# CodeHerder documentation

Every guide that ships inside the app, readable here without an account.

Source: https://codeherder.com/docs/

Docs

Every guide that ships inside the app, readable here without an account.

158 guides, no login required.

You'll write the briefs, not the code:

1. [Welcome to CodeHerder](https://codeherder.com/docs/welcome/)
2. [Writing tasks an agent can build](https://codeherder.com/docs/writing-tasks/)
3. [Approvals & staying in control](https://codeherder.com/docs/approvals/)

You want the CLI and the wiring:

1. [Quickstart](https://codeherder.com/docs/quickstart/)
2. [Using the ch CLI](https://codeherder.com/docs/using-the-cli/)
3. [Capabilities](https://codeherder.com/docs/capabilities/)

## Getting started

What CodeHerder is, the object model, and your first merged pull request.

- [Welcome to CodeHerder](https://codeherder.com/docs/welcome/) What CodeHerder is and the core idea behind it — herding AI coding agents through staged, reviewable work.
- [Quickstart](https://codeherder.com/docs/quickstart/) From a fresh account to your first merged pull request — install the CLI, connect a repo and a device, and file your first story.
- [Run a task on your own machine](https://codeherder.com/docs/local-tasks/) Describe work in a git repository with one command and watch an agent build it — no account and no workspace setup required.
- [Core concepts](https://codeherder.com/docs/concepts/) The object model — accounts, workspaces, tasks, members, agents, sandboxes, repos, and devices, and how they fit together.
- [Using the ch CLI](https://codeherder.com/docs/using-the-cli/) The conventions every ch command follows, so the CLI reads the same everywhere.
- [Your sessions in the terminal](https://codeherder.com/docs/terminal-console/) Run ch with no command to get a session sidebar and terminal tabs — open a session, switch workspaces, and start a new one without leaving the terminal.

## Managing work

Filing, tracking, reviewing and steering tasks once the herd is running.

