One planner, several workers. Each in its own pane and its own worktree.
Drove runs one planner and several worker agents side by side in herdr panes. The planner, Claude Code or Codex, splits the work into Cairn tasks, starts a worker for each, reviews their diffs and merges. The workers, Claude Code or Codex too, write the code.
A drove road is the old Scottish cattle route the drovers walked to market, the herd beside them for weeks. Drove walks a run the same way: one planner keeps the herd moving, and every worker keeps to its own lane.
Fig. 1One run: the planner’s pane, and a tab of workers
Seat names, task refs and states are illustrative. The branch names are the shapes Drove uses: worktree-<seat> for a Claude worker, drove/<seat> for a Codex one.
02how a run works
The planner plans. The workers write the code.
Every agent runs in its own herdr pane, and each worker has its own git worktree. Either side can be Claude Code or Codex. There is no daemon: the planner’s own MCP server, or for a Claude planner with the mod a child process of the mod, reads each worker’s report file and wakes the planner. Run state is plain files under ~/.drove.
The planner
Claude Code or Codex
Splits the goal into Cairn tasks, and starts one worker per task.
Reads each worker’s diff, sends approve or changes, and merges.
Never edits code and never runs builds: a guard hook denies it.
Started by drove plan in a herdr pane, or by /orchestrate in Claude Code with the mod.
A worker
Claude Code or Codex
Works one Cairn ref, in its own pane and on its own branch.
Has one tool, report, and nothing it can do to the run itself.
Commits its own paths after an approve, and never pushes.
A Claude worker’s worktree comes from claude --worktree; a Codex worker’s is made by Drove.
How a message gets there
Every report goes through the worker’s outbox; only the wake differs. Every control the planner sends has an id, so a delivery is never repeated, and nothing is ever typed into a pane that shows a dialog.
Planner to worker
The first brief
herdr agent start with no prompt, then the brief by herdr agent prompt once the agent is up.
Later, to a Claude worker
herdr agent prompt, guarded: a blocked pane gets nothing typed, and the message waits.
Later, to a Codex worker
codex queue to the worker’s thread, which queues even while it is mid-turn.
Worker to planner
A Codex planner
codex queue to the planner’s thread.
A Claude planner with the mod
The mod’s bridge hands it the reports, and they arrive as a turn of their own once the session is idle.
A Claude planner without the mod
A channel notification from its MCP server, else herdr agent prompt once its pane has been idle for five seconds.
Any planner
Piggyback: every planner tool result ends with any reports still pending.
~/.drove: the whole of the run’s state
~/.drovemode 700
config.jsonoptional settings
runs/<run-id>/
run.json
roster.jsonwritten under a lock, atomically
events.jsonlappend-only, one write per line
planner/pending.jsonlreports a wake could not deliver yet
seats/<seat>/
token32 random bytes, mode 600
outbox.jsonlthe worker’s reports, one writer
hooks.jsonlwhat the hooks saw
launch.jsonthe launch spec, token redacted
03a worker’s life
A worker’s life, from a pane to a merged branch.
Spawn
The planner names a seat, a kind, one Cairn ref and a brief. Drove opens a pane, waits for the shell prompt, then starts the agent, and if it does not appear, resets the pane and tries once more. The brief goes in after the agent is up, never as a launch argument.
Work
A Claude worker gets its worktree from claude --worktree, on branch worktree-<seat>. A Codex worker gets one made by Drove, on drove/<seat>. The worker never pushes: a hook denies it.
Report
The worker calls its report tool: done, question, blocked, promote or progress. Anything but progress wakes the planner.
Verdict
The planner reads the diff and sends approve or changes. After an approve the worker commits its own paths and reports done again, expecting nothing back.
Close
The planner merges, then closes the seat. A Claude seat is closed by closing its pane, never with /exit, and Drove releases the worktree lock Claude leaves behind. Codex gets /quit first. A worktree is removed only on request, and only when its branch is merged.
The five reports
Kind
Waits for
Meaning
done
review
Finished and verified. Sent again with nothing expected, it confirms a commit after an approve.
question
answer
Needs a decision. Marked for the human when only the human can make it.
blocked
answer
Something outside the worker’s control stops it.
promote
answer
Asks for a stronger model or more effort.
progress
none
Updates the roster only. It never wakes the planner.
outbox.jsonl
{"v":1,"id":"r-<seat>-<ms>-<4hex>","run":"…","seat":"w-api","token":"…","kind":"done","expects":"review","summary":"one line","details":"branch, files, test output","at":"2026-10-09T10:20:53.000Z"}
A verdict, as the worker receives it
⟦drove v1 run=drove-20261009-1042-a3f1 from=planner to=w-api id=c-17 kind=verdict verdict=approve expects=none mac=9f2c0d1e⟧Approved. Commit only your own paths now …↩ Reply with the drove report tool (server drove): kind done, expects none, with the branch and the commit sha.
The header is machine-parseable and still readable to a model that has never seen the format. The reply line is generated from the kind, so the worker always knows how to answer. The mac is an HMAC of the id and the body, keyed by the seat’s token.
Promote, demote, down and up
promote changes a worker’s model or effort, and demote moves it back. A Claude worker with the mod switches on its next request; otherwise, and for Codex, Drove restarts the agent with resume once it is idle. A restart is never done mid-turn.
drove down saves every session id and stops the run. drove up resumes it, and drove up --seat relaunches one dead seat.
04the rules
Rules Drove enforces, rather than asks for.
Each rule is a guard, a check or a refusal in the code, not a line in a prompt.
01The planner does not edit code or run builds.
