Skip to content
v6.1.0MIT

Run a mission too big for one agent: turns your coding agent into a director that raises a horde — workers in worktrees, one ticket each, a one-shot review of every change that can send work back but never approve it, an architect subagent with a veto over the graph, legislate that writes each territory's law down, and a retrospective that closes the mission out.

Changelog

All notable changes to this project will be documented in this file.

The format is based on Keep a Changelog. Version numbers follow the Yggdrasil family's one-number policy, not Semantic Versioning: the core of the family (Yggdrasil, Grain, Jarl and Horde) ships together under one number, so a minor release can include changes that ask something of you. From 6.1.0 on, a release lists them under Before you upgrade and walks through them under Upgrading from the previous version; read those first, then Changed and Removed.

Unreleased

6.1.0 - 2026-09-29

Needs Yggdrasil 6.1.0 or newer and Grain 6.1.0 or newer; Horde names the release to install when it finds an older one.

This release gives every mission a record you can open with Jarl, puts Grain's measurements in the architect's hands, adds a review before every landing, and makes every Horde command an MCP tool your agent can call. Horde ships under one version number with Yggdrasil, Grain and Jarl, which is why a release with upgrade steps carries a minor number (Yggdrasil's docs/family-contracts.md, "One number for the family"). Read Before you upgrade, follow Upgrading from 6.0.0, and pin the exact versions of the family tools your pipeline runs.

Before you upgrade

  • Horde now needs Yggdrasil 6.1.0 or newer and names the release to install when it meets an older CLI (npm i -g @chrisdudek/yg). Horde's worktrees carry no install of their own, so give ygCommand an absolute path to a CLI at your graph's version.
  • Grain 6.1.0 or newer is now part of every mission. horde init and planning check for it before they create anything and print the install steps when it is missing or older; put grain on your PATH or name it once with --grain "…" on horde.mjs init (grainCommand always names a Grain now). A repository with no graph gets one read out of its code by Grain; for a blank graph, run yg init yourself first.
  • Each mission now keeps its record (tickets, your rulings, questions and answers, its journal) in a Jarl loop, written by the Jarl that ships inside Horde; with the Jarl plugin installed, jarl resume --root .horde/hordes/<mission> shows it live. Horde's scheduler stays in charge of the tickets, so close and archive a mission with horde.mjs done and horde.mjs archive, where Jarl's own close and archive point you.
  • A mission stays on the release it started with, so finish a 6.0.x mission on 6.0.x. Horde 6.1.0's commands decline a 6.0.x mission and say so; horde.mjs archive sets it aside, and history and blame read it there.
  • Prose rules now have one judge: the reviewer configured in your Yggdrasil graph (yg check --approve). The other judging paths retire with their settings: config.judge, node.mjs verdicts, the judge list in tick.mjs output, and the retrospective's two-judge measurement (retro.mjs --second, config.retro.judgeSampleRate, config.retro.judgeTier); Horde ignores a leftover judge key. If your graph has prose rules, configure a reviewer. Until then their tickets wait on one question for the whole mission, and horde init asks for a reviewer before it accepts a commit hook that runs a full yg check on them.
  • With a reviewer configured, each worker runs yg check --approve before its last commit without asking first. Yggdrasil's own agent manual (yg prime) tells any agent to run that fill once its change is final, and the client's one "go" for the mission covers its cost, so Horde asks for no separate consent. Approvals the graph reserves for a person, such as an architecture change or a suppression, still come to you. A prose rule costs one reviewer call for each component it judges (or each file, for a rule that judges file by file) when first judged and again after its inputs change, times the consensus count. The reviewer you configure decides where that lands (per token with an API provider, your subscription with an agent CLI, local with Ollama), and yg check --approve --dry-run counts the calls in advance.
  • The conflict-of-interest guard is now firm: a change to what an existing rule says and a change to the code that rule judges always land separately, with no waiver. It covers rules whose id contains /, including every rule installed with yg pack add, and edits to an installed rule's yg-aspect.adapt.yaml beyond its status or review date. Plan such work as two tickets.
  • Evidence rests on proof Horde runs itself. horde done runs the trunk gate at the trunk tip and re-runs every evidence row filled by a command, accepting the rows that pass; a "reproduced by" typed into the charter by hand needs a real run first. wave evidence <id> takes --ask <id> (client testimony), --artifact <path> (a file on the trunk) or --run "<command>" (a command the row names, run on the trunk) in place of --by. wave close --gate green --sha <sha> runs the gate at that commit before it closes the wave, and --evidence goes with --gate green --sha.
  • The promises rule package now carries the family's release number, published as pack/promises@6.1.0 (the version Yggdrasil 6.1.0 installs) with a fifth rule, evidence-is-live. A repository that installed it under Horde 6.0.0 has it recorded as 0.1.0; run yg pack update promises to move to the current rules.
  • Tickets and questions now have their own numbers (t-001, a-001), and the ruling that records an answer is named ask-001. Each ticket field sits on its own line. A ticket becomes merged when it lands; for a merge you made yourself, use queue.mjs set <ticket> merged --sha <sha> with a sha on the mission's trunk, in place of tk.mjs status <ticket> merged.
  • Under --runner external, tick now follows the process runner.spawn starts and leaves the ticket with its worker while that process lives. Keep the agent in the foreground in that command: one sent to the background (&, nohup, a detaching launcher) ends at once, and tick settles its ticket while the worker is still at work.
  • For scripts: handoff.mjs read builds the resume state from the mission's record, so handoff.mjs write, add-waiting and rm-waiting retire. horde init --json reports reviewerGap (the rules waiting on a reviewer, and what settles them); read reviewerGap.gap where you read reviewer: true|false.