- [How work flows](https://codeherder.com/docs/how-work-flows/) Task types, workflow stages, stage gates, the merge agent stage, and how to move a task yourself from the web app or the CLI.
- [Customising workflows](https://codeherder.com/docs/task-types/) Tailor a workspace's workflows — their stages, gates, fields, and parent rules — from Settings → Workflows or the ch CLI.
- [Customising a task's workflow](https://codeherder.com/docs/workflow-overrides/) How to inspect a task's effective workflow, and override it for one task or its whole type.
- [The stage library](https://codeherder.com/docs/stage-library/) Browse and author the shared stages your workflows are built from, and compose a workflow's pipeline from them instead of writing one by hand.
- [Auto tasks — the agent chooses the workflow](https://codeherder.com/docs/auto-tasks/) File a task whose workflow the agent picks for itself from your stage library, and set the floor and ceiling that bound what it may pick.
- [Writing tasks an agent can build](https://codeherder.com/docs/writing-tasks/) How to write a task an agent can actually build, with fields it can act on.
- [Choosing a task's base branch](https://codeherder.com/docs/base-branch/) Set which branch a task's sandbox is cut from and where its merge request lands — at creation, afterwards, for schedules, and when you don't set one.
- [Understanding the task hierarchy](https://codeherder.com/docs/hierarchy/) How work nests from initiative to epic to story, the rules that govern each level, and how to navigate the tree from the CLI and web app.
- [Tasks that span several repositories](https://codeherder.com/docs/multi-repo-tasks/) How a single task works across a set of repositories — up to ten — with its own checkout, base branch, and merge request per repo.
- [Editing and cancelling tasks](https://codeherder.com/docs/editing-tasks/) How to edit a task's fields, complete it early, or cancel, archive, and reopen it.
- [Version history and going back](https://codeherder.com/docs/version-history/) What carries a version history, what each history row shows, and whether you can go back to an earlier one.
- [Assigning and claiming work](https://codeherder.com/docs/assigning-work/) How CodeHerder assigns and staffs work, and how to unstick a stalled task.
- [Why isn't my task moving?](https://codeherder.com/docs/task-not-moving/) A diagnostic guide for a task that looks stuck, and how to unstick it.
- [Blockers and blocked tasks](https://codeherder.com/docs/blockers/) What a blocker is, how a task gets one, which ones clear themselves, and how to file, view, and resolve one.
- [Network access approvals](https://codeherder.com/docs/egress-approvals/) How a session asks for a blocked network destination, who can answer, what each answer allows, and how to revoke it.
- [The Placement report](https://codeherder.com/docs/placement/) Read the Placement report to see which devices could run a task or agent right now, and exactly why the others can't.
- [Staffing coverage](https://codeherder.com/docs/stage-staffing/) See which agents and devices can staff each workflow stage, spot coverage gaps, and find out why one exists.
- [Approvals & staying in control](https://codeherder.com/docs/approvals/) Approval gates, the pending-advance state, approving and rejecting, separation of duties, finding what's waiting on you, and comment gates.
- [Reviewing an agent's work](https://codeherder.com/docs/reviewing-work/) Inspect an agent's output at the review, merge, and verify checkpoints — read hand-off comments, open the merge request, or send it back for rework.
- [Review debt](https://codeherder.com/docs/review-debt/) How long work waits for review, how long review takes, how often it loops back to the build stage, and what review costs.
- [Change shape](https://codeherder.com/docs/change-shape/) Read the size and spread of a task's change at a glance, and optionally require it to stay under a limit before a stage advance.
- [Composition outcomes](https://codeherder.com/docs/composition-outcomes/) See whether letting an agent choose a task's own workflow actually pays off, compared with a hand-pinned or default workflow for the same task type.
- [Cost and rework per completed task](https://codeherder.com/docs/outcome-cohorts/) See what a completed task actually cost, how often it was right first time, and what the window spent regardless of outcome.
- [Judge calibration](https://codeherder.com/docs/judge-calibration/) Measure whether your judge's verdicts are trustworthy enough to route work on, and see what changes once they are.
- [Prompt trials](https://codeherder.com/docs/prompt-trials/) Measure a proposed stage prompt against 6 to 12 real tasks before you promote it, read the guardrails, and roll it back.
- [Retrospectives](https://codeherder.com/docs/retrospectives/) Turn on evidence capture and analysis, read what a retrospective found, and judge a proposed change before you touch anything.
- [Setup comparison](https://codeherder.com/docs/setup-comparison/) Put two setups side by side on the same stages and see which one actually held up.
