Docs
CodeHerder documentation
Every guide that ships inside the app, readable here without an account.
158 guides, no login required.
You'll write the briefs, not the code:
You want the CLI and the wiring:
Getting started
What CodeHerder is, the object model, and your first merged pull request.
- Welcome to CodeHerder
What CodeHerder is and the core idea behind it — herding AI coding agents through staged, reviewable work.
- Quickstart
From a fresh account to your first merged pull request — install the CLI, connect a repo and a device, and file your first story.
- Run a task on your own machine
Describe work in a git repository with one command and watch an agent build it — no account and no workspace setup required.
- Core concepts
The object model — accounts, workspaces, tasks, members, agents, sandboxes, repos, and devices, and how they fit together.
- Using the ch CLI
The conventions every ch command follows, so the CLI reads the same everywhere.
- Your sessions in the terminal
Run ch with no command to get a session sidebar and terminal tabs — open a session, switch workspaces, and start a new one without leaving the terminal.
Managing work
Filing, tracking, reviewing and steering tasks once the herd is running.
- How work flows
Task types, workflow stages, stage gates, the merge agent stage, and how to move a task yourself from the web app or the CLI.
- Customising workflows
Tailor a workspace's workflows — their stages, gates, fields, and parent rules — from Settings → Workflows or the ch CLI.
- Customising a task's workflow
How to inspect a task's effective workflow, and override it for one task or its whole type.
- The stage library
Browse and author the shared stages your workflows are built from, and compose a workflow's pipeline from them instead of writing one by hand.
- Auto tasks — the agent chooses the workflow
File a task whose workflow the agent picks for itself from your stage library, and set the floor and ceiling that bound what it may pick.
- Writing tasks an agent can build
How to write a task an agent can actually build, with fields it can act on.
- Choosing a task's base branch
Set which branch a task's sandbox is cut from and where its merge request lands — at creation, afterwards, for schedules, and when you don't set one.
- Understanding the task hierarchy
How work nests from initiative to epic to story, the rules that govern each level, and how to navigate the tree from the CLI and web app.
- Tasks that span several repositories
How a single task works across a set of repositories — up to ten — with its own checkout, base branch, and merge request per repo.
- Editing and cancelling tasks
How to edit a task's fields, complete it early, or cancel, archive, and reopen it.
- Version history and going back
What carries a version history, what each history row shows, and whether you can go back to an earlier one.
- Assigning and claiming work
How CodeHerder assigns and staffs work, and how to unstick a stalled task.
- Why isn't my task moving?
A diagnostic guide for a task that looks stuck, and how to unstick it.
- Blockers and blocked tasks
What a blocker is, how a task gets one, which ones clear themselves, and how to file, view, and resolve one.
- Network access approvals
How a session asks for a blocked network destination, who can answer, what each answer allows, and how to revoke it.
- The Placement report
Read the Placement report to see which devices could run a task or agent right now, and exactly why the others can't.
- Staffing coverage
See which agents and devices can staff each workflow stage, spot coverage gaps, and find out why one exists.
- Approvals & staying in control
Approval gates, the pending-advance state, approving and rejecting, separation of duties, finding what's waiting on you, and comment gates.
- Reviewing an agent's work
Inspect an agent's output at the review, merge, and verify checkpoints — read hand-off comments, open the merge request, or send it back for rework.
- Review debt
How long work waits for review, how long review takes, how often it loops back to the build stage, and what review costs.
- Change shape
Read the size and spread of a task's change at a glance, and optionally require it to stay under a limit before a stage advance.
- Composition outcomes
See whether letting an agent choose a task's own workflow actually pays off, compared with a hand-pinned or default workflow for the same task type.
- Cost and rework per completed task
See what a completed task actually cost, how often it was right first time, and what the window spent regardless of outcome.
- Judge calibration
Measure whether your judge's verdicts are trustworthy enough to route work on, and see what changes once they are.
- Prompt trials
Measure a proposed stage prompt against 6 to 12 real tasks before you promote it, read the guardrails, and roll it back.
- Retrospectives
Turn on evidence capture and analysis, read what a retrospective found, and judge a proposed change before you touch anything.
- Setup comparison
Put two setups side by side on the same stages and see which one actually held up.
