Each piece checks what actually happened — the real diff, the real trajectory, the real file — not what the agent claimed.
Bound to a file, not a moment. It keeps failing and feeding the error back until the code actually satisfies it — not a one-shot reject.
Write tests for the charge flow.
+test('applies tax after the discount', () => {+ const t = charge(100, { discount: 20 })+ expect(t).toBe(88) // (100-20)*1.1+})
The claim, checked against the artifact. Did the diff really contain the change; does the cited source line actually resolve — not whether a rule merely fired.
A move that has to add up to nothing. The before and after cancel out once known-legit differences are set aside — the empty residue is the proof it was mechanical, not regenerated.
$ sed -n '4,6p' config.ts >> loader.ts && sed -i '4,6d' config.ts # deterministic — lines moved, no model in the loop
A scope the agent enters on its own — detected from what's happening, not a step it has to remember. Enforced only while it's active.
$ echo "<div />" > dist/index.html gate: deploy-safety — write to dist/ blocked (build output, do not hand-edit) $ astro build → 12 page(s) built to dist/ gate: deploy-safety — passed
A checkpoint on one action. It reads what the action requires and either lets it through or blocks it — once, at the moment it matters.
A standing map of where writes are even allowed. Deny by default — a path outside the structure never lands.
Shipped the charge route and wired the webhook. #done
A durable label pinned on the artifact — a comment in the code that later checks anchor to, surviving renames and moves.