Templates and copies: your own versions of an app's agents

Last updated October 9, 2026

On this page

Draft for review

Every agent an app brings is a template: what the app ships for that agent at one app version, read-only. Nobody asks a template and it never runs. The agents people ask are copies made from templates. A copy has its own name, its own one line ("Answers new demo requests within minutes"), its own way of talking, a subset of the template's tools, its own limits, and works for the company, some teams, some people, or one person. When the app is updated, no copy changes: each copy shows "v2 available" to whoever manages it, and that person chooses what to take.

There is one kind of agent. A team's agent and a person's own agent are the same thing, a copy, and differ only in whom they work for (the user's decision of 8 October 2026). A copy that works for one person is that person's own; Your own agents, and private ones covers those. Who may make and change copies is a permission, manage agents; see Manage agents.

This page covers templates, making a copy, who it works for, changing it, template updates, and pausing and archiving. It describes the golive branch. What is not possible yet is listed at the end.

Words#

Word What it means
Template One agent an app ships, at one app version: read-only, never asked
Copy An agent made from a template, with its own settings and its own changes. Every agent of an app that people ask is a copy
Company copy The copy each template gets when its app is enabled. It keeps the template's id: sales-assistant is the Sales Assistant people have always asked
Works for Whom a copy works for: the company, teams, people, minus exceptions
Personal copy A copy that works for one person, who owns it
Manager Whoever may change a copy: an admin, or a holder of manage agents whose teams cover it, or, for a personal copy, its owner

People who only use agents read "a version of Sales Assistant for Sales", "your own version"; the word "copy" is on the managers' screens. Eval cases are called checks on every screen.

What the upgrade changed#

A company that ran OrchKernel before templates and copies existed is moved at the first start of the new binary, once, and nothing anyone uses changes:

  • Each app's agents became their templates' company copies, with the same ids, threads, delegations, repeats and history. Alice still asks Sales Assistant.
  • Each agent's settings moved from the app's record onto the agent: who it acts for became works for, marked required (it keeps acting for them without their turning it on), its budget became its monthly limit, and its trust and on or off stayed as they were. An earlier copy (a "fork") became a copy of its template.
  • An agent whose lifetime budget was already spent was paused, with the reason "Its budget was used up before the upgrade", so the upgrade starts nothing that had stopped.
  • Every admin got one notice: "Agents are now copies of their app's templates. Nothing changed for anyone. Managers can now make their own copies." It lists each agent's new monthly limit ("Sales Assistant: $50.00 a month, was $50.00 in total") and the agents paused for their budget.
  • Each team lead got a grant of manage agents kept from team lead, with exactly what a lead could do before (see Manage agents).

A fresh Enable does the same in one step: it records the templates and makes each one's company copy with the Enable sheet's agent settings. In the demo every app is enabled this way.

Where you find templates and copies#

You want to Go to
See an app's templates and make a copy Apps > the app, tab Templates (admins and holders)
See the copies made from an app The app's Agents tab
See every copy you manage Apps > Agents ("Agents I manage"; admins see "All agents"); holders reach it from Manage agents at the end of the sidebar's Apps section
See the agents that work for you My agents in the sidebar (Your own agents)
See every agent in the company Directory; Pick from templates there lists the templates too

Someone who neither is an admin nor holds manage agents and opens Apps reads "Only admins and people who manage agents open Apps. Your agents are on My agents."

A holder sees, on an app's page, only Overview (read-only), Templates and Agents: "Make copies of this app's agents for the teams you manage agents for, and keep them up to date."

The Templates tab#

One card per template, with "Each template is an agent the app ships, read-only. Make a copy to give a team, a list of people or one person their own version, with its own name, way of talking, tools and limits. A copy never changes when the app is updated; whoever manages it chooses." above them.

Part What it shows
Head The name, its one line, and a menu (below)
Facts The version it last changed in ("v2 · changed in this app version"), "3 required guardrails" with a lock, "1 required check", how many copies you may see, "Not copyable" where it applies
Suggested schedules Each one in a line ("Your follow-ups today · Weekdays at 09:00, each person's time"); see Team schedules
Tools As chips
Make a copy Admins and holders, when it may be copied
Preview The whole template in a drawer: what changed in each version, goal, steps, "Always and never" (the guardrails, required ones locked), "Ask first" (the approval points), what it gives back, its checks, tools and model rules
Ask for my own When people may ask for their own (see Asking for your own)
People may ask for their own Admins: a switch that opens the template to personal copies

The card's menu holds Update every copy that can take it (holders and admins), and for admins Apply required parts to every copy, Pause every copy and Resume every copy.

