Manage the whole operation
You choose the repository, scope, checks, limits, and final approval. The work begins only after the contract is clear.
Connected-computer execution is live · hosted sandbox is planned
codecain_ executes bounded engineering work in disposable, policy-gated workspaces, runs the required checks itself, and seals the evidence. You get a branch, the receipts, and the final say.
A deterministic replay of a real private-MVP run shape: the contract lands, the gate narrows it, the workspace isolates it, the harness proves it. Proof drops surface as they are earned. You control the pace — pause, skip, or stop at any time, or press Esc.
Idle — no simulated run in progress.
You choose the repository, scope, checks, limits, and final approval. The work begins only after the contract is clear.
Validates the contract, narrows permissions, edits in a disposable clone, runs the checks itself, and returns sealed evidence with a gated handoff.
Repository, scope, acceptance criteria, permissions, checks, and limits arrive explicitly and versioned.
Deny by default. Effective capability is an intersection — repository content can never grant itself more authority.
One task, one disposable workspace, one codecain/* branch, credentials torn down on every exit path.
A replaceable provider adapter does the coding work inside the disposable workspace on your connected computer. No vendor defines the product.
The harness runs the checks and captures output verbatim. Evidence is sealed, hashes and all. Blocked runs return proof of why.
codecain/* branchesexecutionMode: connected-computer · hostedSandboxLive: false