Skip to content

headcount

An agent organization shaped like a company — a chief executive over sixteen independently installable departments and 172 skills, where a skill is a folder of Markdown that loads itself when a request matches its description, one tree installs in both Claude Code and ChatGPT because only the manifests differ, and the 184 outside authorities that settle a question rather than decorate an answer — a regulator, a standards body, primary law — sit in a catalog beside the skills they answer for, each labeled with what an agent may do with it.

Screenshot of headcount
Editor screenshot, 1 Oct 2026headcount ↗

What it is

A skill library organized the way a company is: a chief executive over sixteen departments — security and legal risk, finance, people, marketing, IT operations and the rest — and each is a plugin that installs on its own, so a project loads only what it needs. Inside are 172 skills, addressed as department:skill so that names never collide, each a folder holding a SKILL.md that loads when a request matches its description. Two departments are reviewer-class: they review what the others build, hold no write surface, report to the chief executive rather than into the function they oversee, and their blocking findings cannot be overruled by the department they review. The same tree installs in Claude Code through a plugin marketplace and in ChatGPT and Codex through a second set of manifests: the skill files are identical and only the manifests differ. Where an outside authority settles a question the skill carries the sources it checks against, 184 of them across 150 skills, each labeled with what may be done with it. MIT licensed, all of it written for this repository.

Who built itBy the profile on the account, a CIO in Atlanta, Georgia, with a company list naming Drummond IT, Keel GRC and vibld; the account was opened in 2015 and carries 57 public repositories and 62 followers. He is the only human author of the repository: 44 of its 87 commits are his under two identities — 39 from cbrock84@gmail.com and 5 from chris.brock@drummond.com, which GitHub attributes to a second account, chris-brock — and 42 are authored by Claude from noreply@anthropic.com. One outside contributor wrote the remaining commit, and 36 commits carry a co-author trailer, 33 of them naming Claude Opus 5.

How it is put together

The parts · 6

An org chart expressed as a file tree, with the installable department as the unit of distribution. Each department is a plugin directory holding a manifest for each host tool over one shared skills tree, and each skill is a directory rather than a file so that its supporting documents travel with it. Because nearly everything a reader sees — the README, the org chart, the social card, the per-skill source lists, the Codex manifests, the file that describes the repository to an agent — is generated from the tree with a check mode that fails the build on drift, there is very little hand-maintained prose outside the skills themselves, and the checks are the product’s real interface. Two principles hold it together. Everything that governs an agent is machine-checked: the surface map, the authority column, the charter roster, the source vocabulary and the reference graph all fail continuous integration rather than relying on discipline. And where a boundary has to exist between two departments it is written into the skills that would otherwise collide, because the overlaps that forced the earlier consolidations were exactly the ones left unstated.

