The boundaryA continuable child uses its ordinary Agent inbox as the only turn queue. Parent follow-ups share that inbox with input owned by other runtime actors.

One inbox. Several owners.

Empty filtered listmeansno eligible follow-upsnotempty inbox

Expose the narrow control set.

listBound the view.

Exact live child, direct parent, stable IDs, short previews, pagination, and no cold resume.

cancelRace the claim.

Cancel-first records a durable splice. Claim-first returns false and never aborts the turn.

replaceMake it atomic.

Cancel and insert one parent-owned follow-up in one generation-checked transaction.

reorderPreserve other owners.

Reorder only eligible follow-ups; never move or drop runtime notices.

Linearize cancellation.

Parentcancel(id)
↘
Mutation boundaryeligible + pending?repeat authority check
↗
Agentclaim(id)
cancel winsinbox/spliced

outcome: canceled; no later user message for that id.

claim winsReturn false

The message owns the active turn. Do not call Agent.cancel().

Interrupt is not queue cleanup.

interrupt()cancels current work with keepInbox: truepending FIFO survives

Until scoped controls exist, keep one unacknowledged correction per child, aggregate related changes, and wait for a report or settlement before sending another order-sensitive follow-up.

Six proof gates.

Exact live direct parentStable occurrence identityNo cold resume on listClaim/cancel race is honestRuntime notices never moveEvery acceptance is accounted

Primary evidence.

Keep the full subagent contract.

The canonical guide adds current operator workarounds, authority filters, atomic replace semantics, failure routing, and twenty regression gates.

Read and star on GitHub