Some templates are never copied: the Context app's agents, the built-in agents (Architect, Coordinator, Designer, Schema Steward) and a template whose role is an admin's. The Inbox Assistant is copied only as each person's own (The inbox assistant).

Making a copy#

Make a copy opens a sheet, "Make a copy of Sales Assistant" (full screen on a phone), in five numbered sections:

Section What you set
1 Name and purpose Name (required) and What it is for, the one line people see in the picker. It says where it starts from: the template at its version, or a copy's own behaviour
2 Who it works for The company, teams or people, and Except… (below)
3 How it works First How it talks and who it serves: tone, languages, region or time zone, who it serves and a sign-off, in plain fields. Then the playbook's sections as cards (Goal, Steps, Always and never, Ask first, What it gives back), each with Edit. A required item shows a lock and "Required by the template" and stays, whatever you type
4 What it can use The template's tools as a checklist: "Untick a tool to take it away. Nothing can be added beyond the template's." Then the Model: the company's default, or one the template allows
5 Limits Per month, Per person per month, Per run, At most at once (1 to 50; 1 to 3 for a personal copy), each with a note: "Admins set any limit" for an admin, "within the limits your admin sets" for a holder

The foot sums it up ("Works for 2 people in Sales · up to $200.00 a month") beside Make the copy. A problem the server finds shows at its field.

The copy is made at its source's behaviour. Anything you changed in section 3 is filed as a change to the copy right after, which waits for someone else to read it (Behaviour changes). The notes say so: "Made Inbound Sales Assistant", then "Your instruction changes are waiting for review by another manager or an admin".

Try it: Eli makes Inbound and Outbound Sales Assistant#

  1. As ada, give Eli (an engineer) manage agents for Sales: People, tab Permissions, Grant, Person Eli Novak, Some teams, Sales, Grant (Manage agents).
  2. As eli, open the sidebar's Apps section and choose Manage agents. It opens Apps > Agents I manage: "The agents you set up for others."
  3. Open Enabled, CRM, tab Templates. On Sales Assistant choose Make a copy.
  4. Name it Inbound Sales Assistant, one line "Answers new demo requests within minutes". Under Who it works for choose Teams: Support reads "Outside the teams you manage agents for" and cannot be ticked. Tick Sales; the note reads "Works for 2 people."
  5. On How it talks and who it serves choose Edit: Tone "Warm and brief", Who it serves "Inbound demo requests". On Steps choose Edit, add a line "Demo requests: answer within minutes with two times from the calendar", and choose Keep.
  6. Choose Make the copy. The notes read "Made Inbound Sales Assistant" and that its instruction changes wait for review. On CRM's Agents tab its row reads Change in review.
  7. Make a second copy, Outbound Sales Assistant, "Reaches new prospects by email", for Sales, and untick Create calendar event under What it can use. Taking a tool away needs nobody's review.
  8. As sam, open Inbox. The change to Inbound waits for him (he manages agents for Sales and did not propose it): it says what it is ("Inbound Sales Assistant's own instructions") and that its checks passed. Approve, then Promote. Eli could not have done either himself.

As alice, the agent picker offers both new copies with their one lines, beside Sales Assistant. On My agents Inbound reads "Offered to you" until she asks it the first time; then it works for her.

When making a copy is refused#

You try to You read
Make a copy for a team outside your grant "You manage agents for Sales only; Support is outside your scope"
Make a copy for the company with a grant for teams "You manage agents for Sales only; the whole company is outside your scope"
Name an admin, or someone who holds manage agents, in works for "Only an admin can make an agent work for Priya Shah"
Reuse a shared copy's name "a copy named Inbound Sales Assistant exists; choose another name" (409 copy_exists); the sheet adds "Another copy has this name: choose another."
Copy the Context app's agents, a built-in agent, or a template with an admin's role 409 not_copyable
Give it a tool its template does not have 422, naming the tool
Set a limit above the admin's ceiling "monthly limit: up to $1000.00, set by your admin" (the default ceiling)
Copy from an app that is paused "the crm app is paused; resume it first"
Make more than 500 shared copies "the company has 500 shared copies; archive some first". Personal copies do not count

A holder whose grant was kept from team lead may make a copy, but it waits for an admin, as a lead's copy did before: the answer is 202 with an approval in the admins' inbox.

