Skip to content

tryveto/veto-codex

v2026.9.1203

How Veto works in Codex: research, design, implementation, verification and durable handoffs.

Veto Codex release 2026.9.1203

Renamed from Veto Stack 2026.9.1202. The entry skill is now veto-codex; the other twelve skill names and nine role responsibilities remain. Source checks, installation guidance, and presentation metadata follow the rename. Historical evidence remains historical.

Added the final-integrated-candidate replay rule to the existing verification and finish procedures. No new public skill, external service, hook, or permission is introduced. See the current verification note for what was actually tested.


2026.9.1202 — Repository and portable roles

Adds an offline, checked role-context reader and conditional entry routing. Keeps all 13 public skills and the nine original role guides. Adds no hooks, model configuration, credentials, or host automation. The enclosing repository provides the readable guide, tests, and deterministic release tooling. Native qualification remains unrun. Historical records below retain their original scope.

2026.9.1201 — Agent-native method

Upgrade of supplied 1111. Retains all 13 public skill names, nine role guides, goal templates and existing acceptance/feedback tools.

  • Tighten the existing entry point and add five contextual lifecycle playbooks.
  • Reuse the live repository's verify-veto route; do not create another harness.
  • Add read-only, candidate-bound handoff integrity checks and a worked example.
  • Repair goal-routing hints and mandatory nonempty/same-task/state-consistent readbacks.
  • Make the existing prompt reminder conditional, never an authorization assertion.
  • Add regressions and native qualification specifications; provide the enclosing marketplace and an existing-install upgrade/rollback work order.

No native host installation, product change, new automatic hook or release performed.

Earlier release history

Changelog

2026.9.1111 — native goal and blocked-title guards

Built in place on 1110. The 13 public skill names and nine role guides remain; the first two state hooks now have one explicit, testable boundary.

  • Add a pure guard for explicit native-goal adoption: read the current goal, use only a supported create/update operation, and verify the same task's active objective before reporting success.
  • Keep document-only goal drafts separate from native state, preserve active or paused goals when replacement is unsupported, and keep completion a separate user-authorized action.
  • Add idempotent one-prefix 🛑 title planning for genuine blockers while preserving renamed base titles and requiring title readback.
  • Route the existing prompt reminder through the package helper without adding a second writer, automatic mutation, service, telemetry or permission. Add 24 focused helper regressions and E100–E104 behavior specifications; native and agent outcomes remain unproven until observed in a supported task.

2026.9.1110 — decision continuity and catalog check

Built in place on 1109. Same 13 public skill names and nine role guides; adds a focused continuity reference and repairs the package's real multi-plugin marketplace check.

  • Adapt the useful Veto subset of the separate decision-recording and AI-workflow utilities into one conditional decision/correction reference.
  • Route “record why we chose this,” “revisit the reasoning,” and recurring-mistake repair through the existing independent-judgment and work-control entries.
  • Allow unrelated marketplace entries while rejecting duplicate canonical entries; archived Veto cards remain an explicit warning until the host supports per-entry retirement.
  • Add two marketplace-helper regressions and two behavioral specifications. No automatic memory, queue, service, permission or product action is added.

2026.9.1109 — source and identity boundaries

Built on 1108. Same 13 skills and nine role guides; executable helpers, test implementations, goals and acceptance schemas unchanged.

  • Added selective Git guidance for isolated writers, intended commits, exact reviewed/integrated identity, effective gates and preservation-first recovery.
  • Added selective WorkOS guidance for separate environments, stable callbacks, canonical admission, current-context assurance, logout and causal negative tests.
  • Refined existing release guidance: guarded current-main eligibility where active, final post-auth target, intermediate-version evidence and configuration identity.
  • Routed the methods through existing implementation, integration, testing and lead entries; preserved the enforced unattended production-verification boundary.
  • Added E86–E97 as behavioral specifications, not executed model trials. Retained all 85 earlier cases unchanged. Archived original source skills outside discovery.

See source decisions and verification.

2026.9.1108 — candidate-bound delivery

Built on 1107, not the reuploaded 1106 reference. Keeps 13 skills and nine role guides.

  • Add one conditional reference connecting canonical source, sandbox transfer, branch preview, shared promotion and production-readiness evidence through existing repository procedures.
  • Require observed remote identity, relevant readiness and actual journey evidence; distinguish source, artifact, configuration, schema and exposure. No local-SHA fallback or green-HTTP shortcut.
  • Preserve exact-candidate authority, shared-preview ownership, environment-specific build qualification and recovery for code, state and effects. No new publisher, controller, scheduler or credentials.
  • Add source-attributed WorkOS organization-switch and Records/backend regressions; preserve normal admission, run limits and observable termination.
  • Clarify unknown-impact CI selection, trusted gate policy, authorization of replayed results and the operator's requested delivery stage.
  • Add E78–E85 as unexecuted behavioral specifications. Goals, helpers, executable tests, original fixtures and existing acceptance/feedback schemas are unchanged.

See source decisions and verification.

2026.9.1107 — risk-weighted engineering

Built from the supplied 1106 archive. Keeps 13 skill names and nine role guides.

  • Add conditional engineering-quality and design-system references to existing build/design/test routes; no codebase, toolchain or CI migration.
  • Add bounded WorkOS production-verification planning and an inactive request template. Real admission/MFA, subtractive limits and observable termination remain implementation/approval prerequisites, not claimed capabilities.
  • Add the existing-launcher startup fast path, review-coverage versus candidate-health distinction, and evidence-based correction of the agent's own diagnosis.
  • Preserve the integration sample as an inactive exact source. Add E70–E77 as unexecuted behavior scenarios.
  • Preserve all executable helpers/tests, goal templates, feedback schemas and existing evidence controls. No installed runtime, permission or product change.