- [Stage judging](https://codeherder.com/docs/stage-judging/) Turn on independent scoring of finished stage attempts, see what gets judged, read the results, and know when a verdict can send work back.
- [Stage signals](https://codeherder.com/docs/stage-signals/) See how well each workflow stage's gate calls it, including which attempts are accepted, reworked, or never resolved, and how accurate the gate is.
- [Stage-attempt detail](https://codeherder.com/docs/stage-attempts/) Go from a stage's acceptance rate down to the individual attempts behind it, and learn what every column of the attempt table means.
- [Trial runs](https://codeherder.com/docs/trial-runs/) Replay a set of finished tasks under a different setup to measure it, safely, before you switch to it.
- [Finding and tracking your work](https://codeherder.com/docs/tracking-work/) How to find and track the tasks that matter to you across CodeHerder.
- [My work](https://codeherder.com/docs/my-work/) Your personal queue — blockers, network access requests, approvals, tasks you created or watch, and the apps and machines connected to your account.
- [Following a live agent session](https://codeherder.com/docs/following-a-live-session/) Watch an agent session live, send input, and review its finished timeline.
- [Sessions from the command line](https://codeherder.com/docs/session-cli/) Find, watch, and steer an agent session with ch session — plus what a finished run left behind and who can do what.
- [Start a session in your own checkout](https://codeherder.com/docs/local-sessions/) Turn the git checkout you're already sitting in into a CodeHerder session, in the same terminal, with nothing cloned or moved.
- [Start a session on a device](https://codeherder.com/docs/dev-sessions/) Start a session on a device for work that isn't tied to a task, as yourself or as an agent.
- [When an agent needs your input](https://codeherder.com/docs/agent-input/) How an agent asks for your input, and where you can see and answer its questions and notes.
- [Choosing what reaches an agent session](https://codeherder.com/docs/subscriptions/) Add, narrow, or mute the workspace events an agent session receives, from a task or session page or with ch task subscriptions and ch session subscriptions.
- [Watching tasks and notifications](https://codeherder.com/docs/watching/) Subscribe to a task, pick what each DM mode delivers or choose exact events, and see every other source that lands in your inbox.
- [Activity feeds](https://codeherder.com/docs/activity/) Where to see what actually happened — a task's Activity timeline, the workspace Activity panel, and the four `ch activity` scopes from the CLI.
- [The commits and merge requests a task produced](https://codeherder.com/docs/task-commits/) Find the commits and merge requests one task made, from the task page's panels or from `ch task commits` and `ch task merge-requests`.
- [What CodeHerder built in this repo](https://codeherder.com/docs/repo-activity/) Read the commits and merge requests CodeHerder has made against a repo, and see how that compares to everything else landing there.
- [Where a task came from](https://codeherder.com/docs/task-lineage/) How CodeHerder records who filed a task, how to read its Origin row and Lineage section, and the CLI reads for both.
- [Messages and your inbox](https://codeherder.com/docs/messages/) How to send messages and manage your inbox, from the CLI or the web app.
- [Tracking codebase size](https://codeherder.com/docs/codebase-size/) See how a workspace's or a single repo's production and test line counts trend over time, in the web app or from the CLI.
- [Collaborating](https://codeherder.com/docs/collaborating/) Task comments and hand-off notes, editing a comment, @-mentions, team messages, the workspace wiki, blockers, and task dependencies.
- [Working nearby](https://codeherder.com/docs/working-nearby/) What makes two live sessions neighbours, the Working nearby panel, ch sandbox neighbors, and what agents are told automatically.
- [When a merge request's pipeline never starts](https://codeherder.com/docs/ci-triage/) Tell a pipeline that never started from a failed job at the merge stage, find the real cause, and follow the bounded wait-and-recreate policy.
- [Workspace wiki](https://codeherder.com/docs/memory/) How the workspace wiki stores durable pages, how to find one by text, path, or tag, and how to check wiki health, so learnings survive session resets.
- [Workflow proposals](https://codeherder.com/docs/workflow-proposals/) How the Workflow proposals page shows pending schema changes agents or members propose, and how an owner or admin applies, rejects, or reads them from the CLI.
- [Agent Experience surveys](https://codeherder.com/docs/surveys/) Ask your agents a short question set while they work, gate their next move on an answer, and read the results in the web app or with ch survey.
- [Attaching files and images](https://codeherder.com/docs/attachments/) How to attach files and images to a task, from the web app or the CLI.
- [Writing in the house prose style](https://codeherder.com/docs/writing-style/) The plain-English writing style CodeHerder asks every agent to use, why it exists, and where it shows up across the API, CLI, and MCP.