plugins/ — sixteen departments
The product. Each department carries a .claude-plugin/plugin.json of 351 to 527 bytes and a .codex-plugin/plugin.json of 692 to 978 bytes over one shared skills/ tree. Marketing is the largest at 38 files and 96 KB, then executive at 16 files and 88 KB, technology at 32 and 77 KB, IT operations at 25 and 74 KB and finance at 28 and 74 KB; customer experience and corporate strategy are the smallest at 13 and 12 files. A skill is a directory holding SKILL.md beside an optional references/ directory, which is where the emitted source lists land. Skill bodies run from 1,915 bytes for solution-exploration to 8,921 for chief-executive.
.claude/agents/ and docs/AGENT-SURFACES.md
Twenty-one charters, one for every installed roster row. Each states why the agent exists, its surface as writes and reads with the note that it never commits, the standard its surface implies, the verification that proves it, and a six-section return contract ending in open questions for the orchestrator. The map they hang from lists nineteen builders and two permanently read-only reviewers with class, install status and authority, then a glob block per surface and the rule that a new department adds its row, its block and its charter in the same change.
sources/
Ten files totalling 115 KB, one per subject area, each a list of TOML entries mapping an outside authority to the skills whose answers it settles, with the reachability date and the license class on every entry. sources/README.md holds the format and the closed license vocabulary. The per-skill lists emitted from here are generated rather than maintained, and the generator is the only thing that writes into a department’s references/ directory.
scripts/, and the guard that lives inside a skill
Thirteen files and 131 KB. Six generators — the org chart at 33 KB, the industry-pack emitter at 22 KB, the README at 18 KB, the source catalog at 11 KB, the Codex port at 9.8 KB and the social card at 9.2 KB — and seven checks: the surface guard, 17 KB of Node with no dependencies, shipped inside the executive department as part of agent-hierarchy, plus US English spelling, never-block consistency, provenance, skill references, the source catalog and skill frontmatter. check-all.sh runs all fourteen the way CI does, and CI calls that same script.
docs/ and docs/assets/
Eight documents and 310 KB, led by the decision log at 82 KB and 39 numbered entries and the source catalog at 48 KB, then worked situations that cross departments, a getting-started guide, the agent surface map and a generated Markdown org chart, with a 151 KB interactive chart and a GitHub Pages entry point beside them. The asset directory holds 3.5 MB: light and dark org chart images, a social preview, and three terminal-styled demo clips of 22, 26 and 26 seconds, each marked as an illustrative demo so nobody mistakes one for a capture of a real session.
verticals/ and .github/workflows/
Two industry packs, industrial and education, each a vertical.toml plus industry-only skills and fragment files that are spliced into a core skill ahead of its ## Never block. They emit standalone repositories into a gitignored dist/. Two workflows of 607 and 744 bytes: one runs the full check script on every push and pull request with read-only permissions, and the other fetches every cataloged URL on a weekly cron, deliberately outside the per-push workflow.

Choices, and what they beat

  • A department as the installable unit over one flat skills directory

    Every skill description loads into context, so past a hundred skills the choice was between a directory structure that merely organizes the repository and one that changes what gets loaded. Departments as separate plugins mean a project takes only the functions it uses — and a later constraint made the split mandatory rather than tidy: one host budgets skill descriptions at roughly eight thousand characters against about fifty thousand for the whole catalog, so installing everything at once is not just noisier there, it does not work.

  • Rewrite every imported skill from scratch over keeping the upstream notices in a licenses directory

    A marketplace meant to be installed is distribution, so the notice requirement would have followed every copied skill. All 77 vendored skills were removed along with their datasets and font binaries and the capability re-authored, and twelve skills that had arrived from a shared folder with no license got the same treatment — absent terms are a weaker position than a permissive license, not a stronger one. The cost is recorded rather than hidden: a bundled style and palette database could not be re-authored, so the design skills teach method instead of shipping a dataset, which the log calls a real capability reduction, accepted knowingly. The first, botched execution of it produced a standing rule: never delete a source before the replacement has been diffed against it.

  • Agents split by exclusive write surface, with an authority column beside it over splitting agents by topic, and leaving the landing question to whoever was driving

    A topic split has no checkable boundary — two agents on SEO and UI end up in the same file and neither is wrong — while an exclusive-glob surface can be proven unique by a script that runs in continuous integration. The authority column was added afterwards because the map answered where an agent may write and never whether that write could land without a decision, which in practice was settled per dispatch from memory. It is mostly one value on purpose: gating every row would be decoration, and the two rows that are gated are the ones whose mistakes reach past their own directory.

  • A catalog of references with a closed license vocabulary over vendoring the public-domain material so that skills work offline

    A snapshot of a live feed is wrong the day after it is taken, and a pointer is current the moment a regulation changes. The license class is the load-bearing field rather than the URL: most of what a professional must cite is not open, so the vocabulary has ten values and three of them exist to mark sources routinely assumed reusable — free to read, free behind an account, and sold. An entry classed wrongly as open invites an agent to reproduce text it was only ever allowed to cite, which is why the tie-break is the more restrictive class.