A guard hook denies it: edits outside a scratch folder, file writers, runtimes, package installs, and writes through gh or curl. Read-only git stays allowed, so the planner can read every diff and merge.
02Workers never push, and nobody pushes to production.
A worker’s guard denies any git push, for Claude and for Codex, whether or not Codex runs in its sandbox. The planner may push, but never to a production branch.
03At most five worker panes.
A sixth needs the human’s yes: drove budget 6, or a dialog in the mod. The guard denies drove budget to every agent, so no agent can raise its own limit.
04Drove never answers a dialog an agent shows.
A folder-trust prompt, a hook review, an update offer: Drove reads the screen, names the dialog, and puts it on the board for the human. One wrong answer to Claude’s exit dialog deletes a worktree and its commits, which is why a Claude seat is closed with its pane, never with /exit.
05Your config is not Drove’s to edit.
Drove never edits ~/.claude, ~/.codex or ~/.tmux.conf, and never writes AGENTS.md or CLAUDE.md into a repo. Permissions, hooks, MCP servers and role text are set per launch, from files under ~/.drove.
06One Cairn task per worker. Drove keeps no queue.
Work items are Cairn tasks, and each worker is spawned with exactly one ref. Cairn is the queue, so there is nothing in Drove to fall out of step with it.
07Planner messages are signed.
Each control carries a MAC keyed by the seat’s token, minted fresh at every spawn. A Claude worker with the mod marks a message that fails the check as unverified, and acts on a promote only when it verifies. Codex workers do not check yet. The token is not a boundary against the worker itself: file permissions are, with ~/.drove at 700 and tokens at 600.
05the mod
In Claude Code, one command. /orchestrate makes the session the planner.
With Drove’s orchestrator mod loaded, typing /orchestrate and a goal in a Claude Code session inside a herdr pane makes that session the planner. It gets the tools spawn_worker, message_worker, review_verdict, promote_worker, demote_worker, close_worker and roster, and a board and a wake bridge run inside Claude. Typing /orchestrate again in the same session re-attaches to the run.
With the mod
# in a herdr pane, with Drove's mod/# in CLAUDE_CODE_PLUGIN_DIRSclaude/orchestrate <goal>
# in a herdr pane, with Drove's mod/# in CLAUDE_CODE_PLUGIN_DIRSclaude/orchestrate <goal>
The mod is a thin layer. Claude Code’s plugin runtime has no Node, so the mod cannot import Drove’s code: it drives Drove through its CLI, and its tools run the same functions as the CLI and the MCP server. What stays in the mod is what only Claude can do:
Switching model and effort per request, for the planner and for a Claude worker.
The board inside Claude, with its pills and toasts.
The dialog that asks you for a sixth pane.
A Claude worker’s questions, permission state, context use and activity, written for the planner to see.
Without the mod, any herdr pane can start a planner. drove plan creates a run, records the pane as the planner pane and replaces itself with claude or codex, with Drove’s MCP server, guard hooks and role text attached.
Without it
# or --kind codex; add --goal "..." for a first instructiondrove plan --kind claude# in a spare pane: live seats, states and what needs a humandrove board
# or --kind codex; add --goal "..." for a first instructiondrove plan --kind claude# in a spare pane: live seats, states and what needs a humandrove board
06status
What has been seen working, and what has not.
Drove is v1, and young. Its design marks every claim as seen working, stated in the docs but not yet run, or a guess to verify. This page keeps the same line, and prints the unproven column as large as the other.
Seen workingin real runs, the mod, or a spike
A Codex planner spawning a Claude worker and running it to a report
Claude workers in their own worktrees through claude --worktree, with no folder-trust prompt
Briefs delivered by herdr agent prompt once the agent is up
Messages to a Codex worker by codex queue, including mid-turn
A Codex planner woken through codex queue
Per-request model and effort switching in a Claude worker, through the mod
Not run live yetsaid out loud
A Codex planner with a Codex worker
The sixth-pane budget dialog, in both clients
The fixes of 10 October 2026 in a real run, including the message check
Waking a Claude planner through a channel, which is a research preview
Message signatures in Codex workers, which do not verify them in v1
Known limits
The Codex launch line is still over 1024 bytes. macOS cuts a typed line at 1024 bytes until the shell is reading input, so Drove shrinks the line and waits for a settled prompt before it types. A shell that draws its prompt before its init has finished could still defeat the wait. The fix is a Drove-owned CODEX_HOME.
A Claude worker may start without your unpushed work. Claude branches its worktree from origin/main and Drove cannot set the base, so work merged locally but not pushed is missing. Push, or run git merge --ff-only main in the worker’s worktree. Codex workers start from the run base.
Codex may ask once to approve Drove’s hooks. Drove never answers that dialog; it shows it on the board.
The mod needs Node on the path. It runs Drove’s CLI, so Node 22.18 or newer must be on PATH, or set in the mod’s nodePath.
07open source
Open source, coming soon.
Drove’s repository is private for now and has no licence yet. It will be published; until then there is nothing to clone, and this page links no repository rather than a page that answers 404.
What it will need
Node 22.18 or newer. Drove runs its TypeScript directly, so there is no build step.
herdr 0.9 or newer. The planner runs inside a herdr pane.
claude, codex, or both, on PATH.
Cairn for the tasks. Each worker is spawned with one Cairn ref.
What it is made of
TypeScript run directly by Node, ES modules, zero runtime dependencies, and tests on node:test. One binary, drove, whose MCP tools call the same functions as its commands.
08the family
Drove walks the agents. The others are what they carry.