9b8d55bc18
Scopes the lead's next direction on top of the peer-launcher arc, as a proposal (ticket split deferred): - A · sandboxed, role-specific workers — a sandbox is a *placement*, so it slots into the CB-401 SPI as a new kind: sandbox adapter exactly the way CB-402's opencode slotted in as a new provider (SPI proven placement-neutral, not just provider-neutral). Ownership line held: bridge launches INTO a peer-owned image, never provisions the IDE/dev-tools inside it. - B · main-agent pairs (Opus + cloud) — both mains are MCP clients so neither can be called into; each needs a pull inbox → depends on CB-308's per-agent channels. PrimaryRegistry single-slot → multi-slot. - C · orchestrator tier — SessionManager recursed one tier up (orchestrator:mains :: main:workers) + context scoping; re-roots the human from a live primary to the orchestrator. 10 mermaid diagrams (component + sequence per development, ownership guardrail, staging graph), all mmdc-validated and theme-safe. §7 pins the bus-vs-env-manager boundary as an acceptance criterion on A; §8 stages A → CB-308 substrate → B → C.