  • A second set of manifests over the same tree over emitting a standalone repository for the other host tool

    Both hosts read the same skill format — frontmatter, a body, optional scripts, references and assets — so there was no content to port, only a manifest in a different place. Emitting a second repository was rejected in writing: an industry pack emits a different catalog, while this would have emitted the same 172 skills twice, giving two install sources for identical content and requiring a re-emit before any fix reached half the users. A contributed copy of the tree was rejected for the same reason, and was a month stale by the time it was reviewed.

Read fromdocs/DECISION-LOG.md (81,522 characters, 39 numbered decisions, each with lettered options and a recorded resolution), docs/AGENT-SURFACES.md, docs/SOURCES.md (184 sources over 150 skills with the license split), sources/README.md, sources/security.toml, docs/GETTING-STARTED.md, README.md and AGENTS.md, the plugin manifests for security on both hosts, .claude-plugin/marketplace.json, plugins/executive/skills/agent-hierarchy/SKILL.md, scripts/check-all.sh, the repo-meta, sources and verticals charters, both workflow files, and the complete 446-file tree with sizes.

Build log

6 stages
  1. 01

    The library existed before the repository did, and most of it had to be rewritten

    The repository was created on 2026-08-28 and its first commits import work that already existed: five MIT-licensed skill collections in the account’s own repositories, holding 106 skills, of which 84 were taken — 22 skipped as duplicates or superseded variants — plus twelve from a shared Drive folder with no license and no stated terms at all. Both batches had to go. A marketplace meant to be installed is distribution, so every affected skill was rewritten and the originals, their references, the datasets, the font binaries and the license files were removed — 77 vendored skills, then the twelve Drive skills. The consequence is written down, not glossed: part of what was removed was data, not prose — a palette database, licensed fonts — so the replacement design skills teach method instead of shipping a dataset, and the log calls that a real capability reduction, accepted knowingly. A standing rule came out of the same episode, after the first execution deleted the originals before checking coverage: never delete a source before the replacement has been diffed against it. All 100 were then restored from git history and audited against their successors: six had lost real substance and were patched, and one capability with no home became a skill of its own. The repository now holds 1,745 stars, 263 forks, 11 watchers and 3 open items.

  2. 02

    Sixteen departments, and the boundary between each pair written into a skill

    The shape was decided early, then argued with for weeks. Every skill description loads into context, so past a hundred skills the author chose departments as separate plugins over one flat directory, then extended that into a C-suite hierarchy. Security became its own department with its own CISO charter rather than skills under technology, because modeling the CISO beneath the CTO reproduces the conflict the role prevents. An empty administration department was folded into legal and risk and the executive office, and deleted. Three departments nobody had asked for — customer experience, data and analytics, corporate strategy — were built together at five skills each, after a coverage check called support the most conspicuous absence. Project management was pulled out of operations into a program management office under the chief operating officer, because the founding rule splits by exclusive write surface and project management crosses all sixteen. Corporate IT was split away from product engineering, and the four overlaps that forced it were written into the skills: who owns access policy against who executes a joiner-mover-leaver process, who owns recovery objectives against who owns the restore. Coverage was then checked against the BLS Standard Occupational Classification, which found eight gaps, six of them functions the taxonomy names and the catalog lacked.

  3. 03

    Agents split by write surface, and a second axis added once the first proved insufficient

    executive:agent-hierarchy is the method, extracted from twenty-four agents over a 1,500-file monorepo, shipped here with a 415-line playbook, starter rosters and an executable guard. The rule: split agents by exclusive write surface, not by topic, because a topic split has no checkable boundary — two agents on SEO and UI edit the same token file and neither is wrong. Builders edit inside one surface and never commit; reviewers are permanently read-only; the orchestrator is neither and is the sole committer. The map is a file, docs/AGENT-SURFACES.md, a row per agent, a glob block per surface, one owner per path, and agent-guard.mjs check fails CI when a path is claimed twice or owned by nobody. Twenty-one charters sit in .claude/agents/; a row without a charter or a charter without a row fails the same check. The second axis exists because the first said where an agent may write and never whether that write could land without a decision. Authority has three values: take the result, surface the diff before landing, or do not dispatch it unasked. Nineteen of the twenty-one rows take the first, and the author defends that rather than decorating the column: a department writes only in its own plugin directory. The exceptions are the agent owning the checks and the generators, and the one owning the industry packs, whose output ships into somebody else’s repository.

