Skip to content

feat: autonomous agent org — roles, peer review, intake, live demo - #2

Closed
bashebr wants to merge 23 commits into
mainfrom
feat/agent-org
Closed

bashebr wants to merge 23 commits into
mainfrom
feat/agent-org

Conversation

@bashebr

@bashebr bashebr commented Aug 28, 2026 •

Copy link
Copy Markdown
Owner

What

Adds the autonomous agent org capability to ai-native-sdlc: scaffold named, role-based agents into any project so the SDLC loop runs with peer review and less human steering.

  • init_org.py scaffolds org/ — org chart, role cards (CEO-human, CTO, PM, product engineering agent, engineers, reviewer), reporting/peer-review/escalation protocol, status + review queue, multi-channel intake.
  • sync_issues.py — GitHub issue intake: pull open issues into org/intake/github/ (idempotent, state-tracked) and push feature tickets.
  • Human involvement stays at the critical gates: PM first review of intents (CEO on ambiguity), CEO on unresolved spec/plan disagreement, and CEO approval for PR merge and release.
  • Expense-tracker example is now a real static app (HTML/CSS/vanilla JS, localStorage) with no API calls and no secrets — no backend, no keys, no external requests.

Live demo

https://bashebr.github.io/ai-native-sdlc/ — hosted on GitHub Pages from the gh-pages branch (the app also runs locally and is Vercel-ready via vercel.json).

How to use

python3 skills/ai-native-sdlc/scripts/init_workflow.py my-project --name "My idea" --git
python3 skills/ai-native-sdlc/scripts/init_org.py my-project

See skills/ai-native-sdlc/references/org.md and docs/superpowers/specs/2026-08-28-agent-org-design.md.

Validation

  • quick_validate.py: 80 passed, 0 failed
  • test_gate.sh: 25 passed, 0 failed
  • test_init.sh / test_init_org.sh: pass
  • unittest discover -s tests: 23 tests OK
  • Secret scan: no API keys/tokens/credentials in the tree, git history, gh-pages branch, or served HTML.

bashebr added 22 commits August 22, 2026 22:34
- production-gate.sh: match deploy actions (kubectl/helm/terraform/etc.)
  instead of the word 'deploy'; read-only allowlist ends doc-read false
  positives; RELEASE_APPROVAL_EXPIRY (ISO-8601 or epoch, fail-closed);
  jq-independent JSON parsing for hook stdin mode
- quick_validate.py: self-contained skill/plugin validator (frontmatter,
  plugin.json sync, YAML/JSON parse, bash -n, gate suite, scaffold smoke)
- run_evals.py: eval-suite runner for Phase 4 with JSON eval format,
  --min-pass-rate gating, --record history; agent-evals.yml.example now
  calls it (previously referenced a nonexistent check.sh)
- detect_bands.py: Phase 6 control-band reference implementation
  (rolling-30d mean/sigma, Western Electric rules, drift rule)
- init_workflow.py: scaffold workflow-graph.yaml, .gitignore, evals/README;
  add --dry-run, --git, --name validation
- New templates: runbooks/rollback-deploy.md (fixes dangling bands.yaml
  route), incident.md, PULL_REQUEST_TEMPLATE.md, evals.example.json,
  project workflow-graph.yaml
- tests/ (gate 21 cases, init, band detector, eval runner) and
  .github/workflows/self-check.yml so the repo practices what it preaches
- SKILL.md: version field, rule->enforcement compliance matrix, self-test;
  README/AGENTS.md validation instructions point at real artifacts;
  CHANGELOG.md, SECURITY.md
- gate_ledger.py: record/list/verify a hash-chained gates/ledger.jsonl
  (every gate decision is a committed, tamper-evident record); verify
  --require-committed rejects uncommitted ledgers; --graph --require-gates
  enforces completeness against workflow-graph.yaml; duplicate ids are
  rejected (append-only)
- production-gate.sh: RELEASE_APPROVAL=ledger:<id> verified against the
  ledger (committed, approved, unexpired) before a deploy is allowed;
  tampered/uncommitted/unknown records BLOCK
- Scaffold copies gate_ledger.py, run_evals.py, detect_bands.py, and
  gates/README.md into new projects
- tests: 6 ledger unit tests (chain, tamper, expiry, decision, committed,
  graph completeness) + 4 gate integration cases (uncommitted blocks,
  valid allows, unknown blocks, tampered blocks)
- quick_validate, SKILL.md (matrix + assets/scripts), README, CHANGELOG
  updated
GitHub Actions runners have no user.name/user.email configured, so the
temp-repo commits in test_gate_ledger.py (test_require_committed) and the
ledger section of test_gate.sh failed with exit 128, breaking the
self-check job. Set a local identity in both fixtures.

Verified by running the full suite with an empty HOME (simulating the
runner's missing git config): gate, init, 19 unit tests, quick_validate
51/51 all green.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 40a7881049

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +135 to +136
max_seen = max([last_seen] + [int(i["number"]) for i in new_issues])
state[key] = max_seen

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Page intake before advancing its high-water mark

gh issue list --help describes --limit as the “Maximum number of issues to fetch,” so a repo/filter with more than 100 open issues is only partially read here. If that page contains issue #500 but omits an older #200, this records 500 as the state; all later runs discard #200 because it is no longer greater than last_seen, permanently losing that demand from intake. Paginate through the initial result set or track processed issue IDs/files instead of advancing a numeric high-water mark from a partial page.

Useful? React with 👍 / 👎.


try:
if args.command == "pull":
return _pull(Path(args.config), args.dry_run)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Resolve intake paths from the scaffolded project

Following the documented adoption command in references/org.md:94 from the parent directory leaves this default path relative to that parent rather than to my-project. The configured my-project/org/intake/config.json is therefore ignored; _load_json falls back to {}, and a real pull targets the current GitHub repository and writes ./org/... outside the scaffolded project. Anchor the default config and its relative state/output paths to the script's project root, or require cd my-project before invoking the script.

Useful? React with 👍 / 👎.

Comment on lines +148 to +151
const imported = JSON.parse(String(reader.result));
if (!Array.isArray(imported)) throw new Error("not an array");
state.expenses = [...state.expenses, ...imported];
save();

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Validate imported records before persisting them

A syntactically valid JSON array is accepted without validating its entries. For example, importing [{}] appends and saves the object before render() throws on e.date.startsWith; the catch only shows an alert, so the malformed data remains in localStorage. On the next reload, load() returns that saved array and the initial render throws uncaught, leaving the demo unusable until the user manually clears site storage.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant