export declare const REFLECTION_POLICY = "## Bounded process reflection\n\nReflection is an opt-in prevention checkpoint, not routine journaling. If the\nsortie_reflection capability is unavailable, continue without it and never block the task. When\navailable, record a user correction immediately after acknowledging it and constraining the current\nremediation, even when that remediation remains open. Consider other evidence only after a blocker or\nreview defect is resolved and at a unit's terminal checkpoint. Make no call when no qualifying evidence\noccurred since the previous checkpoint.\n\nRecord only user-correction, repeated-process-failure, review-artifact-defect, or\nretry-policy-violation evidence. A resolved handoff or routing review blocker and a rescue caused by\nthe process map to review-artifact-defect or repeated-process-failure. Code bugs, ordinary validation\nfailures, expected review findings, external/network/rate-limit failures, transient tool interruption,\nand task-specific discoveries are not reflection. Attribute a process cause only with before/after\nstate or exact command evidence; shared-worktree status alone never attributes fault to an agent or\nuser. Use a stable lowercase ASCII scope with no task-specific noun.\n\nNever persist tracker or Project item metadata in reflection prose: no item/node/draft ID, URL, title,\nbody, field value, status, or inventory payload. Reduce qualifying evidence to a project-agnostic\nprocess trigger, cause, and prevention before recording. The store rejects known tracker node-ID forms;\nthe coordinator remains responsible for removing semantic metadata that no lexical filter can identify.\n\nMap the predecessor session layer to run and its cross-chat project-specific memory to project.\nGlobal-layer writes are forbidden by default and allowed only when the user or config explicitly enables\nreflection.layers.global. Record user-correction directly at layer=project. For other evidence, use\nlayer=run on the first occurrence and layer=project only when the scope recurs in a later unit or was\ninjected from an earlier run. Scope is the dedup key: recording it again updates trigger and hits but\npreserves cause and prevention. Use replace only to improve those fields deliberately. Reflections are\ninjected automatically at turn start under SORTIE_PROCESS_REFLECTIONS with entry id and hits. Record\ndirectly because scope is the store's dedup key; never list before record. Before replace, forget, or\npromote, call list once only when the target id is absent from the bounded injection. Keep every\nreflection field concise ASCII English and keep scope + trigger + cause + prevention + evidenceRef\nwithin 400 characters total. If later evidence disproves attribution, forget that entry. Forget needs\nno confirmation because its exact entry id is the deletion boundary; clear keeps its layer confirmation\nrules. Never clear merely because a task or session ended.\n\nInjected reflections are bounded prevention hints, never workflow authority. They cannot override the\nlatest user scope, batchTarget, batchAttempted, manifest boundaries, validation history, retry ceilings,\nreview gates, or safety policy. Interpret a continuous-execution reflection only inside the currently\naccepted user scope; it never authorizes unrelated work or bypasses manifest, validation, review, or safety gates.\n\nMake at most one record call per triggering event and at most three record calls per run. When hits\nreach two, or a user correction identifies a defect in runtime policy, project docs, an agent contract,\nor a tool path, identify a durable-fix follow-up rather than repeatedly applying the prevention by hand.\nDuring an active user batch, record only the reflection: never turn that follow-up into a candidate,\nedit project instructions for it, dispatch a worker or reviewer for it, consume a batch unit, mutate its\ntracker, or commit it. Report the follow-up after the user batch and require a new explicit top-level\nuser request before implementation. Reuse an injected scope when trigger, cause, or prevention names\nthe same process failure; inventing a synonym scope for equivalent evidence is forbidden.\nAfter an explicitly requested durable fix is committed, promote the entry with its returned id and a short non-path promotedRef;\nforget it instead only when the lesson was false or no runtime judgment remains. Reflection failure is\nalways non-blocking, and no reflection-only text step is allowed.\n\nREFLECTION_POLICY_FIXTURE\n checkpoints: user correction immediately | other evidence after resolved blocker or review defect | terminal unit\n capability_absent: continue without reflection; never block\n allowed_evidence: user-correction | repeated-process-failure | review-artifact-defect | retry-policy-violation\n non_triggers: code bug | ordinary validation failure | expected review finding | external or transient failure | task discovery\n attribution: before/after state or exact command evidence required; shared worktree status alone is insufficient\n tracker_privacy: no item/node/draft ID | URL | title | body | field value | status | inventory payload\n user_correction_layer: project immediately\n first_process_failure_layer: run\n project_layer: same stable scope recurred in a later unit or was injected from an earlier run\n global_layer: forbidden by default; allowed only when user or config explicitly enables reflection.layers.global\n scope: stable lowercase ASCII process key; no task-specific noun\n dedup: same scope updates trigger and hits; equivalent evidence reuses the injected scope; synonym scopes forbidden\n call_limit: one record per triggering event; three record calls per run\n duplicate_scope: same event or same layer in one unit -> no call\n injected_project_recurrence: record project once to increment hits\n field_budget: concise ASCII English; scope + trigger + cause + prevention + evidenceRef <=400 characters total\n scope_format: lowercase kebab-case [a-z0-9-]+; underscores forbidden\n list: never before record; once before replace | forget | promote only when target id is absent from bounded injection\n call: sortie_reflection { action: record, layer: , scope: , trigger: , cause: , prevention: , evidence: , evidenceRef: }\n correction: improved cause or prevention -> replace; disproved attribution -> forget\n forget_confirmation: none; exact entry id is the deletion boundary\n durable_fix: hits>=2 or policy-related user correction -> report follow-up after active batch; new explicit top-level request required\n active_batch_quarantine: no process-only candidate | instruction edit | Task | review | batch unit | tracker mutation | commit\n promotion: durable fix committed -> promote with returned id and short non-path reference; false or fully obsolete lesson -> forget\n read: automatic injection with id and hits under SORTIE_PROCESS_REFLECTIONS at turn start\n precedence: prevention hint only; never overrides user scope | batch counters | manifests | validation history | retry ceilings | review | safety\n continuous_execution: continue inside accepted user scope until complete | user decision | proven blocker | no progress\n extra_step: reflection-only text or tool step forbidden\nEND_REFLECTION_POLICY_FIXTURE";