Plan before code
We write down goals, risks, and user value before agent flows implement.
We hire people who want to build with agents — not only use them. From PRD to reviewed PR, specialised AI agents run implementation and verification; humans own prioritisation, quality, and decisions. Home care is the hard real-world domain where the workflow has to prove itself.

Build-first means: plan before code, small vertical releases, traceability, and human responsibility before automation — the same continuous learning loop as the product itself.
We write down goals, risks, and user value before agent flows implement.
AI can produce a lot, but code, design, content, and data flows are reviewed as product work.
Home care is the proving ground: planners, caregivers, clients, and family — not a demo sandbox.
We prefer useful improvements that can be tested, measured, and improved over large opaque leaps.
Delivery mandate
Product owners write a PRD with change, success metric, and non-goals. Darwin then runs preflight, intake, scope, a native implement session (spec + tests + code + dossier), verify, and the external reviewer loop — humans approve the evidence before merge.
North star
We measure the elapsed time from PRD intake to merged PR, model spend per shipped feature, and token efficiency. The point is not replacing product judgment; it is removing avoidable handoffs from work that has already been specified.
Workflow
Each stage produces a checked artifact. The next stage refuses to start without it, making the pipeline a one-way contract from product intent to merged change. Stages and tooling evolve — treat this as the current contract shape, not permanent law.
| # | Stage | Output | Owner |
|---|---|---|---|
| 0 | Preflight | Env/auth proven before any model spend | Orchestrator |
| 1 | Intake | Worktree, branch, install + generate | Orchestrator |
| 2 | PRD | Validated frontmatter + readiness | Human (wrote) / runner |
| 3 | Scope | Anything left to build? (~$0.16) | Scope gate |
| 4 | Implement | Spec + tests + code + dossier in one session | Native executor |
| 5 | Verify | Repo gate green + acceptance coverage | Outcome kernel |
| 6 | Reviewer loop | Push, PR, Codex/CodeRabbit settled | Reviewer loop |
| 7 | Approve + merge | Human Approve → gh merge --auto | Human + merge queue |
Migrated platform source
Each workflow concept is shown as part of one operating model, so candidates and partners can understand how strategy, implementation, verification, and review connect.
The job is to shorten the path from product intent to verified change without removing accountability. Read this first: humans own priority, quality, and decisions.
The workflow splits responsibility across Architect, Editor, Reviewer, Verifier, and Orchestrator. The role chooses the model by task, cost, risk, and context.
Darwin is a thin in-house Node loop that holds intake, queue, status, and evidence together. It should stay simple, observable, and replaceable in parts.
The component map separates what is used by the PRD-to-PR pipeline, what is parked, and what remains in the prioritized build queue.
The adapter shape lets the workflow select a model without locking the product process to one vendor or one interface.
Spec means testable acceptance scenarios, not loose wishes. Gherkin and a done contract gate reduce spec drift between PRD, tests, and implementation.
The review loop polls external reviewers, classifies severity, and re-enters the editor with an idempotent action list.
Automation should scale only when evidence, cost, and quality hold. Otherwise it must be easy to stop or roll back.
The features per second per token metric is read together with cost, quality, and business signals to see whether the workflow actually improves delivery.
Every delivery should leave a trace: trace.zip, screenshot.png, console.log, test excerpts, and a short explanation of what the artifact proves.
We do not claim this is the only correct way. It aligns with established practice for effective agents, human oversight, and continuous delivery — sources to read yourself:
Related pages in the product and platform story — with working links.
How CAIRE composes AI agents into an operating system for home-care delivery.
OpenVRPTW, NP-hardness, and the hybrid human-AI optimization model that powers scheduling.
OpenHow CAIRE handles AI regulation, audit trails, and responsible deployment in healthcare.
OpenTwelve guides cover every stage in depth — vision and mandate, agent roles, the dossier pattern, the reviewer-feedback loop, and the orchestrator that ties it together.
The product we build and the way we build it share a philosophy: trace what changed, learn from outcomes, and keep humans accountable for decisions that matter.
Deep dive
Diagram 1
Diagram 2
Diagram 3
CAIRE's engineering execution model is an agentic PRD-to-PR pipeline. A human writes a product brief; specialised AI agents handle spec, tests, implementation, review, and verification; the human approves a screenshot. Compute is the bottleneck — not headcount.
From a sentence to shipped software. The human appears in two places only — writing the PRD, and approving the dossier screenshot.
The agentic workflow is not "AI assistance for engineers". It's the execution model. Four commitments make the workflow distinctive.
