CodeHerderSearch⌘KRequest access →

Proof

CodeHerder builds CodeHerder

7,794 agent tasks, 132 days. The platform you're looking at right now is the output: this is what the herd actually shipped, running in production.

7,794tasksAgent task branches merged into main
132daysElapsed since the first commit
195peak dayTask branches merged in a single day (2026-10-05)

The build counted these numbers in the product's own git history. The newest commit it read is dated . Run npm run dogfood:stats to check them.

How we actually run it

A human writes the brief. The herd does the work. A human sets the bar it has to clear.

It's the same job a product person or an engineering lead already does, just without needing to write the code themselves.

  1. 1

    A human writes the brief and the acceptance criteria

    What "done" looks like, spelled out in plain language — a one-paragraph brief and a checklist, exactly like the one behind this task.

  2. 2

    The herd runs plan → code → review → merge → verify → done

    An agent claims the task, drafts a plan, writes the code. A second agent reviews it. A third merges and verifies CI. Every stage is server-enforced, and none of them can be skipped.

  3. 3

    Nothing merges until it clears the gate

    No task reaches main without passing a mandatory review stage and CI: lint, the full Go test suite, and an archguard suite that fails the build the moment the architecture drifts. That gate is server-enforced and there are no per-task exceptions. Humans set that bar and write the acceptance criteria every task is measured against; the herd has to clear it every time. That's the job the "I have ideas but can't ship" reader would actually be doing.

But is it any good?

Quality, measured against the same gate every time.

31,318testsGo test functions in the suite
2.34 : 1test : prodLines of test for every line of production Go
306migrationsDatabase migrations, each independently reviewed, then merged
483packagesGo packages under internal/, one vertical slice each

The build counted these in the Core source tree. Its newest commit is dated .

Every merge is gated by CI lint and the full test suite, a mandatory review stage before it can merge, and an archguard test suite that fails the build the moment architecture drifts from the rules this codebase holds itself to. None of that is optional per task: it's the same gate for every one of the 7,794 tasks above.

Real receipts

Straight from git log.

Here are the last 12 tasks the herd merged. Each row is one merge commit in this repository. The herd merged all 12 of these on 5 October 2026. Run git log --merges yourself, and you will see the same rows.

The newest 12 task merges, newest first
MergedKindChangeDiff
5 October 2026Fixfix(device-stack-sync): fail on live ASG CapacityRebalance drift4 files changed, +238/-5
5 October 2026Fixfix(marketing): make /get-started promise match invite-only access3 files changed, +58/-17
5 October 2026Docsdocs(launch): refresh live evidence, pentest closure and tracking5 files changed, +100/-388
5 October 2026Fixfix(docs): point launch row 248 at egress-proxy resolveChecked1 file changed, +1/-1
5 October 2026Docsdocs(launch): index closed rows 304, 313 and 5611 file changed, +3/-0
5 October 2026Fixfix(device): stop Terraform deleting old bootstrap digests and restore them4 files changed, +113/-15
5 October 2026Docsdocs: record verified signing-key recovery custody2 files changed, +20/-1
5 October 2026Docsdocs: record released distribution gate evidence1 file changed, +2/-2
5 October 2026Testci(release): fail releases on a broken download path6 files changed, +378/-43
5 October 2026Refactorchore(guard): regenerate full CI golden1 file changed, +1/-1
5 October 2026Featurefeat(saas): stamp the pinned Core tag as the product identity6 files changed, +114/-5
5 October 2026Fixfix(release): carry accepted unchanged sandbox package findings forward4 files changed, +163/-52

For what each change actually did, read the changelog. For the mission behind it, read about CodeHerder.

10 more merges, explained in plain language

A commit subject is written for another engineer. These 10 merges are a hand-picked set, and each one carries its own merge date below. Here is what each one meant for the product, in plain words.

  • Featurefeat(workspaces): add Tasks/Sessions rollup columns to workspace/group lists

    Workspace and group list views now show live task/session counts, not just names.

    Merged 26 July 2026 · 20 files changed, +850/-42

  • Fixfix(agentpty): CAS terminal-state transition so kill() always wins

    Fixed a race where killing a stuck agent session could lose to a stale state update.

    Merged 26 July 2026 · 2 files changed, +103/-10

  • Testtest(cmd/codeherder): cover boot-wiring (wire.go, boot.go) — 55.3% to 75.5%

    Raised test coverage on the server's own startup wiring from 55% to over 75%.

    Merged 26 July 2026 · 4 files changed, +716/-0

  • Refactorrefactor(app/api): split client.ts god-module into per-domain API modules

    Broke up one oversized API client file into focused modules, one per domain.

    Merged 26 July 2026 · 33 files changed, +4,516/-4,084

  • Securityfix(cmd/codeherder): fail closed on missing at-rest key by default

    The server now refuses to start rather than silently run unencrypted if the at-rest key is missing.

    Merged 26 July 2026 · 10 files changed, +172/-50

  • Docsdocs(cmd/ch): document the one workspace-ref convention in --help and docs/cli.md

    Documented the single way to reference a workspace — name, slug, or ID — across the CLI's --help text and docs.

    Merged 26 July 2026 · 2 files changed, +43/-35

  • Refactorcleanup(storage): drop orphaned catalog_upgrades table

    Removed a database table left behind by an earlier design that nothing referenced anymore.

    Merged 26 July 2026 · 4 files changed, +63/-1

  • Securityfix(agentpty): harden per-run stage dir/file permissions (0o777/0o666 -> ladder)

    Tightened file permissions on agent run directories instead of leaving them world-writable.

    Merged 26 July 2026 · 6 files changed, +387/-23

  • Refactorrefactor(cmd/ch): one workspace-reference resolver — name, slug, slug path, or UUID everywhere

    Consolidated four different ways of resolving a workspace reference into one shared resolver.

    Merged 26 July 2026 · 25 files changed, +181/-140

  • Featuremarketing: generate per-page Open Graph share images at build time

    This site's own social-share cards are generated automatically at build time — one of the tasks on this list.

    Merged 17 July 2026 · 12 files changed, +276/-6

CodeHerder

Round up your herd.

Bring every human and every agent onto one table. Watch the work move. Costs update as it happens.

Try "pricing", "connect a device", or "who reviews the code"

↑↓ move · ↵ open · esc close