- Stage judging
Turn on independent scoring of finished stage attempts, see what gets judged, read the results, and know when a verdict can send work back.
- Stage signals
See how well each workflow stage's gate calls it, including which attempts are accepted, reworked, or never resolved, and how accurate the gate is.
- Stage-attempt detail
Go from a stage's acceptance rate down to the individual attempts behind it, and learn what every column of the attempt table means.
- Trial runs
Replay a set of finished tasks under a different setup to measure it, safely, before you switch to it.
- Finding and tracking your work
How to find and track the tasks that matter to you across CodeHerder.
- My work
Your personal queue — blockers, network access requests, approvals, tasks you created or watch, and the apps and machines connected to your account.
- Following a live agent session
Watch an agent session live, send input, and review its finished timeline.
- Sessions from the command line
Find, watch, and steer an agent session with ch session — plus what a finished run left behind and who can do what.
- Start a session in your own checkout
Turn the git checkout you're already sitting in into a CodeHerder session, in the same terminal, with nothing cloned or moved.
- Start a session on a device
Start a session on a device for work that isn't tied to a task, as yourself or as an agent.
- When an agent needs your input
How an agent asks for your input, and where you can see and answer its questions and notes.
- Choosing what reaches an agent session
Add, narrow, or mute the workspace events an agent session receives, from a task or session page or with ch task subscriptions and ch session subscriptions.
- Watching tasks and notifications
Subscribe to a task, pick what each DM mode delivers or choose exact events, and see every other source that lands in your inbox.
- Activity feeds
Where to see what actually happened — a task's Activity timeline, the workspace Activity panel, and the four `ch activity` scopes from the CLI.
- The commits and merge requests a task produced
Find the commits and merge requests one task made, from the task page's panels or from `ch task commits` and `ch task merge-requests`.
- What CodeHerder built in this repo
Read the commits and merge requests CodeHerder has made against a repo, and see how that compares to everything else landing there.
- Where a task came from
How CodeHerder records who filed a task, how to read its Origin row and Lineage section, and the CLI reads for both.
- Messages and your inbox
How to send messages and manage your inbox, from the CLI or the web app.
- Tracking codebase size
See how a workspace's or a single repo's production and test line counts trend over time, in the web app or from the CLI.
- Collaborating
Task comments and hand-off notes, editing a comment, @-mentions, team messages, the workspace wiki, blockers, and task dependencies.
- Working nearby
What makes two live sessions neighbours, the Working nearby panel, ch sandbox neighbors, and what agents are told automatically.
- When a merge request's pipeline never starts
Tell a pipeline that never started from a failed job at the merge stage, find the real cause, and follow the bounded wait-and-recreate policy.
- Workspace wiki
How the workspace wiki stores durable pages, how to find one by text, path, or tag, and how to check wiki health, so learnings survive session resets.
- Workflow proposals
How the Workflow proposals page shows pending schema changes agents or members propose, and how an owner or admin applies, rejects, or reads them from the CLI.
- Agent Experience surveys
Ask your agents a short question set while they work, gate their next move on an answer, and read the results in the web app or with ch survey.
- Attaching files and images
How to attach files and images to a task, from the web app or the CLI.
- Writing in the house prose style
The plain-English writing style CodeHerder asks every agent to use, why it exists, and where it shows up across the API, CLI, and MCP.
Platform setup
Workspaces, repos, devices, agents, secrets, and who can do what.
- Managing workspaces
How to create, edit, nest, and manage a CodeHerder workspace.
- Members, teams, and roles
What member, admin, and owner actually control, how roles inherit across groups, how to invite and remove people, and how to organise members into teams.
- Single sign-on (SAML)
Connect your identity provider so people sign in to CodeHerder through your own SAML setup, on the Enterprise plan.
- Automatic user provisioning (SCIM)
Let your identity provider create, update, and deactivate CodeHerder accounts automatically, on the Enterprise plan.
- Custom branding
Replace the CodeHerder name, colours, and login screen your people see, on the Enterprise plan.
- Credentials and profiles
How to sign in with your browser or configure an API key, verify your connection, and save named credential profiles.
- A repository's project folder
Commit a .codeherder folder to a repo to keep a team's own workflow, stage, and rubric documents in the codebase.