Upgrading from 6.0.0

A mission keeps the record format it started with. Updating Horde writes nothing into your repository: a mission's state stays out of git as before.

  1. Finish every mission you started with Horde 6.0.x on that release.
  2. Install Yggdrasil 6.1.0 or newer (npm i -g @chrisdudek/yg) and Grain 6.1.0 or newer (clone https://github.com/krzysztofdudek/Grain, or /plugin install grain@grain-marketplace after /plugin marketplace add krzysztofdudek/Grain). If ygCommand is a relative path, make it absolute.
  3. Update the Horde plugin: in Claude Code, /plugin marketplace update horde-marketplace, then /plugin install horde@horde-marketplace and /reload-plugins; in the Copilot CLI, copilot plugin update horde.
  4. Set each finished 6.0.x mission aside with horde.mjs archive <mission>; history and blame keep reading it there.
  5. If your graph has prose rules and no reviewer, configure one. horde init and the mission frame tell you when this applies.
  6. If the repository installed the promises package under Horde 6.0.0, run yg pack update promises.
  7. If you run workers with --runner external, make sure runner.spawn keeps the agent in the foreground.
  8. Update any script that calls wave evidence --by, handoff.mjs write, add-waiting or rm-waiting, tk.mjs status <ticket> merged, tk.mjs review-request or list --review-pending, node.mjs verdicts, retro.mjs --second or the cost report, or that reads reviewer from horde init --json or weight from queue.mjs plan --json.
  9. Start the next mission with horde.mjs init <mission> --base <branch>, adding --grain "…" when grain is not on your PATH.

Added

  • Every command is also an MCP tool. The plugin starts a server named horde (horde_tick, horde_land, …, horde_help) that runs the same scripts with the same answers and locks.
  • Horde runs on Windows, with your configured commands under Git for Windows' sh.exe (see Requirements in the README). A portable plugin.json at the repository root serves Copilot and Codex.
  • A review before every landing. A reviewer reads the change once and records what it finds, with no power to approve; Critical and Important findings send the ticket back for another round, and the landing checks run in full either way. The director can skip a stuck review with a reason (tk.mjs review-skip).
  • Your approval now covers the proof as well as the rules: a change waits for your answer before it puts a promise back to planned, deletes a test file, removes assertions, switches a case off, or changes what a gate, a commit or push hook, or a CI workflow runs.
  • Test reports as proof: with gates.report.path and gates.report.format (junit, tap or playwright-json) set, a promise counts as kept when its case is in the report and passed. Promises and evidence rows can name their kind of proof (e2e scenario, hermetic test, mutation, recorded stub, artifact, client testimony) and who reproduces it.
  • gates.testFile runs a single test file, so the check that a new test fails without the change reaches tests node --test cannot run. tk.mjs new|edit --no-new-tests "<reason>" declares a change that adds no test.
  • queue.mjs regate <ticket> --note "<why>" reruns the gate at the same commit for a flake, and tk.mjs new … --reverts <ticket> undoes a landed ticket through the usual checks.
  • Prototypes: a ticket filed with tk.mjs new --kind prototype builds something the client can look at while a promise is still hard to describe. It stays off the trunk, and the client's acceptance (tk.mjs accept) is its proof.
  • Grain scores an accepted cut against random cuts using your repository's history, seeds each area's rules from its code (advisory, for you to confirm), and has tk.mjs new point out a declared file's companions outside the ticket.
  • The plan ranks each ticket's size against the mission and suggests splitting the biggest quarter. A ticket that reaches past the mission's scope, or claims proof the mission never promised, comes back with a question for you.
  • horde.mjs history lists every finished mission with what it promised, proved and proposed.
  • Rulings reach Yggdrasil's logs. decide.mjs add --node <path> records a component's why, and a ruling for a whole type (--area <type>) joins the type's decisions once you ratify it with one word (decide.mjs ratify, then ask.mjs answer <a-id> tak or nie); horde.mjs done commits them to the mission's trunk.
  • A plain-language report for the client, refreshed on every tick, wave close and new question, with a before-and-after measure of the mission's code (report.mjs, report.out). notify runs a command of yours when a question is filed or a wave closes; write its placeholders bare.
  • Landings merge what parallel tickets share in component and type logs, Yggdrasil's lock files, and files listed in config.appendOnly (horde init adds a root changelog).