## Platform setup

Workspaces, repos, devices, agents, secrets, and who can do what.

- [Managing workspaces](https://codeherder.com/docs/workspaces/) How to create, edit, nest, and manage a CodeHerder workspace.
- [Members, teams, and roles](https://codeherder.com/docs/members-and-teams/) What member, admin, and owner actually control, how roles inherit across groups, how to invite and remove people, and how to organise members into teams.
- [Single sign-on (SAML)](https://codeherder.com/docs/sso/) Connect your identity provider so people sign in to CodeHerder through your own SAML setup, on the Enterprise plan.
- [Automatic user provisioning (SCIM)](https://codeherder.com/docs/scim/) Let your identity provider create, update, and deactivate CodeHerder accounts automatically, on the Enterprise plan.
- [Custom branding](https://codeherder.com/docs/branding/) Replace the CodeHerder name, colours, and login screen your people see, on the Enterprise plan.
- [Credentials and profiles](https://codeherder.com/docs/credentials/) How to sign in with your browser or configure an API key, verify your connection, and save named credential profiles.
- [A repository's project folder](https://codeherder.com/docs/project-folder/) Commit a .codeherder folder to a repo to keep a team's own workflow, stage, and rubric documents in the codebase.
- [Connect CodeHerder to claude.ai or ChatGPT](https://codeherder.com/docs/connect-to-claude-or-chatgpt/) Connect CodeHerder to claude.ai or ChatGPT to manage tasks from either app.
- [Project defaults for the CLI](https://codeherder.com/docs/project-config/) Commit a .codeherder.env file to a repo so everyone who checks it out gets the same server and workspace, without exporting anything themselves.
- [What Claude and ChatGPT can do with CodeHerder](https://codeherder.com/docs/mcp-tools/) What a claude.ai or ChatGPT connector to CodeHerder can read and write on your behalf, what it can't touch, and what to do if something goes wrong.
- [Connecting repositories](https://codeherder.com/docs/repositories/) How to register and manage a git repository in your workspace.
- [How do I add a device?](https://codeherder.com/docs/adding-a-device/) Two ways to connect a machine to CodeHerder — install the ch CLI on a machine you have, or launch a device on AWS.
- [Launch a device on AWS](https://codeherder.com/docs/launch-a-device-on-aws/) Launch a CodeHerder device on AWS in one click from the Devices page.
- [MicroVM runners](https://codeherder.com/docs/microvm-runners/) Let CodeHerder launch its own short-lived AWS devices automatically when your workspace's queue outruns your fleet.
- [Devices that clean up after themselves](https://codeherder.com/docs/ephemeral-devices/) Run a throwaway device server that registers itself, does its work, and archives itself once idle — no operator required.
- [Managing your devices](https://codeherder.com/docs/devices/) How to manage your devices — names, load, concurrency, and usage limits.
- [AI credentials on a device](https://codeherder.com/docs/device-ai-credentials/) Give a device more than one Claude credential, cap how much of one it may use, and see how a session picks between them.
- [Git tokens on a device](https://codeherder.com/docs/git-tokens-on-a-device/) Give one device several scoped GitHub or GitLab tokens, and see exactly which one a repository gets.
- [Changing a device's settings](https://codeherder.com/docs/device-settings/) Change six device settings from the web app, see when each one takes effect, and learn why a device can show a different value.
- [Running the device server as a service](https://codeherder.com/docs/running-the-device-server/) How to run ch device-server as a persistent background service with systemd (Linux), launchd (macOS), or Docker so it survives terminal logout and reboot.
- [Device tokens](https://codeherder.com/docs/device-tokens/) What a device token is, and how to rotate it or revoke an extra one from the CLI.
- [Isolating agent runs on a device](https://codeherder.com/docs/agent-isolation/) What an agent running on your device can reach, and the shipped ways to tighten it.
- [Who can run code on your device](https://codeherder.com/docs/device-trust/) What a compromised server or a workspace admin can run on a linked device, what is recorded, and how to limit it.
- [Running a stage in your own container image](https://codeherder.com/docs/stage-images/) Give a workflow stage its own container image and a setup script to prepare it, for projects that need a toolchain the default image doesn't have.
- [Agents and the CLI](https://codeherder.com/docs/agents-and-cli/) How to create, configure, and deploy an agent — and how agents act in sandboxes and sessions, how cost is tracked, and how to install and use the ch CLI.
- [Choosing the coding-agent CLI your agents run](https://codeherder.com/docs/harnesses/) The five coding-agent CLIs CodeHerder can launch, what stays the same across all of them, and the four things that actually change when you switch.
- [Agent personas and system prompts](https://codeherder.com/docs/agent-personas/) What the persona and system prompt fields on an agent's launch config do, how to set and update them, and how to write ones that are effective.
- [Monitoring your agents](https://codeherder.com/docs/monitoring-agents/) See what your fleet of agents is doing and whether it is healthy — the Agents page, workload snapshots, and per-agent event feeds.
- [Which model your agents run](https://codeherder.com/docs/agent-models/) How CodeHerder picks the AI model for a stage — the tier a stage asks for, a model named outright on a launch config, and cost-aware routing on top.
