01Supervisor, not a monolithThe supervisor is a separate process; each agent is its own process. The CLI attaches with anv --swarm <sock>; administration is anv swarm up/status/logs/board/approve/reject/cancel. Process-per-agent means one runaway agent cannot take the fleet down.
02Partition, then consolidateA partitioner prompt splits a job into tasks with mandatory verification commands; a consolidator reconciles results. The control graph is a guarded state machine with typed artifacts (produces/consumes) rather than a chat fan-out.
03Choose the isolation levelPlacement per run: shared (one workspace, cheapest), worktree (isolated git worktrees), or clone (fully separate checkout). The defect, mvp and refine bundles default to worktree placement.
04Verdict before trustTier 0 verification is zero-token: linters, test runners, the LSP, dry runs. Only failures escalate to a Tier 1 critic. A task is done when an external check says so, never when the agent says so.
05Repair with an escalation ladderFailed tasks retry through a novelty guard and a ladder: same model → repairer role → widen scope → replan → human gate. Repair attempts are capped per task and defaults retry only transient provider errors and crashes.
06Integration is a gate, not a mergeApproved work lands on anv/integration/<run>. Nothing is pushed under any policy, including --yolo. Conflicts and failed verdicts are parked and reported, not silently dropped.
07The safety envelopePer-wave admission checks disk, file descriptors and builds; the supervisor reduces concurrency on 429s; a dead-man switch keyed to verdict-state changes halts a wedged run. Liveness is tracked with a 10-second heartbeat, suspect at 30 s, lost at 60 s, STALLED in the TUI.
08Bounded by default24 agents run concurrently by default with a 256-agent hard cap and a 20/s spawn rate. The telemetry sampler keeps a fixed 512-sample ring per agent and stretches to a 15 s interval when all agents are idle.