Accept the work when the evidence says so.
Closeout is an open specification for declaring what must be verified before an agent's work can be accepted, and recording the evidence used to make that decision.
| Requirement | State | Record |
|---|---|---|
| testing/check | passed | exited 0 |
| testing/tests | passed | exited 0 |
| security/validate | passed | exited 0 |
| adversarial-review | missing | no evidence for this candidate and policy |
blocked
The file is the requirement
Commit .agents/closeout.yaml in the repository under review. Imports add requirements under a prefix. A skill becomes a requirement only when the policy names it. If the file is absent, there are no requirements. When the base and the head both resolve, that decision is accepted. If the file is present and does not load, acceptance is blocked.
Commands run at the candidate
A command requirement is an argv. The reference runner checks out that commit in a detached git worktree, runs the argv there, and deletes the worktree. A line in chat that says the tests passed is not command evidence. A review requirement stores findings. The runner computes the outcome from those findings and the independence flags.
Same inputs, same decision
The effective policy, the candidate commit, and the evidence determine acceptance. Two models do not have to write the same review. Their findings are judged against the policy. A change to the candidate, or to a file the policy hashes, makes earlier evidence stale.
What the runner returns
| Exit | Decision |
|---|---|
| 0 | accepted |
| 1 | rejected |
| 3 | blocked |
| 2 | the invocation is invalid |
Bring your own agent and orchestrator. Commit the requirements once under .agents, and use them wherever the work runs. A session hook can consult the decision. It does not open a pull request. The orchestrator checks the current decision at that boundary.