed since your last edit, and never twice in a row. Its mod shows an UNVERIFIED status.
hook + mod
06Count returns, not dispatches.Say dispatched, returned and failed. A dead reviewer looks exactly like a clean one.Fan-out harnesses fail open: a dead lens reads as a clean lens.
summarizing a fan-out.
dojo-flow: the scorecard reports dispatched, returned and failed.dojo-verify: its mod shows the same tally as it happens.
workflow + mod
07Debug by disproof.State the causal chain and the smallest experiment that turns the bug on and off. If you can't, observe; don't patch.If you can't name the experiment that toggles the bug on and off, observe instead of patching.
you're about to patch.
dojo-protocol: the protocol and its skills. No hook checks it.
prose
08Config before code.Check env, settings and credentials before reading logic.Total, input-independent failures point to wiring; partial, input-dependent failures point to logic.
it fails every time, at a boundary (401, connection refused, missing on startup).
dojo-gates: config-first adds a note after a 401, a refused connection or a missing command.
hook
09Silence is not a finding.Prove it can see a known positive before you trust a negative.A probe that prints nothing may never have run, so silence isn't a finding until a control shows the instrument works.
a probe printed nothing.
dojo-gates: empty-probe adds a note once per session after a probe that printed nothing.
hook
10Irreversible needs a yes.Check exactly what will leave the machine, then get the person's go.A public deploy isn't reversible, and your last deploy may not be what is live.
push, deploy, publish, delete, send.
dojo-gates: refuses blanket staging, rewrites of pushed commits, secret printing and tokens in URLs. Checking what leaves the machine and getting the go is prose.
hook + prose
Notes
What this table doesn't claim.
Turning it off
dojo-protocol adds the ten rules to the session's context at the start. A project's ./DOJO.md replaces the text, and DOJO_PROTOCOL_OFF=1 turns it off.
Taught, not enforced
Rules that ask for judgment can't be enforced by a hook. Disjoint file ownership between agents, for example, is taught by a skill and isn't enforced by anything outside the dojo-flow workflow.