Skip to content

A delivery workflow
for your coding agents.

You ask for a change. Assay turns your request into a brief, coordinates the agents, and records review and verification. You control the merge and consequential decisions.

From request to a checked result

  1. Ask for a change

    You · goal + constraints

  2. Define the work

    Planner · brief + checks

  3. Build in isolation

    Worker · draft PR

  4. Review separately

    Reviewer · attributed verdict

  5. Decide to merge

    You · human decision

  6. Verify on main

    Non-author · recorded evidence

Illustrative flow · you initiate the work and control the merge. Select a step for its detailed guide.

Keep using the agents you know.

Assay adds the work orders, handoffs and evidence that let them work together.

Start with one repository.

Set up Assay in one repository.

Read the setup requirements

Intake through verification on main. Release and deployment are outside this flow.

The precise claim

Assay doesn't certify that agent output is correct. It certifies who verified it, how, and when. That is narrow on purpose: it's the claim that survives an audit.

  • Five desks, attributed separately. Five desks take a brief from intake to a verified merge. Review and verification are posted by identities you configure so the author cannot post as them: segregation of duties between the agent that writes and the agent that verifies. That is a claim about attribution, not proof a review was thorough. In Solo mode one login holds every role, and this separation does not exist. Merging is a person's.
  • Verified after the merge. After the merge, a non-implementer re-runs the brief's Verify table on main and records the evidence. Implementers stop at implemented.
  • A computed board. Nobody types the status board. It is computed from an append-only evidence record, and the build fails if the paperwork does not reconcile. It is derived from agent-authored artifacts with consistency linting, not measured from ground truth.
    1. todo
    2. in progress
    3. implemented
    4. verified
    5. done
  • Start small. Apache 2.0. One binary in CI, one reviewer identity, draft PRs only. The install and GitHub Apps pages carry the setup cost in full.

What Assay does not claim

  • Not a replacement for your SDLC, QA, security review, or your auditors. It is a control layer inside the regime you already run.
  • Not a certification, a seal, or a regulatory safe harbor. It produces evidence; your assessors weigh it.
  • Not tamper-proof. Tamper-visible, contingent on your branch protection and required checks staying enforced.
  • Not a guarantee that agents write correct code. Verification exists precisely because they sometimes don't. Assay does not make agents trustworthy; it makes drift, missing evidence, and register tampering machine-visible.