01Plan firstAnvaya's --plan-only mode is read-only by construction: write and exec tool calls are blocked at dispatch, so exploration cannot mutate the tree. In-session plan stepping is on the roadmap, not shipped.
02Act with real tools21 native tools compiled into the binary, read/edit/patch, glob/grep, run_command and run_script, a pooled LSP, repomap PageRank, web fetch/search, and a mind tool for recall and record. No plugin layer.
03Verify objectivelyTests, builds and external checkers are first-class: the benchmark program treats a passing verifier as the only definition of completion, and the same discipline applies in normal use.
04Isolate the messSubagents (explore, general, plan, build) run in fresh windows and return summaries; up to four run concurrently; a 30-second stale heartbeat surfaces STALLED in the TUI instead of hanging silently.
05Constrain blast radiusA declarative sandbox policy enforces read/write/exec/network scopes at the tool layer. Profiles: project, computer, strict. --yolo bypasses approval but does not widen confinement.
06Remember outcomesEvery turn can feed the Mind graph: typed decisions, patterns and fixes that decay by type, drift-check against git, and carry a Beta-Bernoulli utility score from actual use.