Ids: a shared copy's id is the template's id and the name, sales-assistant-inbound (then -2, -3); a personal copy's id is opaque, pc- and ten letters. Its skills are copied as <skill>-<the rest of its id> at version 1. Every id a copy or a template holds is reserved: hiring an agent with it is refused (409 id_reserved), live or archived.

Who a copy works for#

Works for names the company, teams and people, minus Except…:

  • The company is every active person who is not an admin.
  • A team is its members who are not admins. The picker says so: "Admins are not included through teams. Add Ada Park by name to include them."
  • A person named is included, an admin too (only an admin may name an admin or a holder).
  • One person alone makes a personal copy: "This makes a personal copy for Alice Chen. Alice turns it on, and may make it private."

A holder's people search finds only people in their teams, so a holder who cannot open People can still choose Alice.

Works for is an offer. A copy acts for a person only once that person turns it on. Asking it the first time turns it on ("Ask it, and it works for you"), and so does Turn on on My agents or on the copy's page. Not for me or Turn off for me turns it off for them again. Until then the copy acts for nobody, and My agents shows it as "Offered to you".

Required for them. An admin may mark a copy required: it then acts for everyone it works for without their turning it on, and they cannot turn it off ("Sales Assistant is required for you by an admin; it stays on"). The company copies made at the upgrade or at Enable are required, so nothing changed for anyone.

Each person a copy acts for gets one delegation, owned by the app ("via CRM", see Delegations): act as them, limited to the copy's tools, collections and data classes, no passing on. People who join or leave a team, are deactivated or offboarded, or turn the copy on or off, gain or lose it at once.

When a copy stops working for someone (its works for changed, it was archived, they left the team), they get an inbox notice, "Inbound Sales Assistant no longer works for you (Eli Novak, 9 Oct)": their repeats on it pause, and approvals and questions its runs left for them are cancelled with a line in the thread.

Changing a copy#

A copy changes in two ways.

Settings#

Settings (on the copy's row menu, or on its page) opens "Settings of Inbound Sales Assistant":

  • Name and purpose. On a copy that works for others, a new name or one line reaches other people's pickers, so another manager or an admin reads it first; the save answers "Saved; the new name and one line wait for another manager or an admin to review".
  • Who it works for, the same picker.
  • Limits.
  • Updates and requests: Take template updates on its own when they only add, and People it works for may ask for their own.

Everything else applies at once. If someone saved since you opened the sheet, it reloads: "Someone changed it since you opened it: it has been reloaded, so save again." If your permission was taken away meanwhile, the save is refused with who and when: "You no longer manage agents for Sales: Ada Park removed it at 10:02".

Only an admin changes a copy's trust tier (through the API, see For developers) or raises a limit above the ceilings.

Behaviour changes: instructions, checks and tools#

Instructions, the How it talks card, guardrails, approval points, checks, tools, memory, template updates and restores go through the change pipeline (Changing a skill or playbook): a proposal on the copy, its checks run, then reviewed and promoted. A copy has at most one open behaviour change (409 proposal_open).

The change Who reviews it
Only narrowing: a tool or memory taken away, a check added, with a model passing every check Reviewed automatically; the proposer promotes it
An owner's change to their own personal copy that weakens nothing, with a model passing every check Reviewed automatically; the owner promotes it
New or changed instructions, the How it talks card included, on a copy that works for anyone but the proposer A second person, never the proposer: another holder whose teams cover the copy, or an admin. New text is always read by someone
Anything that weakens: a guardrail or approval point edited (made longer with an exception included), removed or reordered; a check removed or what it expects changed A second person, never the proposer, and the change says "Takes out a guardrail"
Anything that widens: a tool or memory the template has, given back An admin
A check that passed only with the demo's stand-in, or did not run A second person; an admin may approve without checks, with a reason
Anyone but the owner changes a personal copy's behaviour First the owner's OK, showing the exact change; then as above. Taking a tool away applies without it, and the owner is told

What a copy's change may carry is fixed: playbook text, checks, tools within the template's, memory within the template's. Anything else (a skill's permissions or collections, its run caps or triggers, the agent's role, team, reports to, trust, budget, model rules, the template link) is refused with 409 copy_setting, naming the field. A change made against an older version of the copy is refused at promote with 409 copy_moved ("Inbound changed after this proposal was made: make it again from the current version"), so a stale change never undoes a later tightening.

