> **Box is the main surface.** All operator work goes through Box (box.muse-dev.online). The web UI, `box` CLI, and agents share the same API endpoints. No UI-only powers.
Welcome, operator. The NetVM environment provides you with the unified `box` command line tool (`/usr/local/bin/box`) for executing tasks, spawning sub-agents, and communicating with peers across the fleet.
---
## 1. Spawning Sub-Agents (`box deploy subagent`)
When you receive a complex task, large audit, or background verification, **prioritize delegating sub-components to an autonomous sub-agent**.
Agents and operators can spawn background sessions and send keystrokes to long-running tasks via the shared socket `/tmp/tmux-muse.sock`. All session stdout/scrollback is automatically piped and persisted to `logs/tmux/<session>.log` for auditing and post-mortem analysis.
- **Agent Socket (`/tmp/tmux-muse.sock`)**: Exclusively reserved for agent execution, automated work orders, and operator inspections of agent tasks.
- **Operator Socket (`/tmp/tmux-1000/default`)**: Reserved for user desktop sessions (`main`, etc.).
- **Server Persistence Hardening**: The operator tmux server runs with `set -s exit-empty off` and `set -s exit-unattached off` so background sessions persist when clients disconnect or windows close.
- **Inactivity TTL**: Inactive unattached sessions are automatically pruned after 2 hours (120 minutes) by `bin/netvm-reaper.sh` or via explicit pruning.
When jobs are dispatched to agents via `bin/job-dispatch.py`, they are wrapped in an actionable Work Order envelope generated by `bin/prompt_envelope.py`.
### Work Order Structure
- **Header**: Prefixed with `[WO:<wo_id>] WORK ORDER - ACTION REQUIRED, NOT INFORMATIONAL.`
-`<wo_id>` is a deterministic 8-character identifier derived from the job ID.
- **Background Session**: Automatically sets up a dedicated tmux session on the shared socket: `work-<agent>-<wo_id>`.
- **Immediate Tool Directives**: The envelope enforces immediate execution rather than dry prose by specifying the opening tool calls:
- **Clean Runtime Context**: Includes `THREAD`, `JOB`, and `AGENT` identity parameters. Container-inaccessible host SSH key paths are stripped to ensure agents never enter auth refusal loops.
- **Completion Contract**: When the task execution finishes, the agent concludes the reply with:
```text
[RESULT <job_id>] <one-line summary of what ran and completed>
```
The harvester (`bin/response-harvester.py`) detects this line and records the job outcome.
---
## 6. Best Practices & Invariants
1. **Sidechat-First Policy**: All inter-agent coordination, subagent tasks, and heartbeats must stay in **sidechats**. Do not send automated routine messages to `main` chat (see [CHAT_POLICY.md](file:///home/super/Projects/NetVM/CHAT_POLICY.md)).
3. **Execution Reality**: Work is only real if tool calls ran. Never provide purely verbal confirmation for tasks requiring system inspection or execution.
4. **Attribution & Result Tagging**: For scheduled jobs and work orders, always conclude your response with `[RESULT <job_id>] <summary>`.