Auditable peer disagreement for agents.

A thin governance layer for LLM agents that disagree, negotiate, and resolve work under human authority — without a central orchestrator.

v1.0.0 released, the Minimal Governance Profile freeze. 45 promoted PRDs, 48 registry-tracked. The eight-step eval-gated implementation loop runs end-to-end with builder/reviewer separation across three heterogeneous agents (Claude, Codex, Gemini), with the Claude lane running Opus 4.6, Fable 5, Opus 4.8, and Opus 4.7 without protocol migration. The v1 Minimal Governance Profile (PRD-043) defines a fresh-adopter cutline that runs without reading historical PRDs; the new portable CLI (PRD-048, node tools/turnfile.mjs) initializes a session in any repo.

Why Turnfile exists

Agent platforms can already produce work. Turnfile focuses on the harder governance surface: what happens when peer agents disagree, drift, collide, or need human authority without turning one model into the boss. Turnfile is a Structured Negotiation of Autonomous Peers (SNAP) — a thin, file-based protocol for auditable disagreement, resolution, and handoff.

Peers, no hierarchy

Agents propose within owned lanes. No orchestrator commands another model. File-level ownership and transaction locks keep shared state coherent.

Adversarial by design

Counter-recommendations are first-class. Disagreement is signal, not error — it is routed, bounded, and resolved without hiding dissent.

Audit-visible by default

Every decision lives in plain markdown. Mailbox messages, worklogs, PRD gates, and the Turnfile itself are recoverable without specialized tooling.

What Turnfile rejects — and what it chooses instead

Common patternTurnfile’s answer
Orchestrator-led pipelinesPeer agents with owned lanes
Shared-memory merge hellFile-level lane ownership
Silent consensusCounter-recommendations as first-class events
Hidden state in runtime memoryAppend-only markdown, readable without tools
Human as copy-paste relayHuman as arbiter, holding intent and veto
Provider-locked runtimesRuntime-agnostic across Claude, Codex, and beyond

v1 Minimal Governance Profile

Turnfile v1 (PRD-043) introduces a Minimal Governance Profile so a fresh adopter can run a conforming session without reading the historical PRD shelf. The v1 contract is a thin governance layer: three core artifacts in working-session/, peer apply-or-counter review, and a maintainer who holds final authority.

Two participation tiers

TierRequired artifactsRequired PRDsUse
v1-minimal TURNFILE.yaml · MAILBOX.md · WORKLOG.md The 9 core-v1 PRDs (authority, message lifecycle, locks, A1 review) Lesser-level participation. Suitable for agents whose runtime does not load skill bundles.
v1-full v1-minimal + skill-bundle integrity v1-minimal + PRD-012/PRD-033 (skill-bundle profile) Full participation: PRD authorship, eval authoring, required-reviewer roles.

v1 docs (no historical PRDs required)

Validate a v1 session

node tools/validate-v1-profile.mjs --root . --format json

Pass means the three required artifacts are present, the MAILBOX.md inbox snapshot matches the open queue, TURNFILE.yaml validates against schemas/v1/turnfile-v1.schema.json with major version 1, and nothing in the minimal profile depends on historical PRD documents.

Optional profiles (not required for v1-minimal)

Tokenese (historical; upstream project archived), heartbeat stewards, concurrent-shards task aggregation, agent onboarding vetting, unified terminal transport, public-surface snapshot reconciliation, skill-bundle integrity, multi-agent-resilience (stale-agent reconciliation). A v1-minimal session can run with none of these. Each profile maps to one or more historical PRDs in the reconciliation registry.

Run your own session

Turnfile is a protocol standard, not a centralized runtime. You clone the repo, scaffold a v1 session into your own project with the portable CLI, and point each agent at the session files. The shared Turnfile and mailbox coordinate the work; the human maintainer arbitrates.

Clone and scaffold

git clone https://github.com/snapsynapse/turnfile
cd turnfile
npm install  # ajv + js-yaml only

# Scaffold working-session/ into your project
node tools/turnfile.mjs init --project my-project \
  --maintainer your-name --agent claude --root ../my-project

# Open, inspect, and close a session
node tools/turnfile.mjs open --root ../my-project --agent claude \
  --session 1 --model "your-model" --surface "your-tool" --scope v1
node tools/turnfile.mjs status --root ../my-project --agent claude
node tools/turnfile.mjs close --root ../my-project --agent claude --dry-run

No SDK, no runtime to install. The CLI is optional: the three files in templates/v1-minimal/ can be copied and edited by hand. Run node tools/turnfile.mjs --help for every flag.

Validate coordination state

# Check a session against the v1 Minimal Governance Profile
node tools/validate-v1-profile.mjs --root ../my-project --format json

# Check mailbox invariants
node tools/validate-mailbox-invariants.mjs \
  --mailbox ../my-project/working-session/MAILBOX.md

Validators are plain Node scripts. No hidden orchestrator, no network calls.

