Discussion about this post

User's avatar
Foundation's Edge's avatar

Good synthesis of the Routines + CMA stack. One architectural piece I would add to the magic framing: CMA is a hosted meta-harness, so the durable contract is the resource shapes (sessions, agents, environments, vaults), not the loop itself, which is deliberately thin so harness assumptions do not go stale as models improve. And the boundary worth naming for adopters: self-hosted sandboxes move where tool calls run, but every tool result still transits Anthropic's context window for the next inference step. Execution sovereignty, not reasoning sovereignty - that distinction carries most of the enterprise adoption decision.

Foundation's Edge's avatar

The brain/hands/log decomposition is right as far as it goes, but the May 19 updates move a boundary it doesn't capture: self-hosted sandboxes hand the Environment back to you (your VPC, your egress rules), while the loop itself — session orchestration, tool routing, the next inference step — still runs on Anthropic's control plane. I decomposed CMA from the wire up after the London event, and the result is that 'execution sovereignty' is only half right: owning the container is not owning the harness. The vault-proxied credentials are the tell — the real trust boundary sits between your sandbox and their router, and the new MCP tunnels make that seam load-bearing. At Sentry scale the question stops being build-vs-buy on infra and becomes which failure modes you're allowed to audit.

3 more comments...

No posts

Ready for more?