The measurement leaves one machine: several tools, several people, over time.
Context and Value
The first two milestones prove the chain on one tool and attach it to the work. Everything that follows requires crossing a boundary the design has so far avoided: another vendor, another repository, another person, and a retention longer than a working week.
The mechanics are already known, and were measured rather than assumed. Each remaining tool exports tokens and a session identifier; what differs is which signal carries them and how the export is switched on. Two of them export no amount at all, so a price table becomes unavoidable. And the flag that makes per-step attribution readable also logs what was typed, so redaction has to happen before anything is stored or sent.
Boundaries
- Includes: Codex, Copilot, Cursor and OpenCode, added one at a time, each with its own gate to lift.
- Includes: a price table, for the two tools that export tokens without a cost.
- Includes: redaction of sensitive attributes before storage or upload.
- Includes: the commit trailer, which attaches cost at commit precision rather than session precision.
- Includes: the upload, and reporting per person, per team and per epic.
- Excludes: replacing any tool's own measurement. The framework configures exports, it does not compute tokens.
- Excludes: anything that would mirror a backlog across supports.
Success Evidence
A team lead reads a week of work broken down by person, tool, model and step, on tools other than Claude Code, from a repository they did not have to open.
The decision that gates this milestone — made
Settled on 2026-08-31 by @blafourcade, in writing: aidd_docs/memory/internal/decisions/measurement-may-reach-a-hosted-destination.md, posted on #297.
#297's privacy clause is reaffirmed unchanged. Its standard clause — "Sink is an OTel collector. No SaaS." — is superseded: a hosted destination is allowed, and it is never ours to fix. The person names the destination, what travels is the already-published record contract, anyone can run their own and lose no capability, and nothing about measuring or reading requires an account.
The argument this section used to carry is also factually out of date, and its correction is what makes the decision liveable:
- The journal names nobody. No line it writes carries any identity field. It records the repository, the task folders written into, the skills run and their timings.
- It does not enter git history.
aidd telemetry on git-ignores it; committing it takes deliberately deleting that line.
- A person can refuse, and their refusal wins.
AIDD_TELEMETRY=0 is honoured by the hooks and the CLI alike and overrides whatever a repository's committed switch says — which answers "the safeguard protects the wrong people" directly.
- A person can remove what was measured.
aidd telemetry forget shows what would go, and what git history keeps whatever it does, then removes it on confirmation.
One boundary from that decision binds this milestone directly: the framework exposes, the destination analyses. Aggregating across people and repositories belongs to a hosted destination, not to what runs on a machine.
Design: aidd_docs/specs/2026_08/2026_08_13-work-tracking-linkage.md
The measurement leaves one machine: several tools, several people, over time.
Context and Value
The first two milestones prove the chain on one tool and attach it to the work. Everything that follows requires crossing a boundary the design has so far avoided: another vendor, another repository, another person, and a retention longer than a working week.
The mechanics are already known, and were measured rather than assumed. Each remaining tool exports tokens and a session identifier; what differs is which signal carries them and how the export is switched on. Two of them export no amount at all, so a price table becomes unavoidable. And the flag that makes per-step attribution readable also logs what was typed, so redaction has to happen before anything is stored or sent.
Boundaries
Success Evidence
A team lead reads a week of work broken down by person, tool, model and step, on tools other than Claude Code, from a repository they did not have to open.
The decision that gates this milestone — made
Settled on 2026-08-31 by @blafourcade, in writing:
aidd_docs/memory/internal/decisions/measurement-may-reach-a-hosted-destination.md, posted on #297.#297's privacy clause is reaffirmed unchanged. Its standard clause — "Sink is an OTel collector. No SaaS." — is superseded: a hosted destination is allowed, and it is never ours to fix. The person names the destination, what travels is the already-published record contract, anyone can run their own and lose no capability, and nothing about measuring or reading requires an account.
The argument this section used to carry is also factually out of date, and its correction is what makes the decision liveable:
aidd telemetry ongit-ignores it; committing it takes deliberately deleting that line.AIDD_TELEMETRY=0is honoured by the hooks and the CLI alike and overrides whatever a repository's committed switch says — which answers "the safeguard protects the wrong people" directly.aidd telemetry forgetshows what would go, and what git history keeps whatever it does, then removes it on confirmation.One boundary from that decision binds this milestone directly: the framework exposes, the destination analyses. Aggregating across people and repositories belongs to a hosted destination, not to what runs on a machine.
Design:
aidd_docs/specs/2026_08/2026_08_13-work-tracking-linkage.md