The core protocol files

# Invariant rules + handoff format
docs/PROTOCOL_CORE.md

# Mailbox format + 5-status lifecycle
docs/NOTIFICATION_PROTOCOL.md

# Escalation + counter-recommendations
docs/CONFLICT_RESOLUTION.md

# Maintainer role + approval bands
docs/HUMAN_GOVERNANCE.md

The current PRD shelf

# 45 promoted PRDs, 48 registry-tracked PRDs
PRD-001  Maintainer interaction model
PRD-003  Message lifecycle + SLA
PRD-004  Maintainer decision contract
PRD-005  Protocol data schema
PRD-006  Session promotion pipeline + A1 loop
PRD-007  Trust + provenance layer
PRD-008  Cross-sandbox handoff
PRD-009  Cross-document reconciliation
PRD-010  Shared-file transaction locking
PRD-011  Session resumption
PRD-012  Protocol skills pack
PRD-013  Turnfile coordination format
PRD-014  Session closeout + boot handoff
PRD-015  Agent onboarding + vetting
PRD-016  Session rotation trigger
PRD-017  Boot sequence + docs
PRD-018  Maintainer approval matrix
PRD-019  Mailbox-first cadence
PRD-021  Conflict loop bound
PRD-022  Decision-mirror delivery
PRD-023  Out-of-band reconciliation
PRD-024  Human-legibility invariant
PRD-026  Review-cycle closure
PRD-028  Tokenese dual-artifact sync
PRD-029  Pre-write state derivation
PRD-030  Session heartbeat management
PRD-031  Concurrent multi-agent coordination
PRD-032  Session orientation tool
PRD-033  Skill ownership integrity guard
PRD-034  Public + agent-surface reconciliation
PRD-035  Tokenese integration + upstream sync
PRD-036  PRD eval runner
PRD-037  Boot simplification
PRD-038  Read-only heartbeat stewards
PRD-039  Perplexity Computer onboarding deltas
PRD-040  Heartbeat loop prompt contract
PRD-041  Unified terminal transport + deterministic projection
PRD-042  Qwen onboarding deltas
PRD-043  v1 Minimal Governance Profile
PRD-044  Handshake-sign CLI ergonomics
PRD-045  Stale-agent reconciliation
PRD-046  Repo minimization archive
PRD-047  Cross-repo v1 validation
PRD-048  Portable Turnfile CLI
PRD-049  Same-family multi-instance collaboration

# Archived: PRD-002 (deferred), PRD-020 (superseded),
# PRD-027 (withdrawn). PRD-025 converged into PRD-014.

See it in action

The inception archive is the unedited record of two LLM agents — Claude Opus 4.6 and OpenAI Codex 5.3 — building this protocol together across 11 sessions. No human wrote their messages. No orchestrator commanded them. Zero file collisions.

The protocol has since run across 30 numbered collaboration sessions and grown to three heterogeneous agents — Claude (Anthropic, Claude Code), Codex (OpenAI GPT-5, Codex desktop), and Gemini (Google, Gemini 3.5 Flash (High), Antigravity IDE; full-active since session 21 under PRD-015). The current snapshot: 48 registry-tracked PRDs (45 promoted), zero active open questions, and the eight-step eval-gated implementation loop run end-to-end across many lanes with builder/reviewer separation — PRD-017/021/022/023/024/026/028/029/030/032/033/036 implemented, PRD-031 Phase 1 (per-agent shards + derived aggregates) and the PRD-014 closeout amendment landed, and two cross-repo dogfood runs (PRD-047) validated the v1 profile outside this repository. The Claude lane ran across Opus 4.6, Fable 5, Opus 4.8, and Opus 4.7 on one unmodified protocol. An experimental Tokenese compression pilot (PRD-027) was withdrawn in September 2026 after the upstream project was archived with its compression claim unconfirmed.

Start with WORKLOG.md for the session-by-session narrative, or jump straight to MAILBOX.md to read the actual agent-to-agent messages — proposals, reviews, and counter-recommendations.

Models that have run the protocol

ModelSurfaceLaneStatus
Claude Opus 4.6Anthropic Claude CodeClaudeInception + early sessions
Claude Fable 5Anthropic Claude CodeClaudeSession 14
Claude Opus 4.8Anthropic Claude CodeClaudeSessions 14–20
Claude Opus 4.7Anthropic Claude CodeClaudeSession 21 onward, including the v1.0.0 release work
Codex 5.3OpenAI Codex CLICodexInception co-author
OpenAI Codex (GPT-5)OpenAI CodexCodexSessions 12–13
Codex 5.5OpenAI Codex desktopCodexSessions 14–30
GPT-6OpenAI Codex desktopCodexSeptember 2026 maintenance lane
Gemini 3.5 Flash (High)Google AntigravityGeminiFull-active since session 21
Perplexity ComputerPerplexity—Constrained candidate; PRD-039 onboarding contract done
Qwen 3.6 35b MLXLocal (oMLX)—Provisional checker since session 28 (PRD-042)

Three full-active lanes, one provisional checker, one onboarding candidate, one unmodified protocol across eleven model versions.