Changed

  • Workers run the tests they touched, and the full suite runs once, at landing. Ready tickets with no files in common share one gate run and keep their own merge commits.
  • tick leaves a ticket with its worker until the worker logs landed <sha> or stopped: <why>, its process ends under the external runner, or you run tick.mjs --reclaim <ticket>. tick --watch logs a refusal and carries on.
  • Run bare, horde.mjs done, wave start, retro and the architect, legislate and retro briefs stay in your current checkout; pass --horde <mission> for the mission's trunk.
  • An open question holds back what depends on its answer; a worker who ran out of spec holds the whole mission.
  • A change that edits a test without adding one lands when its ticket declares no new tests. A component that asks for a log entry per change gets one before its change lands: when Yggdrasil reports its log cycle open (log-cycle-open), record why, run yg check --approve, and commit what it records.
  • Undeclared imports are named by file and line. Yggdrasil 6.1.0 also reports type-only imports, so declare those dependencies or remove the imports.
  • A landing attributes problems the parent branch already has to the parent, and a ticket may name a test-only component beside the ones it changes.

Fixed

  • Fix rounds go to the worker's own work: a moved parent, verdicts a catch-up merge made stale, a missing reviewer or a spent approval leave the count alone, and a catch-up merge that keeps conflicting ends in one question to you.
  • Worker briefs name the worker's worktree in every git command and tell a fix round what sent the ticket back; Ctrl-C on a landing also stops its test command.
  • The new-test check gives a sound answer for tests that run only through your commit gate, including gates that work off staged files.
  • Commands running at the same time take turns on shared state: every write survives, readers see whole files, numbers stay unique, and each branch lands once.
  • Horde's own graph reads pass --no-approve, so they stay free under auto_approve, and a component the graph lacks reads as absent.
  • Scope checks compare whole path segments, treat a git failure as a refusal, and land.mjs --fate reverted --by <commit> checks that the commit undoes the merge.
  • The wave-close audit and queue.mjs quality file each advisory once, across changed counts and Yggdrasil 6.1.0's renamed classes. Rerunning the plan review keeps merged tickets as they are.
  • horde init asks Grain for its proposal against the Yggdrasil --yg names and commits the graph before cutting the trunk; a repository with several build tools runs every test suite at each gate.

Removed

  • tk.mjs review-request and tk.mjs list --review-pending; the review before every landing takes their place.
  • Cost tracking and the charter's cost limit. Track what a mission spends in your own account, as for any agent work.
  • The weight estimate in queue.mjs plan, and weight in its JSON.

6.0.0 - 2026-09-12

Needs Yggdrasil 6.0.0 or newer; an older one is refused with the release to install.