Once a change is promoted, the copy's card and the top of each person's conversation with it say so in one line: "Updated 9 Oct by Eli Novak: new steps for demo requests".

Rules a copy carries#

A copy's own approval rules only tighten: they deny a step, or ask someone before it. Each matches that copy only. The approver is the person it works for, an admin, or a named person who may read what the step carries (naming yourself needs an admin); on a personal copy every rule asks its owner, whoever writes it. A rule records its author, and removing it needs at least its author's authority ("Ada Park, an admin, set this rule; only an admin removes it"). A copy made from another copy inherits that copy's rules. Copy rules arrive with storage version 5; before it they are refused with not_ready. There is no screen for them yet.

Rules that name a template cover its copies#

A rule of an app, or of the company's policy, that denies a step or asks for approval and names a template covers every copy of that template, so no copy escapes it. The founder app's founder-investor-mail-needs-admin holds every copy of Investor-Update Writer, and the gate's trail says "matched as a copy of investor-update-writer". An allow rule never reaches through a template: it covers only the exact agent it names. See Policy, rules and kill switches.

Template updates#

Updating an app#

When the binary carries a newer version of a bundled app (or a newer version of a company app is promoted), the app's page shows Update to v2 to admins. The demo starts on CRM version 1 so that you meet it there.

The update card, "Update CRM from v1 to v2", lists:

  • What gets looser, first and in warn, when anything does (a rule removed or relaxed, a tool's risk lowered, a tool added, a row rule widened, a trigger added). Such an update waits for a second admin.
  • What's new: the notes of each version.
  • What changes for the app: collections, tools, rules, triggers and pages.
  • Agent templates: changed, new ("new, with a copy made off and working for nobody") and retired ("retired; its copies keep working with what they have").
  • The copies concerned: "2 copies of Sales Assistant can take v2 (changed: guardrails, steps)".

Update to v2 installs the app's new parts and records the new templates. It changes no copy: "CRM is at v2. No agent changed: each copy offers the update to whoever manages it." A tool the update removes is refused to the copies that still list it ("The CRM app no longer has calendar.create"), shown under Needs attention.

"v2 available"#

Each copy whose template changed then reads v2 available on its row and its page, for its managers and admins; the people who only use it see nothing. Update opens "Update Inbound Sales Assistant to Sales Assistant v2":

  • What's new in v2, then a count: "2 changed in the template · 1 changed in both · 1 required · 6 the same".
  • One row per section, with its state: Changed in the template, You changed this, Changed in both, Required by the template. Open a row for before and after (side by side, stacked on a phone).
  • A section Changed in both needs a choice: Keep mine, Take the template's, or Edit. Apply waits until each has one.
  • A required part reads Included with a lock and cannot be left out.
  • A choice that would take out a guardrail says "Takes out a guardrail".
  • Sections that are the same, or yours alone, fold at the end.

Apply (it reads Apply selected once anything stays yours) files the update as a change to the copy and runs its checks: "7 checks passed", or "1 check didn't pass" with Drop this check, Change what it expects and Ask an admin. With no model, "No AI model is set up, so changes wait for an admin." The update is reviewed as any change is. Once promoted the copy is at v2; a section you kept shows as "You changed this" against v2 next time.

Not now leaves the copy where it is; its row reads "v2 left". When v3 arrives the badge comes back, with the diff from where the copy is.

On a personal copy the owner first sees one button, Take the update, keep my changes: the template's parts where only it changed, the owner's where both changed, and every required part. Choose part by part opens the full sheet.

Automatic updates, required parts and many copies#

  • Take template updates on its own when they only add (a copy's setting, off by default; on a personal copy only its owner sets it): an update that only adds guardrails, approval points and checks, or lines at the end of a section, is applied once its checks pass. Anything else waits. When the manager who turned it on loses the permission, it turns off.
  • Required update: a copy that lacks a part its template now requires reads "Required update". An admin's Apply required parts to every copy files one change per copy with only those parts; personal copies wait for their owners' OK. For the copies left, the admin may pause them until updated or from a date, and their cards read "Running without a required guardrail since 9 Oct".
  • Update every copy that can take it (holders, admins) files the update for every copy in your teams that has nothing changed in both and nothing that weakens it, and names the rest.
  • Its source changed: a copy made from another copy (International from Inbound) is offered that copy's later changes the same way.