- [Secrets](https://codeherder.com/docs/secrets/) Store encrypted credentials at the workspace level and hand one to an agent through a Credential ref, without ever putting a plaintext value in a launch config.
- [Secrets on a device](https://codeherder.com/docs/device-secrets/) Reference a credential that lives only on a device's own secret store, and get the device owner's acknowledgement it needs before an agent can run.
- [Variables](https://codeherder.com/docs/variables/) Set environment variables and sealed secrets at group, workspace, device, or agent scope, and see which one an agent's session actually gets.
- [Integrations](https://codeherder.com/docs/integrations/) How to connect, test, disable, and remove your workspace's external integrations.
- [Skills](https://codeherder.com/docs/skills/) What a skill is, how to write, enable, and check one reached a session, and how to read its version history.
- [Which skills a stage gets](https://codeherder.com/docs/stage-skills/) How a workflow stage narrows the skills its own sessions get.
- [Updating the CLI and the server](https://codeherder.com/docs/updating/) Update ch manually, plan a self-hosted server upgrade and its maintenance window, see how ch and the device server stay current, and fix a stuck update.
- [Self-hosted deployment](https://codeherder.com/docs/self-hosting/) Download, verify, run, and upgrade a self-hosted CodeHerder server on your own PostgreSQL database, and confirm which build is live, on the Enterprise plan.
- [Hardening a self-hosted server](https://codeherder.com/docs/self-host-hardening/) The production settings, systemd unit, drop-ins and reverse-proxy config to run a self-hosted CodeHerder server hardened, with a way to check the result.
- [Self-hosted logs](https://codeherder.com/docs/self-host-logs/) Find each log a self-hosted server writes, its format, the headers and URL parameters to redact, and a tested Vector example to ship them.
- [Verify a self-hosted host](https://codeherder.com/docs/self-host-host-verification/) Check a self-hosted server host against the reference. Each check has an expected value and a command, plus one script that prints pass or fail.
- [Contain an incident on a self-hosted server](https://codeherder.com/docs/self-host-incident-containment/) Stop agent work, end one person's access, and know when to stop the server instead. Use these steps when you suspect a compromise on a self-hosted server.
- [Monitor background workers](https://codeherder.com/docs/self-host-monitoring/) Poll one endpoint to catch a stuck or always-failing background worker on a self-hosted server, and page when workers are overdue.
- [Recover from a half-applied self-host upgrade](https://codeherder.com/docs/self-host-recovery/) Finish a stopped self-hosted CodeHerder upgrade when downloads, server startup, webapp files, or device versions are out of step.
- [Self-hosted Cognito sign-in](https://codeherder.com/docs/self-host-cognito/) Install the pre-token Lambda, grant the server its Cognito permissions, check them, alert on a denied revoke and turn on threat protection.
- [Self-hosted data residency](https://codeherder.com/docs/self-host-data-residency/) Where self-hosted data lives, every flow that leaves your AWS account, the vendor endpoints the install still calls, and the outbound channels.
- [Self-hosted infrastructure](https://codeherder.com/docs/self-host-infrastructure/) Record the infrastructure you run beside a self-hosted server, list every outbound destination the server can reach, and grant its AWS roles least privilege.
- [Self-hosted KMS keys and attachments bucket](https://codeherder.com/docs/self-host-kms-and-attachments/) Create the secret-store KMS key and an encrypted attachments bucket in your own AWS account, and set the four settings that connect them to your server.
- [Self-hosted outbound firewall](https://codeherder.com/docs/self-host-firewall/) Restrict the outbound traffic of a self-hosted server's app host to the documented destinations, roll the rule out in alert mode first, and test it.
- [Self-hosted support bundle](https://codeherder.com/docs/support-bundle/) Produce a support bundle of setting names, versions, health checks and counters with one command, see every field it holds, and send it by email or ticket.
- [Self-hosted support and incident response](https://codeherder.com/docs/self-host-support/) Who runs a self-host incident, what device owners do, severity levels, a notice-time template, the post-incident review, and tests for paging and key leaks.
- [Self-hosted synthetic checks](https://codeherder.com/docs/self-host-checks/) Run one command on a schedule to prove sign-in, mail, secrets, devices and updates work on your self-hosted server.
- [Alarm on trace export failures](https://codeherder.com/docs/self-host-trace-export/) Watch audit and execution trace export on a self-hosted server. Learn how long an undelivered event survives and set alarms.
- [Check your KMS permissions](https://codeherder.com/docs/self-host-kms-check/) Prove with real AWS KMS calls that your self-hosted server can seal secrets, that a wrong context fails, and that an unauthorised principal is denied.
- [Replacing a compromised self-hosted server](https://codeherder.com/docs/self-host-compromise/) Isolate a suspect self-hosted server, preserve evidence and its chain of custody, build a clean replacement, rotate credentials, and plan emergency host access.
- [Verify the audit export](https://codeherder.com/docs/self-host-audit-integrity/) Check that the audit webhook export you keep is complete and unaltered, even after the server pruned its own rows or a workspace was deleted.
- [Self-hosted key custody](https://codeherder.com/docs/self-host-keys/) Keep the four at-rest keys outside the host, reuse them on a new host, set the production key rules, and protect and recover the KMS key.