Product owners write PRDs. The pipeline takes the PRD from there — spec, tests, code, review, dossier, merge — without a human in the middle of any stage.
Every model call goes through an adapter. Routing is config, not code. When a better or cheaper model ships, rotation is a quarterly review — not a refactor.
Post-merge metrics ramp a feature 1% → 100%. Regression flips the flag back. The decision is mechanical — humans don't decide "ok, ramp this".
Cash balance, revenue, and burn are system inputs. The orchestrator refuses to spawn an expensive run if today's budget is exhausted. No human "tighten the belt" call.
Every architectural decision in the pipeline is graded by one question: does it make us ship more features per second, per dollar (and per token)? The metric is deliberately tiny in absolute value. What matters is the trajectory.
Wall-clock from PRD intake to merged PR. Squeezing this means parallelising stages, caching specs, removing human round-trips. Every shipped feature lands a row in .compound-state/agent-service.db with its elapsed time.
Total model spend across all eight stages, per merged PR. Cheaper providers, smaller models for cheap routing, batch APIs, prompt caching — every lever points back here. The orchestrator refuses runs whose projected cost would exceed today's budget.
Total input + output tokens across the pipeline, per merged PR. The cleaner the spec and the tighter the dossier contract, the fewer tokens the editor burns iterating. Tokens are a leading indicator of cost.
An optimization mathematician agent reads the throughput log every week and proposes routing changes — different model per role, different batch size, different cache strategy. The CPO/CTO agent ratifies. The ratchet only moves one way.
This page itself will move with the metric. New routing wins, new agent prompts, new dossier shapes — every improvement that nudges features-per-second-per-dollar lands here as a refresh.
Each stage produces a checked artefact. The next stage refuses to start without it. The pipeline is one continuous flow, not a checklist — every stage hands off a typed result.
Re-entry: verify and the reviewer loop may send work back to implement (max 3 cycles). Merge runs only after human Approve — not in the unattended walk.
The contract is sharp: no dossier, no merge . Every stage's output is a typed, persisted artefact that the next stage reads — and that a human, an audit, or a future agent can replay.
The agentic workflow doesn't make humans disappear — it makes them strategic. Each role has one or two narrow places to step in. Everything else is software.
Defines what + why Writes the PRD in wiki/plans/ with a success metric and explicit non-goals. Approves (or rejects) the dossier screenshot before merge. Sets the regression threshold that scale-or-kill watches post-merge. 💻
Reviews, doesn't author Reads the auto-generated spec for drift from the PRD. Argues down P2 reviewer comments with a justification when the agent is wrong. Maintains the agent prompts and the model adapter — code about how code gets written. 🛠️
Owns the substrate Operates Darwin (the orchestrator runtime), the launchd job slots, the merge queue. Watches the throughput log: cost per merged PR, features per second per token. Approves model-routing rotations from the optimization mathematician's weekly proposal. 🧪
Writes the rules, not the cases Curates the Gherkin patterns the Test-writer agent compiles from. Audits dossier summary.json for skipped scenarios or empty Playwright traces. Owns the "no dossier, no merge" gate — the only thing the orchestrator cannot skip. 📈
Watches the leverage Reads cost-per-merged-PR trending down month over month as the routing matrix tightens. Tracks features-per-second-per-token as the leverage ratio that doesn't depend on hiring. Ratifies quarterly model-routing decisions; does not pick models. 🔍
Audits the trail Inspects wiki/raw/dossiers/<feature>/ on a merged PR — full Playwright trace, screenshot, console log. Reads the PRD frontmatter to map a shipped feature back to the original brief. Verifies vendor-agnosticism by reading the routing config — no provider lock-in to inherit.
The pipeline targets steady-state product engineering — the work that, in a traditional team, fills standups and sprints. Bigger architectural moves still get a human-led plan.
A new banner, a new page, a form variation. PRD names the acceptance scenarios; pipeline writes vitest + Playwright tests; Editor implements; Verifier captures the screenshot dossier.
PRD frames the bug as a failing scenario. Test-writer compiles it; Editor fixes; resolver-reviewer + perf-reviewer catch N+1 regressions before the PR opens.
Throughput row, KPI tile, dashboard chart. Spec names the data source; tests assert the shape; the dossier shows the metric rendering with realistic seed data.
Quarterly: the optimization mathematician proposes a routing change based on cost, pass rate, latency. CPO/CTO agent ratifies. One config edit; the adapter handles the rest.