Added

  • Landing is automatic: a change that passes every check merges immediately; a failing one is refused with the reason. Only one change lands at a time; a crash mid-landing no longer blocks the next.
  • land --background returns immediately and writes its result to a file. worker.copy/worktree.copy copies files into every new worktree.
  • Weakening a rule (deleting, lowering, moving its review date, narrowing scope, unhooking, disabling for a file) requires the client's written approval — once per landing or for the whole mission.
  • A change cannot both alter a rule and alter the code that rule judges in one landing; both are refused together.
  • Every landing runs the full test suite against a real Yggdrasil build; the architecture check runs on the branch itself and must be fully green.
  • queue plan --out <file> writes the whole plan to a file for the architect.
  • The cost report now counts reviewer calls spent during landing, not just agent runs.
  • A merge is refused when a file belongs to no component, or when a component's log or a graph-changing commit names a wave, ticket, mission or horde instead of describing the component itself.
  • A request is split into components before anything is built; one agent per component, no two write the same files; a component too large is refused, with its size named.
  • Nothing starts until the whole plan is reviewed once by someone who sees all of it.
  • The mission is stateless between runs: tick reads the mission's state, advances what it can, and exits. tick --runner external runs it from any external scheduler, not only a live session.
  • Work sent back past a set number of rounds stops and asks you one question instead of looping.
  • legislate writes a component's own rules from what its work has been refused for.
  • retro closes a piece of work with three lists: what belongs in a standing rule, what's worth saying once, and what no rule will ever capture — plus its cost.
  • Evidence detection: the mission works out what counts as proof in your repository (test suites, a promises directory, a scenario runner) at the start and uses it; a repository with nothing at all is offered a ready-made promises package (four rules, three self-proving for free, the fourth advisory).
  • Every merge commit records what it landed, what it proved, and what it did to the rules.
  • A finished mission archives its own working directory automatically.
  • wave close audits the rules: overdue review_by rules become renew-or-retire tickets, unhandled yg advise/grain advise items are picked up, and rules nothing has hit in two waves are named.
  • One channel reaches you: a stalled worker, work sent back too many times, a request to weaken a rule, or a change to the mission card. Each answer is recorded in the mission's decision log.

Changed

  • No check accepts a recorded result; tests and rules are re-run, never taken on trust. Every step now stops at a time limit and refuses (naming what was stopped and the setting that raises it) instead of running forever — closing a leak that left dozens of orphaned processes on a machine running these checks all night.
  • A port-change approval is required only from neighbours who actually named that port, not every neighbour of the shared component.
  • A ticket with no acceptance line cannot be queued.
  • Quality advisories file tickets only for nodes this horde leases; --all overrides.
  • Mission-wide numbering (work, architect decisions, questions for you) now comes from one sequence instead of three, so a bare number is never ambiguous.

Removed

  • Ports carry no version. <node>/<port>@<version> is refused; contract propose no longer takes --version/--as.
  • No standing cast: a mission runs on two roles, a worker per ticket and one architect — no steward, owner, verifier, auditor, counsel, or sub-teams.
  • No signatures on a ticket: merging needs no author/verifier key or per-node approval.
  • No charter file at a node; its rules, ports and log show through node show.
  • No audit sample.
  • No escalation/dissent mechanism — superseded by the one channel above.
  • Claude Code's experimental Agent Teams feature is not used anywhere in this skill.

Migrating a mission already in flight

Finish a mission started on an earlier release the old way — it still reads its own state and files itself away. Start fresh from the same mission card afterward; the new run rebuilds its work from the evidence the old one left, at the cost of one conversation per component touched.

0.4.0 - 2026-09-08

Experimental. Needs Yggdrasil 5.9.0 or newer; an older one is refused with the release to install.

Fixed

  • Reading the architecture's verdict on a large repository no longer fails with a buffer error. The report can run to several megabytes and is now read whole.

Changed

  • A node's charter no longer records who owns it or under which lease. That is the horde's working state and lives with the roster, so the charter stays true from one mission to the next.

0.3.0 - 2026-09-07

Experimental. Needs Yggdrasil 5.9.0 or newer; an older one is refused with the release to install.

Changed

  • Raising a rule now records why in that rule's own history, not on every part of the system it touches; only a raise that starts blocking merges leaves a note on the parts it now holds. A refused attempt to weaken a rule is recorded too. Needs Yggdrasil 5.9.0; an older one is refused with the release to install.

Fixed

  • A mission that grows a second team no longer ends up with one nobody can reach. Your own session raises every long-lived agent; a team's manager that wants a second team asks for it instead, and you are handed the exact steps to start it. Everyone answers to whoever raised them, and anything meant for someone further away is written down and passed up, so nothing is sent to an address that cannot answer.

0.2.0 - 2026-09-07

Experimental. This version needs a Yggdrasil newer than 5.8.0 — the first one that answers with the documents Horde now reads the graph through. Until that release is out, point the horde at a build of Yggdrasil's development branch: horde.mjs config set ygCommand "node path/to/bin.js". An older Yggdrasil is refused with that instruction, never read around.

