The Graph Can Wait
v1 ships the loop. Plan mode is a named orchestrator, not the default personality. A read-only planning phase writes a plan entry. The operator's approval is a recorded permission. Refusal executes nothing and ends the turn as plan-refused. Each approved step runs as a bounded phase of the same turn. Caps count across the whole turn. There is still one turn_end.
Measurement made the cost visible. On a two-step filesystem task the loop finished in about four steps. Plan first proposed six steps, hit a step cap, and spent several times the tokens. After the planning instruction learned the executable budget — a plan step costs about two model steps — planned length fell and success recovered. Plan was then correct and still nearly three times the loop on a task the loop finishes in one pass. Loop stays the local default. Plan earns its cost where the plan itself is the deliverable.
Ask Is How a Harness Offers a Choice
The model offers two to eight labelled options, at most one recommended. The loop resolves it through the same asker seam a permission uses, selected by an interactive flag rather than by tool name. Nothing executes. Question and answer are durable on their own so replay shows what was asked even when the later turn fails. Declining is an answer the model is told about, never an invented pick. A headless run takes the recommendation and says so. The plan ask is addressed from the durable plan entry so a graphical client can park on the same permission surface.