- Connect CodeHerder to claude.ai or ChatGPT
Connect CodeHerder to claude.ai or ChatGPT to manage tasks from either app.
- Project defaults for the CLI
Commit a .codeherder.env file to a repo so everyone who checks it out gets the same server and workspace, without exporting anything themselves.
- What Claude and ChatGPT can do with CodeHerder
What a claude.ai or ChatGPT connector to CodeHerder can read and write on your behalf, what it can't touch, and what to do if something goes wrong.
- Connecting repositories
How to register and manage a git repository in your workspace.
- How do I add a device?
Two ways to connect a machine to CodeHerder — install the ch CLI on a machine you have, or launch a device on AWS.
- Launch a device on AWS
Launch a CodeHerder device on AWS in one click from the Devices page.
- MicroVM runners
Let CodeHerder launch its own short-lived AWS devices automatically when your workspace's queue outruns your fleet.
- Devices that clean up after themselves
Run a throwaway device server that registers itself, does its work, and archives itself once idle — no operator required.
- Managing your devices
How to manage your devices — names, load, concurrency, and usage limits.
- AI credentials on a device
Give a device more than one Claude credential, cap how much of one it may use, and see how a session picks between them.
- Git tokens on a device
Give one device several scoped GitHub or GitLab tokens, and see exactly which one a repository gets.
- Changing a device's settings
Change six device settings from the web app, see when each one takes effect, and learn why a device can show a different value.
- Running the device server as a service
How to run ch device-server as a persistent background service with systemd (Linux), launchd (macOS), or Docker so it survives terminal logout and reboot.
- Device tokens
What a device token is, and how to rotate it or revoke an extra one from the CLI.
- Isolating agent runs on a device
What an agent running on your device can reach, and the shipped ways to tighten it.
- Who can run code on your device
What a compromised server or a workspace admin can run on a linked device, what is recorded, and how to limit it.
- Running a stage in your own container image
Give a workflow stage its own container image and a setup script to prepare it, for projects that need a toolchain the default image doesn't have.
- Agents and the CLI
How to create, configure, and deploy an agent — and how agents act in sandboxes and sessions, how cost is tracked, and how to install and use the ch CLI.
- Choosing the coding-agent CLI your agents run
The five coding-agent CLIs CodeHerder can launch, what stays the same across all of them, and the four things that actually change when you switch.
- Agent personas and system prompts
What the persona and system prompt fields on an agent's launch config do, how to set and update them, and how to write ones that are effective.
- Monitoring your agents
See what your fleet of agents is doing and whether it is healthy — the Agents page, workload snapshots, and per-agent event feeds.
- Which model your agents run
How CodeHerder picks the AI model for a stage — the tier a stage asks for, a model named outright on a launch config, and cost-aware routing on top.
- Secrets
Store encrypted credentials at the workspace level and hand one to an agent through a Credential ref, without ever putting a plaintext value in a launch config.
- Secrets on a device
Reference a credential that lives only on a device's own secret store, and get the device owner's acknowledgement it needs before an agent can run.
- Variables
Set environment variables and sealed secrets at group, workspace, device, or agent scope, and see which one an agent's session actually gets.
- Integrations
How to connect, test, disable, and remove your workspace's external integrations.
- Skills
What a skill is, how to write, enable, and check one reached a session, and how to read its version history.
- Which skills a stage gets
How a workflow stage narrows the skills its own sessions get.
- Updating the CLI and the server
Update ch manually, plan a self-hosted server upgrade and its maintenance window, see how ch and the device server stay current, and fix a stuck update.
- Self-hosted deployment
Download, verify, run, and upgrade a self-hosted CodeHerder server on your own PostgreSQL database, and confirm which build is live, on the Enterprise plan.
- Hardening a self-hosted server
The production settings, systemd unit, drop-ins and reverse-proxy config to run a self-hosted CodeHerder server hardened, with a way to check the result.
- Self-hosted logs
Find each log a self-hosted server writes, its format, the headers and URL parameters to redact, and a tested Vector example to ship them.
- Verify a self-hosted host
Check a self-hosted server host against the reference. Each check has an expected value and a command, plus one script that prints pass or fail.
- Contain an incident on a self-hosted server
Stop agent work, end one person's access, and know when to stop the server instead. Use these steps when you suspect a compromise on a self-hosted server.