Added

  • Horde now needs Yggdrasil, and sets it up for you. Starting a horde on a repository with no architecture graph creates one first; with Grain installed as well, that first graph is read out of your own code — the components you actually have and the rules you already follow — and you are told up front how much of the code you have today those rules would refuse. Without Yggdrasil it stops and says what to install. The old fallback, a second and weaker map the horde kept for itself, is gone: there is one architecture, the horde reads it and never writes it behind your back, and how current it is has one answer instead of two.
  • A promise between two parts of the system is now a real thing in the architecture rather than a note kept on the side, and it carries a version and the test that proves it. Proposing one — or raising its version — names that test and tells you who is still reading the old version; the architect approves it and is handed the exact change to make. Listing them shows what the architecture actually declares, not what somebody wrote down once.
  • Every role now carries the discipline it is held to, printed into its brief: how a test earns its place, what to do when three fixes in a row did not work, what a claim has to be backed by, how a finding is ranked, and what has to be agreed before anything is built. One text per discipline, so every agent in a role is held to the same words.
  • A discipline can be drilled: point it at a repository and it answers from the files and the branches, not from what an agent said. A real moment from a mission can be recorded as a case, and the recorded cases are re-checked as part of the test suite.
  • Sending a change back for fixes no longer loops forever. The first few rounds go back to the same worker; after that, a fresh, more capable one takes over with the full history handed to it; past a further, small number of rounds it stops asking and tells you a decision is needed instead.
  • A test that passes once and fails the next time is no longer treated as an ordinary failure or silently escalated to a person. Running it again catches the flake, sends the change back with an instruction to make the test reliable, and records what happened.
  • A part of the system that only its own author can review — nobody else assigned to judge it — is no longer stuck waiting forever. Whoever independently verified the change can approve it too, but only when there truly is no one else able to.
  • The merge checklist now judges the architecture on the branch itself, whatever else the gate runs. It first records, for free and with no key, every rule a script can decide; then it names every rule left that a reader has to judge, and those go to the ticket's verifier, whose brief carries the exact commands. The verifier's decision is recorded under its own name, so a later run can re-prove it without a key and the report says whose judgement it was. A change is ready to merge only when the whole architecture check comes out green. Starting a horde says that this is now part of every merge.
  • Showing a node now lists the rules its code must satisfy, each with what breaking it costs: one blocks the merge, one only warns, one is not in force yet. Owners and workers are told to read them before they touch the node.
  • Starting a horde now works out how this repository runs its tests — npm, Maven, Gradle, Cargo, Go, Python, Make — and what its tests are named, and says what it found. Where it can work out neither, it says that too and asks, instead of leaving a merge check that quietly passes on everything.
  • The merge check that proves a new test is load-bearing no longer passes silently on a repository whose tests it does not recognise: it refuses, and says which setting to fill in. When it does pass, it names the patterns it looked for.
  • A change that adds no test — a rename, a refactor, a settings change — can now be verified. It could not be before, and had no way to reach a merge at all.
  • A ticket can name one part of the system, or two when it connects them. Three or more is now refused instead of accepted quietly: nobody owns the whole of such a change.
  • Marking a ticket merged now records the merge everywhere it needs to be recorded. The mission's evidence list used to stay empty unless the same merge was entered a second time by hand.
  • The mission charter — the goal, what is out of scope, the evidence the mission is judged by, and every later amendment — can now be written and read with a command instead of by hand. Rewriting it reports what happened to the evidence list, and warns when a rewrite drops something a verifier already proved.
  • Settings that hold a list of values — the test patterns, the protected paths — can now be set to a list. They used to be stored as text and broke the merge check.
  • A ticket now says which files it touches, what it needs from the rest of the system, what it delivers to it, and which piece of the mission's evidence it earns. A file outside the part of the system the ticket is on is refused, and so is needing something nobody is building.
  • The order of the work is now computed from those tickets instead of typed in by hand: what can start now, what waits on what, the longest chain, which tickets would collide over the same file, who has to approve a change to something others depend on, and which promised evidence nobody has taken. It also says what the whole thing will cost in agent runs and how many rounds it needs. Two tickets waiting on each other is refused, with the circle named.
  • A change that touches a file its ticket never declared no longer merges. Widening the ticket is a command that records who widened it, so the reviewers see it happen.
  • When a ticket does have to go back for another look, that look now covers only what moved: the difference between what was approved and what is there now is written out for the owner and for a verifier, with every point the last review left open. A review of the whole change is still available.
  • Two missions on the same repository can no longer end up owning the same part of it at the same time. Claiming a part already claimed by another active mission is refused, naming which mission holds it and when it was last active; taking it over needs a ruling recorded first. Finishing a mission frees everything it held, and the status screen and the mission list both show who holds what.
  • A ticket can now be marked as quality work — a self-filed improvement outside a wave's assigned scope — rather than the mission's own work.
  • Handing out the next ticket now refuses one whose files would collide with a ticket already being worked on (a ticket that never said which files it touches is treated as touching all of them, to be safe); among what is left, whichever ticket has the most other work waiting behind it goes first, and a quality ticket always goes last, however urgent it looks. A new option explains the decision for every ticket still waiting: its place in line, or exactly what is holding it back.
  • The status screen now shows, for every piece of promised evidence in the mission, exactly how far along it is: nothing claims it yet, filed but not started, in progress, merged but not yet proven, or actually proven. A mission is no longer considered finished just because the work queue is empty — a command checks that every piece of evidence is proven, the whole repository still passes its checks, the sample audit found nothing wrong, and a cost report exists, and it refuses to call the mission done until all of that holds, naming exactly what is still missing. Deleting a promised piece of evidence from the mission's plan is free before any work has started on it; once work is under way, deleting it needs a recorded, approved exception.
  • Any line of code the horde ever merged can now be traced back to its full story: which commit introduced it, which ticket that commit belongs to, who wrote it, who reviewed it, who verified it and at what level, which pieces of evidence it was supposed to prove and whether they were, and what the architecture currently says about the rules standing over it. A closed mission's tickets are searched too, not just the ones still open. A line from before the horde ever touched the repository is reported as exactly that, instead of guessing.
  • A ticket that waits on another can now be started on top of it instead of after it, while the first is still being worked on and reviewed. A chain of three used to take three rounds of waiting even when each piece was an hour's work; now the second and third are written and reviewed alongside the first. They still merge in order, and the reviews of the later ones survive the earlier one landing. The plan says which tickets can be started this way.
  • Closing a round of work now reports the six things that say whether the mission is getting better at itself: how much work ran side by side against how much was planned to, how many reviews carried over without being redone, what share of audited work did not survive a second look and how confident that share is at this sample size, how many questions a person had to answer for each piece of work that landed, whether the repository's architecture rules came out of the round stronger or weaker, and how many people judged a rule by hand outside the normal review. Rules that got weaker are raised with you rather than logged and forgotten. Reading the architecture this way needs a current release of Yggdrasil; an older one is refused outright, naming which release to install, rather than read as loosely as it can be.
  • The audit is now a sample, not a ritual. Instead of always redoing one piece of merged work, the number is set by what the audits keep finding — it doubles when something is caught, thins out after a long clean run, and never drops to nothing. A command says how many to audit next and picks them at random.
  • When the same kind of question has been answered the same way three times about the same part of the system, that is a rule nobody has written down yet. A command finds those, shows the answers as evidence, and hands over the exact command that writes the rule into the architecture.
  • The test suite now walks the whole thing end to end, on the real tools rather than stand-ins: an empty repository with a little history, the architecture read out of that code and accepted into it, a mission opened on top, one ticket written, reviewed, verified and merged, the promised evidence turned green, the mission closed, and one merged line traced back to everyone who signed for it.

