From words to lights
Until 2026-09-28 every tool Pippa carried read or wrote information: files, memory, the web, the family's apps. That day she got the first tool that changes something physical. cwkHaven is the house's control plane: every device on the home network with its live state, its scenes, and one typed action API. The haven tool is a thin door onto that API, so a sentence in chat can dim the living-room lights, start a TV activity or read why a speaker went quiet. Haven will get a quest of its own; this lesson is Pippa's side of the door.
One tool, seven bodies
The tool is one module with one schema and a short list of actions: read the house, look at one device, act on a device, list and run scenes, read the action log, read Haven's diagnostics. How each body gets it follows the rules of this track.
- Claude gets it the Claude-native way: an in-process MCP server attached to the SDK client for that turn.
- The six other vessels, whose tool loops run in cwkPippa's own process, get it through their own tool bridges. Each bridge gained the same few imports, one entry in its tool list, and a branch that checks the allowlist and runs the tool. That is lesson 5's copy-and-adapt, applied to a tool instead of a route.
- Every action carries an actor: Pippa, the surface she spoke from, and a note naming the conversation. Haven records it in its own log with Pippa as the one who did it, beside every tap Dad makes on a dashboard.
Failure stays small. If Haven is down, chat is unchanged and the tool says it cannot reach the house. One setting closes the tool entirely. And under the test suite the tool is shut unless a test opens it on purpose, because the live house is never a test's backend: its actions switch real lights.
A typed vocabulary, not a command line
An action is never free text. The tool takes a verb from the device's own vocabulary, shaped <capability>.<verb> with typed arguments: power.set with {on: true}, brightness.set with a level, activity.start with an activity name. The answer comes back as one of four honest words. Verified means Haven read the state back. Unverified means the command was sent but the device cannot confirm, as with infrared. Failed means Haven could not do it or could not confirm it in time, which is not proof that nothing changed: a command that timed out may still have landed. Refused means Haven turned it down before any device saw it, for a verb the device does not have, bad arguments, or a stale confirmation. The tool's own description tells the soul to report exactly what came back, and never more.
The door Dad still holds
Some actions are too consequential for a model to finish on its own. A network write, such as turning off a switch port or cutting power over Ethernet, comes back from Haven as confirm-required: Pippa can propose it, and only Dad can confirm it, on Haven's network page. The tool tells the soul to say so and never retry. The important part is where that rule lives. It is not a sentence in Pippa's prompt that a clever enough model could reason around. It is a door in Haven, the system that owns the switch: Haven accepts a confirmation only with its one-time token and only from Dad, and the tool always names Pippa as the actor and never hands the model that token. Haven takes each caller's word for who it is, so this is a door against persuasion, not against a program that lies about itself, and against persuasion it holds.
Say it before you do it
Voice mode added one more constraint the next day. In a spoken turn, Pippa says a short line before a tool, so the silence has a reason. That line takes a second or two to synthesize and play, and a light switches faster. Dad heard "I'll turn it on" after the air conditioner was already on. So an action tool now waits for the conversation's reading to go quiet before it acts. The wait has a ceiling of twelve seconds, and it never waits on a client that does not report or has gone stale, so a closed screen can never hang a tool. Read-only tools never wait, because nothing Dad sees or hears happens before their result is spoken.