Pausing, archiving and restoring#

Action Who What it does
Pause A manager; the owner of a personal copy; an admin; the lead of a team a shared copy works for Its runs stop at their next step and its schedules skip. An admin's pause is lifted only by an admin ("an admin paused it; only an admin resumes it"); an owner's own pause only by the owner
Archive A manager, the owner, an admin Asks first, with a reason the people it works for read. Its runs stop, its delegations go, it leaves every picker; its threads, runs, spending and history stay
Restore The same, within 90 days The same id, settings and people back, each person's on or off as it was
Pause every copy Admins, on the template Engages every copy's admin switch; Resume every copy lifts only the switches that action engaged

Pausing an app pauses every copy of its templates. See Policy, rules and kill switches.

A copy's row carries one state capsule, the first that holds: Archived, Paused by an admin, Paused, Needs attention (a tool removed, works for nobody, a required update past its date, its model not cleared for its data), Waiting to be turned on, On. "v2 available", "v2 left", "Required update", Change in review and "Its source changed" go on the second line.

The Agents tab#

Apps > Agents, and each app's Agents tab, list the copies you manage:

Column Example
Name "Inbound Sales Assistant" with its one line; someone else's private copy reads "Private copy" and its owner
Made from "Sales Assistant v1", and "v2 available" in warn
Works for "Sales · 2 people", "Alice Chen (own)"
State One capsule
This month "$14.20 of $200.00"
Actions Open, Update, Pause or Resume, and a menu: Settings, Make a copy of this, Restore, Archive

Search by name or owner, and filter by app, works for, and Update available, Private or Paused. Personal copies fold into one row a template ("Sales Assistant · 2 personal copies") that opens to their list, searched by owner, 50 a page. On a phone each row is a list row with its actions in the row's menu. With nothing made yet: "No copies yet. Make one from a template."

History#

A copy keeps two histories: its settings (each record version, who authorised it) and its behaviour (each promoted change, with the template version). GET /copies/:id/history lists both, newest first. Restoring a settings version writes a new version equal to the old one; restoring a behaviour version files a change through the pipeline.

Not possible yet#

  • Setting a copy's approval rules, its trust tier, or keeping its limit as a one-time total, on the screen: the API only. The upgrade notice names Keep as a one-time total but has no button for it.
  • A schedule section in the Make a copy sheet: add team schedules on the copy's page once it is made (Team schedules).
  • A History tab for a copy on the screen; use the API.
  • "Their manager" as the approver of a copy's rule, before storage version 5 (not_ready).
  • Copies of the built-in agents and of the Context app's agents.
  • Deleting a copy's history.

Known problems on this page#

  • A holder does not see the ceilings. The Limits fields read "within the limits your admin sets" for a holder, not the ceiling itself, because the company's settings answer only admins; a limit above it is refused when the copy is saved ("monthly limit: up to $1000.00, set by your admin").
  • Promote buttons on copies. The Directory's Promote to standard and Promote to trusted are refused for a copy with "sales-assistant's trust tier is set by the crm app; change it on /apps/crm", but the app's page has no trust field any more: an admin changes it with PATCH /copies/:id { "patch": { "trust": "trusted" } }.

For developers#

API#

All under /api, with Authorization: Bearer <token> (see Tokens).

