A delivery workflow
for your coding agents.
You ask for a change. Assay turns your request into a brief, coordinates the agents, and records review and verification. You control the merge and consequential decisions.
From request to a checked result
Ask for a change
You · goal + constraints
Define the work
Planner · brief + checks
Build in isolation
Worker · draft PR
Review separately
Reviewer · attributed verdict
Decide to merge
You · human decision
Verify on main
Non-author · recorded evidence
Keep using the agents you know.
Assay adds the work orders, handoffs and evidence that let them work together.
Intake through verification on main. Release and deployment are outside this flow.
The precise claim
Assay doesn't certify that agent output is correct. It certifies who verified it, how, and when. That is narrow on purpose: it's the claim that survives an audit.
- Five desks, attributed separately. Five desks take a brief from intake to a verified merge. Review and verification are posted by identities you configure so the author cannot post as them: segregation of duties between the agent that writes and the agent that verifies. That is a claim about attribution, not proof a review was thorough. In Solo mode one login holds every role, and this separation does not exist. Merging is a person's.
- Verified after the merge. After the merge, a non-implementer re-runs the brief's Verify table on main and records the evidence. Implementers stop at implemented.
- A computed board. Nobody types the status board. It is computed from an append-only evidence record, and the build fails if the paperwork does not reconcile. It is derived from agent-authored artifacts with consistency linting, not measured from ground truth.
- todo
- in progress
- implemented
- verified
- done
- Start small. Apache 2.0. One binary in CI, one reviewer identity, draft PRs only. The install and GitHub Apps pages carry the setup cost in full.
What Assay does not claim
- Not a replacement for your SDLC, QA, security review, or your auditors. It is a control layer inside the regime you already run.
- Not a certification, a seal, or a regulatory safe harbor. It produces evidence; your assessors weigh it.
- Not tamper-proof. Tamper-visible, contingent on your branch protection and required checks staying enforced.
- Not a guarantee that agents write correct code. Verification exists precisely because they sometimes don't. Assay does not make agents trustworthy; it makes drift, missing evidence, and register tampering machine-visible.