Run a fleet.
Prove every change.
Parallel coding agents in isolated worktrees, held to a governance gate, with a provenance trail. On your machine, on your Claude subscription.
The problem
LGTM is not proof.
Same commit, two records. Only one can say what it did, who reviewed it, and which rule it was judged against.
the problemThe board
Nobody writes tickets.
- Spend attribution joins runs to work itemsyouperf2h
- Search finds keys as well as sessionsagent/pool-2ux5h
- Token gate rejects undeclared utilitiesagent/pool-1gate4m
- Session paint races on a settling turnagent/pool-4test3d
- Flaky session-surface testsagent/pool-2pr 11811m
Agents open, advance and close their own items as part of the work, so the board derives from what happened and cannot go stale.
the boardThe gate
Autonomy has a floor.
Gated: the fleet proposes, you ratify. The default, and where anything unrecognised fails safe.
Full: changes that clear every green gate ship without you. The breakers underneath still hold.
Set how much the fleet may do unattended. Three breakers bind underneath at every setting, which is what makes the dial safe to turn up.
the gate and its breakersThe trail
Why, not just what.
- work.advanceagent/pool-114:22:07token-gate identified -> in_progress
- review.findingreviewer14:48:31token-gate severity medium
- review.verifyverifier14:52:10independent, did not author the fix
- gate.holdbreaker/0115:03:55autonomy-policy governance path
- canon.ratifyyou15:19:02never widen a scale to fit a call site
Every decision appends an event naming its actor. Nothing updates and nothing deletes, so a change walks back to the rule it was judged against.
the trail and the canonLocal first
Nothing leaves.
The graph is a SQLite file on your disk. One thing crosses the boundary: the model call, through your own Claude login.
local firstTurn the dial up.
Start at gated, where the fleet proposes and you ratify. Move it when the trail has earned it. The breakers do not move either way.