Fixed

  • A mission whose last round of work is already closed can now be finished. The audit that samples that round is done after it closes, and the final check kept asking for one it could no longer see.
  • The horde now improves the architecture wherever it works, and only ever asks you before making anything weaker. A rule that has proved itself is promoted on its own: first when it answers its own examples correctly, then to blocking after two rounds of work in which nothing new broke it and nothing is left outstanding — with the reason and the numbers written into the architecture's own history. Improvements the code itself suggests become their own low-priority tickets, worked after everything you asked for and never instead of it. Making a rule weaker, waiving one, or moving its review date stays yours: the horde has no way to do any of it without you. Every round of work ends with a plain list of what it raised and what that was based on, so you can undo any of it. One setting in the mission's charter turns the whole thing off, and a single ticket can be walled off from it on its own.

Changed

  • A review no longer expires just because someone else's work landed first. An approval and a verdict now hold for as long as the ticket's own change is the change that was read, so catching a branch up with the team costs nothing — the tests still run again on the result. Another look is asked for only when the catch-up really touched what the ticket does; how near it has to be before that happens is a setting. Ten tickets ready at once used to cost up to fifty-five verifications between them; now it is ten, plus the few the catch-up genuinely disturbed.

0.1.0 - 2026-09-04

Added

  • First version. A prototype, expect rough edges.