See source decisions and verification.

2026.9.1106 — stable local review

  • Extends the existing build method with an owned, reproducible local lifecycle and separate fast-edit versus packaged-runtime evidence.
  • Makes the existing review loop preserve original saved state, distinguish replay/reference identity, check source/served identity at start and end, and use bounded raw observations across an authorized collector/reviewer handoff.
  • Adds one optional Markdown observation template carried as an existing manifest evidence file; no schema or helper change.
  • Updates adoption with the supplied 1104 review's held-out omission plus correct-repair comparison and a fresh-context transfer check. The feedback-required remedy was already in 1105 and remains unchanged.
  • Consolidates reuploaded organization skills without adding active skills, roles, services, hooks or permissions. Both goal templates remain byte-identical to 1105.
  • Adds E67–E69 behavioral specifications and refines E51/E63; no agent trials claimed. All 177 helper/package tests remain the unchanged executable suite.

2026.9.1105 — adoption and correct-layer recovery

  • Consolidate six supplied skills into existing lead, team, work-order and feedback guidance; keep all 13 active entry points and unchanged goal templates.
  • Put approved HTTP preflight before the first browser navigation; distinguish URL, site, app, reviewer and application failures before proposing changes.
  • Restrict the optional reviewer-policy discussion to an evidenced reviewer-layer defect. The reported pre-approval URL denial is not repaired by that prompt.
  • Add optional --require-feedback to the existing checker, rejecting evidence-only contracts for a feedback-required invocation without breaking legacy use.
  • Report checked package version/path in doctor, explicitly not an attestation of runtime loading.
  • Add one adoption guide connecting the existing coverage/replay/closeout route, actual handoff acceptance and matched behavior evaluation. No automatic enforcement, new scheduler or runtime changes.

2026.9.1104 — Feedback coverage and exact diagnosis

  • Connect original annotation capture, independent coverage audit and candidate verification in existing work-control/product-tests/build routes.
  • Extend the existing receipt checker with pinned schema-2 feedback coverage; keep schema-1 evidence-only compatibility explicit.
  • Add approved HTTP browser preflight and narrow failure diagnosis; preserve prior denials and current permissions.
  • Document action/effect/authority context and a non-installed approver clarification; never replace active policy with a fragment.
  • Preserve skill inventory, roles, product direction, goal IDs and existing implementation. No scheduler, hooks, deployment or policy changes.

Changelog

2026.9.1103 — bounded bets and work control

  • Added one focused work-control skill: input delivery versus intent versus authority; batching, milestone dependencies, pause and in-flight reconciliation, adopted steering, current assignment revisions and late returns.
  • Improved product-sense with the supplied Shape Up study's bounded commitments, real appetite and deliberate next-bet decision; no six-week calendar, Basecamp migration or token quota.
  • Reworked make-a-goal and provided two sub-4,000-character drafts: the full accepted vision with a current bet, and a finite bet that retains parent obligations. No silent deletion of AC-01–07 or goal activation.
  • Incorporated supplied surfaces, primitives and PM guidance and conditional financial-phone guidance without creating duplicate broad skill routers. Added the supplied Prepare This Review HTML unchanged as a clearly scoped synthetic reference.
  • Kept all 12 prior skill names, role ownership, no-eyebrow rule, review-pack helper, pinned-contract receipt checks and heuristic slop scanner. No new executable scheduler or provider.
  • Added structural regression checks and behavioral test specifications. Local package checks are separate from unrun native-host and agent-performance trials.

2026.9.1102 — Stripe-inspired product organization

Updated the whole operating model, not only appearance: user evidence, complete first use, direct artifact review, fast safe change, reusable friction reduction and earned independent opinions. Preserved all nine original skill names and added prototype review, independent judgment and sandbox experience. Rewrote shared team and nine role guides; updated the bounded goal and work/decision templates.

Added an optional standard-library review-packet validator/builder with separately pinned scope, state coverage, explicit-file allowlisting, hashes, neutral first-pass packaging and clear partial outcomes. Retained receipt validation and heuristic slop scanning. Added regression tests and behavioral evaluation specifications, without claiming agent-performance improvement.

Mapped the supplied Stripe study and nine unique skill sources; kept later/public practices distinct from early history and our adaptation. Added the prototype-sharing and autonomous-review operating guide. No native host change, MCP, hooks, scheduler, application deployment, automatic installation or new permissions.

Previous release history

Changes

2026.9.1101 — 11 September 2026

Consolidated the available Veto Stack, feature-team guidance and six supplied skills into nine purposeful workflows with shared references. Preserved product meaning and the latest actual pause/resume authority rather than hardcoding a screenshot's past state.

Added source/adoption mapping for the surfaces, first-feature, integrations and product-manager studies. Included portable root packaging, OpenAI compatibility presentation, Claude Code metadata and a local OpenAI marketplace wrapper. No external services, hooks, network helper, automated installer or telemetry were added.

Replaced receipt-selected acceptance with a separately pinned contract, while stating that hashes do not prove truth or permission. Changed literal slop matches to contextual review candidates so a functional label is not automatically condemned by its class name. Added three starter fixtures, eighteen authored behavior scenarios, oracle-sensitivity checks and local helper tests.

This is a product-development edition, not a verified refresh of every capability in the user's running installation. See migration and verification.