  4. 04

    A catalog of references, and a license class that decides what an agent may do

    Each entry carries a publisher, an https URL, a license class, a jurisdiction, one sentence on what question it settles and the skills it serves. sources/security.toml opens with NIST SP 800-53 Rev. 5 — the control catalog US federal systems are assessed against — public domain as a US government work, so an agent may quote it, with the OSCAL content repository beside it and three security skills served by it. The same file carries ISO/IEC 27001 as sold: cite the clause number, never the wording. Ten license classes are allowed and enforced; three — free to read, free behind an account, sold — exist to mark the sources most often assumed reusable and not, and the tie-break is the more restrictive class. Of the 184 sources, 125 are quotable; the rest are read and cite only. Admission is stricter than it sounds: a source counts only if it settles a disagreement between two competent practitioners, so many skills deliberately carry nothing — nobody adjudicates how to write a good line. A skill with sources must carry a ## Sources section and a skill carrying one must have sources, checked both ways; the links are fetched weekly on their own schedule rather than on every push. The catalog is equally closed to a source with no skill to serve: an issue holds candidate healthcare authorities led by the HIPAA Privacy Rule, waiting for a skill that does not exist.

  5. 05

    Forty-two commits signed by the model, and one pull request per change

    Of the repository’s 87 commits, 42 are authored by Claude via an Anthropic address, under a GitHub account named claude; the author’s own 44 arrive under two identities, and he authors every merge. Content commits carry branch names that say what they are — claude/c-level-depth — and one name, claude/import-agents-drive-gmci3h, is reused across eight merges, which the author explains: that session allowed one development branch, so two separately reviewable commits shipped together rather than pushing to a second. The pull request, not the commit, is the unit of record; its bodies read as engineering reports — what changed by file, what was verified, which decision the work raises. The clearest example is outside work: a contributor who read all 172 skills filed nine defects, and every one was checked against the tree — two merged as mechanical fixes, the rest answered with a new check that fails the build on a ## Never block whose bullets disagree on terminal punctuation, after rejecting the suggested lint, which returned 59 hits, mostly the deliberate house style. A second external pull request, an independent security reviewer shipped inside the installable security department, has been open since 2026-09-21, its author still waiting on 2026-09-28. A third, 358 files packaging the catalog for another agent tool, drew a reply listing what had to change first.

  6. 06

    No releases and no tags: the version lives in sixteen manifests

    The repository has no releases, no tags and no changelog. Distribution is a marketplace pointing at main, and the only versions are per department: all sixteen plugins carry 1.0.0 in both manifests, and the marketplace carries 1.0.0 too. The only version change in the record is proposed by somebody else — the external security-review pull request bumps it to 1.1.0 and regenerates the Codex manifest. The log stays honest about what was verified: publishing on 2026-08-29 closed a gap where the documented install command worked for nobody but the owner, and nothing in that session could run a marketplace install against a clean client, so the manifest was verified only as far as parsing. The rhythm since is a burst and a pause. Eighty-seven commits land in twenty-one days — 36 in August and 51 in September, the newest on 2026-09-17 — and then main goes quiet for two weeks while the external pull request waits. Nothing is archived, and the queue moved while the commits did not, so this record files it active rather than maintained. The one piece of machinery that kept moving is its own distribution: two industry packs, industrial and education, emit standalone repositories from a config plus the core, generating a whole department when a pack asks for one, and the emit is verified by writing into a temporary directory and running the emitted repository’s own checks.

Adjacent records

All records →