- [Self-hosted log retention and access](https://codeherder.com/docs/self-host-log-retention/) Set retention and reader permissions for each self-hosted log class, audit receiver, device log and host-administration session record.
- [Self-hosted backup and recovery](https://codeherder.com/docs/self-host-backups/) Escrow the four at-rest keys, back up and copy the database and attachments, watch the recoverable point, rehearse a restore, and promote it safely.
- [Self-hosted database encryption and TLS](https://codeherder.com/docs/self-host-database/) Encrypt the PostgreSQL database with your own KMS key, then require verified TLS on every connection, and check both with commands.
- [Self-hosted launch workload](https://codeherder.com/docs/self-host-workload/) The launch workload for a first self-hosted customer, in one table with growth columns and a named source for each number, for load tests and sizing.
- [Self-hosted retention and data subject requests](https://codeherder.com/docs/self-host-retention-and-dsar/) How long each class of data is kept, the setting that changes it, and how to answer a data subject request, with backup residue.
- [Sizing a self-hosted deployment](https://codeherder.com/docs/self-host-sizing/) Start-up sizes for the app host, PostgreSQL, and device fleet of a self-hosted server, where each number comes from, and the signals that tell you to grow.
- [Mail, spend and security detections](https://codeherder.com/docs/self-host-detections/) Set SES mail alarms, budget and anomaly alarms for spend outside AI accounting, and map common security detections to event types for your SIEM.
- [Self-hosted device disk growth](https://codeherder.com/docs/self-host-device-disk/) Measure device disk use, see which directories grow and which setting bounds each, set a disk alert, and clean the stores that have no bound.
- [Self-hosted operator access and changes](https://codeherder.com/docs/self-host-operator-access/) CodeHerder staff have no access to your install. See what the operator may do, who approves changes, how to record them, and the joiner, mover and leaver steps.
- [AI provider outages](https://codeherder.com/docs/ai-provider-outages/) See what a rate limit, quota or outage at your AI provider looks like, how CodeHerder limits the retries, what it costs, and what to do on each route.
- [Rotating self-hosted at-rest keys](https://codeherder.com/docs/self-host-key-rotation/) Rotate any of the four at-rest keys or the KMS key on a running self-hosted server, reseal every stored secret, and drop the old key safely.
- [Self-host responsibilities and acceptance](https://codeherder.com/docs/self-host-responsibilities/) Who owns, operates and is told about credentials, devices, identity, backups and contacts on your install, plus the launch acceptance record to sign.
- [Self-hosted service objectives](https://codeherder.com/docs/self-host-service-objectives/) Measure each customer journey and feed on a self-hosted server, see the operating ranges CodeHerder states, and set your own targets from them.
- [Verify Cognito before go-live](https://codeherder.com/docs/self-host-cognito-verification/) Run eleven checks on your own Cognito user pool before live work starts. Each check has a command and an expected result.
- [Self-hosted acceptance journey](https://codeherder.com/docs/self-host-acceptance-journey/) Your instance operator and your team run one journey from the first account to a finished task in each execution mode, and fill in a blank evidence record.
- [Administrator briefing: visibility and trust](https://codeherder.com/docs/self-host-admin-briefing/) What every workspace member can read, what a group passes to child workspaces, and what each execution mode trusts. Your administrator signs it.
- [When GitHub or GitLab is down](https://codeherder.com/docs/self-host-git-host-outage/) What a cloud GitHub or GitLab outage looks like on a self-hosted server, why no stage completes falsely, and what to do during and after it.
- [Diagnose device tunnel failures](https://codeherder.com/docs/self-host-tunnel-failures/) Find why a device keeps going offline, using only ch, the device logs and the support bundle. Then hand off to the support contact without a credential.
- [Release a provisioning breaker](https://codeherder.com/docs/self-host-provision-breaker/) Find why a task stays blocked after repeated provision failures, fix the cause and release the breaker. Hand off to the support contact without a credential.
- [Self-hosted diagnosis exercise](https://codeherder.com/docs/self-host-diagnosis-exercise/) A facilitator stages a tunnel fault and a breaker fault on a test device. Your operator follows the runbooks and hands off. Blank evidence records follow.
- [Self-hosted exit and data preservation](https://codeherder.com/docs/self-host-exit/) Export every workspace, check the export against your database, and keep a readable copy of the database and the attachments bucket.
- [Self-hosted departure checklist](https://codeherder.com/docs/self-host-departure/) Retire a self-hosted install in order. Each step names a command or route and its expected result. A blank rehearsal record follows.
- [Self-hosted licence expiry and renewal](https://codeherder.com/docs/self-host-licence/) How your server warns before the licence expires, what stops after it lapses, what stays enforced, and how to renew without losing administrator access.
- [Self-hosted device isolation](https://codeherder.com/docs/self-host-device-isolation/) What each execution mode isolates, how to isolate a shared device, and what workspaces on one device share.

