The Shepherd Field

Shepherding is a voice-first working relationship: find the right context, think aloud, and ask for bounded action while the person stays in charge.

Share LinkedIn X

The point is not watching everything. It is watching the right things.

Shepherding, not surveillance.
September watch · 8 September 2026 · published snapshot

Tony's August call: Codex leads · carried into September

Field view
September 2026
Context continuity Governed follow-through one task / thread connected work Bounded operatorsActs within clear limits Shepherd fieldVoice, context, safe follow-through Tool yardUseful one task at a time Guide pathFinds context and suggests

11 established candidates · 8 September 2026 · published snapshot

Follow-through Answers Guides Acts with approval Shows the receipt

Read the OpenAI Codex note ↓
How to read this field

Axes Across means more context carried between conversations. Up means more bounded follow-through, approval and evidence.

Zones Tool yard: one directed task. Guide path: contextual advice. Bounded operators: action inside clear limits. Shepherd field: voice, continuity and safe follow-through.

Markers Strong border = stronger source chain; dashed = early research. Solid / half / open dot = documented two-way / limited / unverified voice. Positions are qualitative, not scores. Evidence: what is documented · Inference: our reading · Tony's view: a dated personal call. September method and caveats ↓

History July, August and September are dated published observations. Historical positions share today's plot, with label spacing adjusted for legibility. Animation connects monthly observations, not measured progress between them. ✦ marks an entrant's first month in this watch, not its launch date or a quality award.

What changed this month

Evidence ledger · September watch · 8 September

  1. Codex + AstraExperimental cross-window notes and context retrieval.source
  2. ClaudeShared chat/Cowork memory earns a continuity move.source
  3. CursorGoals, steering and human computer takeover.source
  4. OpenClawTwo-way Talk; configuration and recovery need testing.source
  5. OpenHandsClearer supervision of specialist agent work.source
  6. InterpreterApproval previews; voice is local dictation.source
  7. LettaPersistent memory; unrestricted CLI default matters.source
  8. Other toolsAugust baseline retained, not a fresh September review.archive
  9. RowboatVoice dispatch and code receipts; mobile unverified.source
  10. gooseSession recall and tool controls; voice is dictation.source

Axes Across means more useful context carried between conversations. Up means more bounded follow-through, with approval and evidence.

Zones Tool yard: one directed task. Guide path: contextual advice. Bounded operators: action inside clear limits. Shepherd field: voice, continuity and safe follow-through.

Signals Strong border = stronger source chain; dashed = early. Solid / half / open dot = two-way / limited / unverified voice. Sourced evidence · Editorial inference · Tony's stated view. Full method ↓

The philosophy

What does it mean to shepherd agentic sheep?

The point is not watching everything. It is watching the right things.

A shepherd protects human attention. They decide which decisions carry consequence, give agents a bounded field in which to work, and make the important moments visible. Agents may plan and act; people remain responsible for the judgement.

  1. Name what matters.Set the outcome, the owner and the point at which a person must step in.
  2. Bound the work.Give only the context and authority needed, with approvals, stop-lines and a route back.
  3. Read the signal.Review exceptions, evidence and receipts. Let routine work stay quiet.
Read Tony Wood's founding essay →

The Shepherd Standard.

A Shepherd helps a person think aloud, recover the right context and delegate bounded work. Authority is earned progressively; capability alone is not enough.

  1. 01
    Serves someone named.
    A person or team can say what the work is for and who owns the outcome.
  2. 02
    Works inside clear boundaries.
    Permissions, responsibility, least privilege and escalation routes are visible.
  3. 03
    Maintains useful context.
    The system knows enough to act well without claiming more access than it has.
  4. 04
    Leaves evidence and receipts.
    Intent, approval, execution and outcome can be inspected afterwards.
  5. 05
    Honours human gates.
    Approval, interruption, stop lines and recovery paths remain real.
  6. 06
    Follows through responsibly.
    People move from directing each step to shepherding the work, while remaining accountable.

Field Notes

Each chart is a dated snapshot. Field Notes are the living record: what changed and why, new entrants, evidence checked, and what we are watching next.

Read the September watch ↓
September watch · field note · 8 September 2026

Astra arrives. The field opens up.

September brings a stronger OpenAI model and a wider choice of assistants we can run and shape ourselves. The useful question stays the same: can I think aloud, recover the right work, and delegate without losing sight of the decisions that matter?

  1. Sourced evidence · OpenAIGPT-6 Astra adds an experimental way for Codex to keep notes and retrieve earlier context windows. Rollout and opt-in limits matter. Astra is assessed within OpenAI Codex, not as a second competing assistant.
  2. Sourced evidence · Claude and CursorClaude's 25 August memory update connects chat and cloud Cowork. Cursor adds goals, steering and human takeover of computer work. These are practical continuity and supervision signals.
  3. New observations · open-source watchOpenClaw, OpenHands, Open Interpreter and Letta enter provisionally. They vary in completeness, voice, licence scope and operational burden. None was installed or hands-on qualified for this review.
  4. Wider contender check · 8 SeptemberRowboat adds a voice-dispatch candidate; goose adds a desktop operator. Both are new to this watch, not new product launches. goose voice is dictation, not a verified spoken relationship. Mobile, recovery and full approval coverage remain open checks, not endorsements.
  5. The control details matterInterpreter's voice is dictation. Letta's interactive CLI defaults to unrestricted permissions. OpenClaw's gateway needs deliberate trust boundaries. Owning the software also means owning its operation.
  6. Editorial inference · proposed movementClaude moves modestly right for shared context. Codex and Cursor hold their positions while the new capabilities are tested. The six entrants have cautious first placements; dashed borders mean early research, not measured inferiority.
  7. Tony's stated view · still dated AugustCodex remains Tony's last approved leading-Shepherd call for his working pattern. September's evidence invites a new judgement; it does not manufacture one. The remaining established tools retain dated August observations.
  8. Cost and ownershipCompare cost per completed, reviewed task: subscriptions or tokens, hardware, hosting, setup, supervision and recovery. Open source does not mean cost-free, offline or private by default. Model providers and connected services have their own terms.
  9. What would change our minds?A repeatable voice-to-work test: recover the right conversation, accept a correction, prepare a bounded action, stop at approval, show a receipt, and recover after interruption. Run the same scenario across tools before promoting a marker.

Under the bonnet: open-weight models

These can power an assistant. They do not supply its memory, permissions or human relationship by themselves.

  • Kimi K3Open weights under a model-specific licence; a large multimodal foundation.
  • Nemotron 3.5 Lightning11 August release aimed at efficient specialist agent tasks.
  • Inkling-Small30 July release, newly added to this watch; open weights with audio and image reasoning.

A naming note: Google Project Astra is a separate research prototype with limited tester access. Its demonstrations are not credited to OpenAI or treated as generally available Gemini capability.

Evidence checked and publication approved 8 September 2026. Placements remain provisional editorial assessments. Future updates require Tony's separate approval; research runs cannot publish them automatically.

August watch · field note · 9 August 2026

August: continuity starts to move

This note records product changes and material evidence corrections against the July baseline. Movement is a dated editorial inference, not a benchmark or permanent ranking.

  1. Sourced evidenceOpenAI adds Project context to ChatGPT Voice; Codex remains a separate history and working surface.
  2. Sourced evidenceClaude Cowork evidence now includes remote web/mobile sessions and saved files; wider Claude adds categorized memory and consented Microsoft 365 writes.
  3. Sourced evidenceCursor adds iPad review and Google Workspace actions; Rovo adds long-horizon context and visible execution traces.
  4. Sourced evidenceGlean documents real-time voice and stronger agent identity; Perplexity Comet joins with voice-led browser action.
  5. Editorial inferenceClaude, Cursor, Rovo and Glean move modestly. Perplexity enters provisionally; its action history is not yet a durable Shepherd receipt.
  6. Tony's stated viewThe July call that OpenAI Codex leads for Tony's working pattern carries into this August watch.
  7. Held this monthMicrosoft 365 Copilot, Gemini, Notion, Motion and Agentforce stay in place; no new evidence crossed a Shepherd criterion strongly enough to move them.
  8. Watching nextDirect voice-to-action continuity, durable receipts across devices, and context that remains useful without quietly widening authority.
First watch · baseline entry · 24 July 2026

First watch: the baseline

This starting note records the first provisional observations. It is a dated editorial baseline, not a claim of complete market coverage or a permanent ranking.

  1. Current fieldTen major candidates, each linked to first-party evidence and a provisional confidence signal.
  2. OpenAI relationshipCodex is plotted once; ChatGPT Work is a related sibling experience with separate history and broader general work.
  3. New entrantAtlassian Rovo joins as a connected-work operator with permissioned actions and limited voice evidence.
  4. Evidence checkedVoice, continuity, desktop and mobile access, context, approvals, audit and receipts.
  5. Still uncertainDirect voice-to-action continuity, plan availability, durable cross-thread memory and real operating safeguards vary.
  6. Watching nextWhether voice, context and bounded follow-through become one coherent, inspectable relationship.

Leadership needs a rhythm for the work.

The Chief Agentic Officer Briefing follows the governance, resilience, evidence and human decisions behind agentic systems.

Join the Chief Agentic Officer Briefing