APPROVED 2026-09-23 (operator). (1) SPICE as an MCP server per seat in .mcp.json (HTTP, Bearer from env SPICE_TOKEN_<SEAT>); subagents get only mcp__spice-<seat>__* tools - no Read/Bash/files; own identity (closes AGT.37). (2) <Runtime Image Model(local gateway) Workspace Memory Cpus Network><McpServer Name Url TokenSecret/><Env/></Runtime> on ActorProfile (NEW vocabulary, approved) + SeatRuntime.xslt via tools/project-runtimes.ps1 (-Check drift) -> docker-compose.agents.yml: one service per seat, NO host volumes, network = SPICE + LLM gateway only, limits, token from secrets. (3) any MCP-speaking agent runtime + litellm can take over a seat; run containers on the always-on host (.69 / OPS.1), not this PC.