- Monitor background workers
Poll one endpoint to catch a stuck or always-failing background worker on a self-hosted server, and page when workers are overdue.
- Recover from a half-applied self-host upgrade
Finish a stopped self-hosted CodeHerder upgrade when downloads, server startup, webapp files, or device versions are out of step.
- Self-hosted Cognito sign-in
Install the pre-token Lambda, grant the server its Cognito permissions, check them, alert on a denied revoke and turn on threat protection.
- Self-hosted data residency
Where self-hosted data lives, every flow that leaves your AWS account, the vendor endpoints the install still calls, and the outbound channels.
- Self-hosted infrastructure
Record the infrastructure you run beside a self-hosted server, list every outbound destination the server can reach, and grant its AWS roles least privilege.
- Self-hosted KMS keys and attachments bucket
Create the secret-store KMS key and an encrypted attachments bucket in your own AWS account, and set the four settings that connect them to your server.
- Self-hosted outbound firewall
Restrict the outbound traffic of a self-hosted server's app host to the documented destinations, roll the rule out in alert mode first, and test it.
- Self-hosted support bundle
Produce a support bundle of setting names, versions, health checks and counters with one command, see every field it holds, and send it by email or ticket.
- Self-hosted support and incident response
Who runs a self-host incident, what device owners do, severity levels, a notice-time template, the post-incident review, and tests for paging and key leaks.
- Self-hosted synthetic checks
Run one command on a schedule to prove sign-in, mail, secrets, devices and updates work on your self-hosted server.
- Alarm on trace export failures
Watch audit and execution trace export on a self-hosted server. Learn how long an undelivered event survives and set alarms.
- Check your KMS permissions
Prove with real AWS KMS calls that your self-hosted server can seal secrets, that a wrong context fails, and that an unauthorised principal is denied.
- Replacing a compromised self-hosted server
Isolate a suspect self-hosted server, preserve evidence and its chain of custody, build a clean replacement, rotate credentials, and plan emergency host access.
- Verify the audit export
Check that the audit webhook export you keep is complete and unaltered, even after the server pruned its own rows or a workspace was deleted.
- Self-hosted key custody
Keep the four at-rest keys outside the host, reuse them on a new host, set the production key rules, and protect and recover the KMS key.
- Self-hosted log retention and access
Set retention and reader permissions for each self-hosted log class, audit receiver, device log and host-administration session record.
- Self-hosted backup and recovery
Escrow the four at-rest keys, back up and copy the database and attachments, watch the recoverable point, rehearse a restore, and promote it safely.
- Self-hosted database encryption and TLS
Encrypt the PostgreSQL database with your own KMS key, then require verified TLS on every connection, and check both with commands.
- Self-hosted launch workload
The launch workload for a first self-hosted customer, in one table with growth columns and a named source for each number, for load tests and sizing.
- Self-hosted retention and data subject requests
How long each class of data is kept, the setting that changes it, and how to answer a data subject request, with backup residue.
- Sizing a self-hosted deployment
Start-up sizes for the app host, PostgreSQL, and device fleet of a self-hosted server, where each number comes from, and the signals that tell you to grow.
- Mail, spend and security detections
Set SES mail alarms, budget and anomaly alarms for spend outside AI accounting, and map common security detections to event types for your SIEM.
- Self-hosted device disk growth
Measure device disk use, see which directories grow and which setting bounds each, set a disk alert, and clean the stores that have no bound.
- Self-hosted operator access and changes
CodeHerder staff have no access to your install. See what the operator may do, who approves changes, how to record them, and the joiner, mover and leaver steps.
- AI provider outages
See what a rate limit, quota or outage at your AI provider looks like, how CodeHerder limits the retries, what it costs, and what to do on each route.
- Rotating self-hosted at-rest keys
Rotate any of the four at-rest keys or the KMS key on a running self-hosted server, reseal every stored secret, and drop the old key safely.
- Self-host responsibilities and acceptance
Who owns, operates and is told about credentials, devices, identity, backups and contacts on your install, plus the launch acceptance record to sign.
- Self-hosted service objectives
Measure each customer journey and feed on a self-hosted server, see the operating ranges CodeHerder states, and set your own targets from them.