Audit pass like the agentic-workflow audit itself: identify drift, fix the doc, run yarn wiki:lint , ship. Wiki-only PRs use the same eight stages with the verifier in light mode.
A hypothetical external data flow starts with a PRD. Tests cover the boundary, and the dossier records what was actually verified. The example describes the engineering method — not a shipped integration or product catalogue.
Autonomous loops without guardrails are how AI projects burn budgets and ship regressions. Every stage of the pipeline is fenced. The Editor agent sits at the centre, surrounded by mechanisms that can either slow it down, redirect it, or stop it entirely.
Eight independent guardrails. No single one prevents bugs alone; together they make autonomous shipping safe enough that the human's only required action is reading a screenshot.
The Editor cannot ship behaviour the spec didn't name. Drift between the PRD and the spec is itself a P2 finding for the verifier — and the spec is short enough to fit in every agent's context, so drift is always provable.
MAX_ITERATIONS = 8 on the editor's inner loop, plus a max of 3 re-entry cycles from review or Codex feedback. Hit the ceiling and the run surfaces failure to a human — it never grinds.
The optional PIPELINE_BUDGET_ENFORCEMENT flag (off in pilot, on once revenue is real) refuses further model calls when the per-run cost would exceed the cap. In pilot the human is the only PRD producer, so cost is implicitly bounded.
A green CI run is necessary but not sufficient. The dossier — Playwright trace, final screenshot, console log, machine-readable summary — proves the feature actually rendered. Reviewers can replay the trace; the human sees the screenshot.
Same pipeline, three ways to enter it. Pick the surface that matches the moment — a PRD in version control, a form on the Dashboard, a message on Telegram. Every surface produces the same dossier and the same merge decision.
Write wiki/plans/<feature>-YYYY-MM-DD.md , create an isolated worktree with ./scripts/git/worktree-add.sh , and the pipeline runs against that branch. Reviewer subagents lint the diff, the verifier captures the dossier, the merge queue lands the PR. Best for engineers shipping in version control.
Paste a PRD path, click start , watch the pipeline progress at localhost:3010 . The dossier viewer surfaces the screenshot, console log, and machine-readable summary inline. Approve / Reject is a button — no GitHub round-trip required. Best for product owners who want a UI, not a CLI.
Post a PRD link to interface-agent . The same backend runs the pipeline; the dossier screenshot posts back to the originating thread. Reply approve and it merges. The lightest possible surface — a notification and an image. Best for the founder reading on a phone between meetings.
The pipeline is built on three open patterns and one discipline. Nothing here is bespoke for the sake of bespoke.
One expensive reasoning pass produces the spec; many cheap edit passes implement against it. ~1/14th the cost of running every call on the reasoning model — the cost driver is the editor, not the architect.
Plain language is too imprecise to coordinate multiple agents. Acceptance scenarios in Gherkin are short enough to fit every agent's context, precise enough to compile to failing tests, and greppable.
A green CI run is necessary but not sufficient. The dossier — trace, screenshot, console log, machine-readable summary — proves the feature actually rendered, in a real browser, in the state the spec named.
External review bots (Codex, CodeRabbit) post comments after every push. The pipeline polls them, treats P1/P2 as failed tests, and re-enters the editor automatically. The discipline is non-optional.
| # | Stage | Output | Driven by |
|---|---|---|---|
| 0 | Preflight Prove git/gh auth and a real 1-token model call before any spend. | Environment OK or BLOCKED-ENV . | Orchestrator |
| 1 | Intake Create isolated worktree, branch, install + generate. | Worktree ready. | Orchestrator |
| 2 | PRD Human wrote the plan; runner validates frontmatter + readiness. | wiki/plans/<feature>-YYYY-MM-DD.md | Human (wrote) / runner |
| 3 | Scope Cheap question: any unbuilt code work left? (~$0.16). | Continue building, or retire to wiki/plans/shipped/ . | Scope gate |
| 4 | Implement One native Claude session: Acceptance Contract, tests-first, code, self-review, dossier. | Code + wiki/specs/ + wiki/raw/dossiers/ in the worktree. | Native executor |
| 5 | Verify Outcome kernel: artifacts exist, then the repo's own gate. | yarn verify:changed green + acceptance coverage. | Outcome kernel |
| 6 | Reviewer loop Rebase, push, PR; poll Codex/CodeRabbit; P1/P2 re-enter implement. | Open PR with settled findings. | Reviewer loop |
| 7 | Approve + merge Human approves dossier; only then does merge run. | gh pr merge --auto --squash via /approve . | Human + GitHub Merge Queue |