## Reference

Plans, spend limits, capabilities, scheduled tasks, webhooks and search.

- [Plans and limits](https://codeherder.com/docs/plans-and-limits/) What your plan covers, with resource limits, usage meters, unlocked features, history retention, and how the Plan page and over-limit prompts work.
- [Understanding costs](https://codeherder.com/docs/costs/) How CodeHerder tracks model spend and how to view costs by window, agent, model, or task — from the CLI or the web app's Cost breakdown page.
- [Reading the Observability report](https://codeherder.com/docs/tool-time/) The full Observability report — summary, rates, trend, attribution coverage, time split, six breakdowns, and the slowest calls, in the app and the CLI.
- [Reading the task flow report](https://codeherder.com/docs/task-flow/) See where a task's elapsed time goes between arrival and completion, and why ready work isn't running.
- [Alert rules](https://codeherder.com/docs/alerts/) Watch a metric on a rolling window, open an incident when it breaches, and route the alert to your activity feed or a webhook.
- [Spend limits](https://codeherder.com/docs/spend-limits/) Cap what an agent, a task, or a whole workspace can spend, see what happens when each cap is reached, and the warnings CodeHerder sends before that happens.
- [The optimization budget](https://codeherder.com/docs/optimization-budget/) Cap what CodeHerder's own quality-improvement work — retrospectives and prompt trials — may spend, read the envelope, and clear an unknown-cost hold.
- [AI usage limits](https://codeherder.com/docs/ai-usage-limits/) What the AI limits meters show, which ones pause a device, and how CodeHerder recovers automatically.
- [Global search](https://codeherder.com/docs/search/) Search across your tasks, wiki pages, messages, comments, workspaces, and support docs — from the web app, the command line, or a connected assistant.
- [Sharing a view with a link](https://codeherder.com/docs/sharing-a-view/) How CodeHerder keeps a page's filters and layout in its web address, so any view you're looking at is a link you can bookmark, reload, or send to a teammate.
- [Sorting a list by column](https://codeherder.com/docs/sorting-lists/) Click a column header to sort a list by it, the shared ordering rules, which pages and columns sort, and what a sort means on a list still loading rows.
- [Unsaved changes and drafts](https://codeherder.com/docs/unsaved-drafts/) How the web app keeps what you type in a form when you reload or navigate away, what the "Draft restored" notice means, and what a draft never includes.
- [Capabilities](https://codeherder.com/docs/capabilities/) What a capability label is, and the places it controls routing and requirements.
- [Scheduled tasks](https://codeherder.com/docs/scheduled-tasks/) Recurring task creation — a schedule fires on a cron cadence and spawns an ordinary task, with a repo set and base branch, into the workflow engine.
- [Webhooks](https://codeherder.com/docs/webhooks/) Receive a signed JSON payload whenever chosen events happen in your workspace.
- [Inbound webhooks](https://codeherder.com/docs/inbound-webhooks/) Let an external system trigger an action on your tasks by sending a signed payload to a URL you control, matched against rules you define.
- [The prototype kit](https://codeherder.com/docs/prototype-kit/) The header a prototype loads, the ten component classes it can use, and the rules that keep every agent-written prototype looking like one product.
- [Reporting a security vulnerability](https://codeherder.com/docs/security-reporting/) Report a security flaw in CodeHerder privately, with no account. What to include, the encrypted option, and response times.

These are the same guides your team reads inside the app. New to a term like "capability" or "sandbox"? The [glossary](https://codeherder.com/glossary) defines the whole vocabulary in plain English first. Want to know what shipped recently? Read the [changelog](https://codeherder.com/changelog).