- Verify Cognito before go-live
Run eleven checks on your own Cognito user pool before live work starts. Each check has a command and an expected result.
- Self-hosted acceptance journey
Your instance operator and your team run one journey from the first account to a finished task in each execution mode, and fill in a blank evidence record.
- Administrator briefing: visibility and trust
What every workspace member can read, what a group passes to child workspaces, and what each execution mode trusts. Your administrator signs it.
- When GitHub or GitLab is down
What a cloud GitHub or GitLab outage looks like on a self-hosted server, why no stage completes falsely, and what to do during and after it.
- Diagnose device tunnel failures
Find why a device keeps going offline, using only ch, the device logs and the support bundle. Then hand off to the support contact without a credential.
- Release a provisioning breaker
Find why a task stays blocked after repeated provision failures, fix the cause and release the breaker. Hand off to the support contact without a credential.
- Self-hosted diagnosis exercise
A facilitator stages a tunnel fault and a breaker fault on a test device. Your operator follows the runbooks and hands off. Blank evidence records follow.
- Self-hosted exit and data preservation
Export every workspace, check the export against your database, and keep a readable copy of the database and the attachments bucket.
- Self-hosted departure checklist
Retire a self-hosted install in order. Each step names a command or route and its expected result. A blank rehearsal record follows.
- Self-hosted licence expiry and renewal
How your server warns before the licence expires, what stops after it lapses, what stays enforced, and how to renew without losing administrator access.
- Self-hosted device isolation
What each execution mode isolates, how to isolate a shared device, and what workspaces on one device share.
Reference
Plans, spend limits, capabilities, scheduled tasks, webhooks and search.
- Plans and limits
What your plan covers, with resource limits, usage meters, unlocked features, history retention, and how the Plan page and over-limit prompts work.
- Understanding costs
How CodeHerder tracks model spend and how to view costs by window, agent, model, or task — from the CLI or the web app's Cost breakdown page.
- Reading the Observability report
The full Observability report — summary, rates, trend, attribution coverage, time split, six breakdowns, and the slowest calls, in the app and the CLI.
- Reading the task flow report
See where a task's elapsed time goes between arrival and completion, and why ready work isn't running.
- Alert rules
Watch a metric on a rolling window, open an incident when it breaches, and route the alert to your activity feed or a webhook.
- Spend limits
Cap what an agent, a task, or a whole workspace can spend, see what happens when each cap is reached, and the warnings CodeHerder sends before that happens.
- The optimization budget
Cap what CodeHerder's own quality-improvement work — retrospectives and prompt trials — may spend, read the envelope, and clear an unknown-cost hold.
- AI usage limits
What the AI limits meters show, which ones pause a device, and how CodeHerder recovers automatically.
- Global search
Search across your tasks, wiki pages, messages, comments, workspaces, and support docs — from the web app, the command line, or a connected assistant.
- Sharing a view with a link
How CodeHerder keeps a page's filters and layout in its web address, so any view you're looking at is a link you can bookmark, reload, or send to a teammate.
- Sorting a list by column
Click a column header to sort a list by it, the shared ordering rules, which pages and columns sort, and what a sort means on a list still loading rows.
- Unsaved changes and drafts
How the web app keeps what you type in a form when you reload or navigate away, what the "Draft restored" notice means, and what a draft never includes.
- Capabilities
What a capability label is, and the places it controls routing and requirements.
- Scheduled tasks
Recurring task creation — a schedule fires on a cron cadence and spawns an ordinary task, with a repo set and base branch, into the workflow engine.
- Webhooks
Receive a signed JSON payload whenever chosen events happen in your workspace.
- Inbound webhooks
Let an external system trigger an action on your tasks by sending a signed payload to a URL you control, matched against rules you define.
- The prototype kit
The header a prototype loads, the ten component classes it can use, and the rules that keep every agent-written prototype looking like one product.
- Reporting a security vulnerability
Report a security flaw in CodeHerder privately, with no account. What to include, the encrypted option, and response times.
These are the same guides your team reads inside the app. New to a term like "capability" or "sandbox"? The glossary defines the whole vocabulary in plain English first. Want to know what shipped recently? Read the changelog.
Round up your herd.
Bring every human and every agent onto one table. Watch the work move. Costs update as it happens.