hc0.io § Operating Standard

Section 1 · Cover

Headcount Zero Operating Standard

The conditions under which software agents run the recurring work of a company, and one human holds the judgment.

Documenthc0.io
Revision2.0
StatusIn force
ScopeAgent-run operations
Sections5
Issued2026

1 · Scope and application

1.1

Purpose

This standard states the conditions under which software agents carry out the recurring work of an organization without a matching count of people. It addresses the case where the number of staff is held near zero and the number of running procedures is not.

1.2

Scope

The standard applies to any procedure an agent runs against a live system: accounts, records, files, budgets, published pages, anything a person would be accountable for. It does not apply to reading, drafting, or analysis that changes no live state. That work is unrestricted.

1.3

Conformance

Conformance is claimed per procedure, never per organization. A procedure conforms when every clause that applies to it holds at the time it runs. A clause that cannot be met is recorded as an exception carrying a reason, an owner, and a review date. An unrecorded exception is a failure of the whole procedure.

1.4

The human gate

One named human holds final authority over irreversible actions and over the promotion of any agent. The gate is a person, not a queue and not a policy document. Where this standard says escalate, it means to that person. Where the gate is unavailable, procedures wait; they do not proceed on assumed approval.

1.5

Revision

A clause is added when a rule has already held in production. A clause is struck when it stops holding. Revisions are dated and cumulative, and a struck clause remains legible in the record with the reason it was struck.

Terms in brief

Agent
A software process that reads context, decides, and acts without a person composing each step.
Procedure
A named unit of recurring work with a defined start, end, and success condition.
Playbook
The written form of a procedure. One entry per step, each carrying a run, a verify, and a recover instruction.
Constraint
A limit enforced in code. It holds whether or not the agent agrees with it.
Guidance
A limit expressed in prose. It informs an agent and does not bind one.
Mutation
Any action that changes the state of a live system.
Trust level
The authorization band an agent holds for one named procedure. Defined in Section 3.
Audit record
The durable entry written for every mutation, sufficient to reconstruct what changed, when, under whose authority, and why.

Contents

02Agent operations Separation of constraint and guidance, mutation preconditions, validation after every change, halting and escalation. 03Trust levels Three authorization levels, the conditions for promotion, the conditions for immediate revocation, and the audit trail requirement. 04Procedure qualification How work qualifies for agent operation: one complete execution, failure capture, playbook, cold verification, hardening, disqualification. 05Reliability and composition Reliability compounds multiplicatively. Component budgets, the single-path preference, maintenance or delete, the one-at-a-time replication gate.

The standard is short on purpose. Every clause here was written after the failure that made it necessary, and none of it is aspirational.

Revision notices

Get a note when a clause changes or a new one is added. Sent when there is a revision to report, not on a calendar.

No spam. Used only to send the notes.

Section 1 of 5 Next · Section 2, Agent operations →