Method and path Who Purpose
GET /templates?app= Holders and admins; anyone for templates they may ask for Templates: app, id, name, one line, changed_in, tools, required parts, copyable, personal, copies
GET /templates/:pack/:agent?version= The same One template in full: definition, skills with playbooks, check names, spec, notes
POST /templates/:pack/:agent/required Admins Apply required parts to every copy
POST /templates/:pack/:agent/required/pause { from? } Admins Pause the copies that lack them, until updated or from a date
POST /templates/:pack/:agent/pause-all, POST /templates/:pack/:agent/resume-all Admins Pause or resume every copy
POST /copies Holders within their teams, admins { from, name, description, works_for, owner?, tools?, model?, limits }; from is { template: { pack, agent } } or { copy }. 201 { outcome: "made", copy }, or 202 { outcome: "requested", approval }
GET /copies?app=&works_for=&state=&update=available&private= Holders (their teams), admins (all), anyone (copies that work for them) Copies
GET /copies/:id The same One copy, or the governance form for someone else's private copy
PATCH /copies/:id Managers { patch, version }: an RFC 7396 merge patch on its record. 200; 202 when it waits for someone; 409 version_conflict
POST /copies/:id/changes Managers { instructions, tools, evals, memory_scopes, rationale }: a behaviour change
GET /copies/:id/update Managers The update diff; 204 when none
POST /copies/:id/update Managers { to, take } (take per section: template, mine or { text }), or { keep_mine: true } for the owner's one button
POST /copies/:id/update/leave Managers { version }: Not now
GET /copies/:id/parent-update, POST /copies/:id/parent-update, POST /copies/:id/parent-update/leave Managers The changes of the copy it was made from
POST /copies/updates Holders, admins { template: "crm/sales-assistant" }: update every copy that can take it
POST /copies/:id/pause, POST /copies/:id/resume, POST /copies/:id/archive, POST /copies/:id/restore See above { reason }
POST /copies/:id/accept The person a personal copy was made for { on }: turn it on, or Not for me
GET /copies/:id/history, POST /copies/:id/history/restore Managers { kind: "settings" | "behaviour", version }
POST /me/copies/:id Anyone a shared copy works for { on }: turn it on or off for yourself
GET /apps/:pack/update, POST /apps/:pack/update Admins The update card; { to, version } updates (also under /modules)
GET /library/agents, POST /library/agents/:id/fork As before The library answers from templates and copies; a fork is a copy working for nobody, made off

A copy's record:

Field Example Set by
agent, template, kind, owner, based_on, authorised_by sales-assistant-inbound, { pack: "crm", agent: "sales-assistant", version: 1 }, shared The kernel
name, description "Inbound Sales Assistant" A manager (reviewed on a copy others use)
works_for { company: false, teams: ["team:sales"], people: [], except: [], required: false } A manager within their teams; required and naming admins or holders, an admin
private, replaces true, sales-assistant-inbound The owner of a personal copy; setting private needs their session signed in within ten minutes (403 reauth_required). POST /copies with private: true for someone else is 403 "only its owner makes a personal copy private"
model { preferred: null, allowed: [] } A manager; on a personal copy, anyone else waits for the owner's OK
limits { month_cents: 20000, person_month_cents: 500, run_cents: 50, concurrency: 10, total_cents? } A manager within the ceilings
trust standard An admin
rules Approval rules, each with its author A manager; they only tighten
state { state: "paused", by, reason, admin } See Pausing
personal_allowed, updates false, { automatic: false } A manager

A patch may not null state, limits, rules or works_for (422). The app record's agents is refused from now on: "agents.sales-assistant: agent settings moved: change them on the agent (PATCH /copies/sales-assistant)".

Errors: 422 invalid with problems, evals_required, not_ready; 409 copy_exists, version_conflict, copy_setting, app_has_copies (ok pack install on an app with copies), not_copyable, proposal_open, copy_moved, id_reserved, required; 403 denied with the reason; 404 for a copy you may not see.

Events#

Event When
app_updated pack, from, to, by, templates_changed
template_recorded A template recorded at an app version
copy_made copy, template, version, kind, works_for (in words), private, by, request
copy_changed A settings change: record_version, fields, by
copy_behaviour_changed A promoted change: kind (customise, update, required, restore), by, reviewed_by
copy_update_available, copy_updated, copy_update_left Template updates offered, taken, left
copy_state_changed Paused, resumed, archived or restored, with reason
copy_accepted, copy_person_changed A personal copy accepted or refused; a shared copy turned on or off for one person

CLI#

The CLI works on the state file, with the server stopped:

sh
S="--state orchkernel-demo/state.db"
ok $S --as eli template list --app crm
ok $S --as eli template show crm/sales-assistant --version 1
ok $S --as eli copy make crm/sales-assistant --name "Inbound Sales Assistant" --works-for team:sales --tools gmail.send --month 200.00
ok $S --as eli copy list --app crm --updates
ok $S --as eli copy show sales-assistant-inbound
ok $S --as eli copy set sales-assistant-inbound '{"limits":{"run_cents":50}}'
ok $S --as eli copy update sales-assistant-inbound --show          # the diff in words
ok $S --as eli copy update sales-assistant-inbound --take steps=mine,guardrails=template
ok $S --as eli copy update sales-assistant-outbound --leave
ok $S --as eli copy pause|resume|archive|restore <id> [--reason ...]
ok $S --as eli copy history <id>
ok $S --as ada app update crm            # the update card; --to 2 updates

ok agent library and ok agent fork <id> --slug acme still work: a fork is a copy working for nobody, made off. Output is the JSON the API answers.