Bounded autonomy
Authorize one phase—or a controlled batch with explicit phase, time and review budgets. Never unlimited autopilot.
AI development with gates, not guesses.
CW gives AI-assisted development a controlled workflow: plan, implement, validate, independently review, and advance only with verified evidence.
Recorded from a real CW workflow using CW version 0.18.3.
Goal: Add a deterministic greeting function with automated tests in one development phase using Python 3
Final result: completed with 1 approved phase and 1 valid gate.
Built in the open
Adoption appears only when public GitHub data is meaningful. Until then, the product's engineering proof speaks for itself.
Public GitHub data · updated periodically
The control layer
Speed is not the same as control. Professional development still needs explicit scope, checks, independent judgment and a defensible reason to advance.
Different responsibilities.
One controlled workflow.
A gated execution model
CW turns autonomous work into a sequence of bounded, verifiable transitions.
Plan
Separation of responsibility
CW deliberately separates the agent that changes the workspace from the agent that evaluates the result.
Independent responsibilities make every approval inspectable.
Control without killing velocity
CW preserves agent momentum while keeping advancement tied to explicit, inspectable evidence.
Authorize one phase—or a controlled batch with explicit phase, time and review budgets. Never unlimited autopilot.
Implementation and review run as separate responsibilities with different permissions and isolated sessions.
Run approved project checks before semantic review, without shell interpretation or agent-injected commands.
Approved artifacts are hashed into gate evidence and rechecked before dependent phases begin.
Contradictory state and evidence stop execution. Backup-first repair reconciles validated evidence without inventing approval.
Follow meaningful Codex checkpoints, elapsed time and redacted run records instead of watching a silent process.
The workflow, visible
CW turns state, live execution and retained evidence into a coherent terminal surface—with stable output for people and versioned JSON for automation.
~/code/sample-app
● connected$ cw status
CW · Codex Workflow v0.18.3by Queopius sample-app dev WORKFLOW ● ACTIVE Progress ##########-------------------- 33%Approved 1 / 3 phasesState IN PROGRESS CURRENT PHASE→ 02 · Build Authentication Attempt 0 / 3 Readiness NOT READY Gate PENDING
Safety model
Serious controls, designed for forward motion. CW rejects ambiguous transitions instead of turning uncertainty into progress.
No valid gate. No next phase.
Implementation ≠ approval.
Evidence beats cached state.
Repair never fabricates approval.
Completed means completed.
Developer experience
Install CW once. Initialize it inside a Git repository. Approve a bounded plan, then let the gate model do its work.
Project-localWorkflow state stays with the repository.
Explicit planningNo reliable goal means no invented work.
No silent updatesInstall and update actions stay intentional.
$git clone --branch v0.18.3 --depth 1 git@github.com:Queopius/cw.git$cd cw$./install.sh $cd ~/code/my-project$cw init$cw plan --goal "Implement subscription billing"$cw plan show$cw plan approve$cw $# Existing managed installation$cw update --version 0.18.3
Inspect the architecture. Read the implementation. Review the safety model. Contribute.
A gate-driven workflow supervisor for controlled AI-assisted software development.
LATEST RELEASEv0.18.3Stable release (opens in a new tab)Documentation
Installation, workflow design, planning, reviews, batch execution, integrations, recovery and architecture.
Read the documentation (opens in a new tab)Installation and first workflow
(opens in a new tab)States, phases and advancement
(opens in a new tab)Evidence and approval contracts
(opens in a new tab)Roles, state and execution model
(opens in a new tab)Diagnostics and safe recovery
(opens in a new tab)Resources
Read the full CW guide.
Source, issues and contributions.
Download and inspect releases.
See what changed.
Security policy and reporting.
Apache-2.0 terms.
FAQ
What CW controls, what it leaves alone, and how it behaves at the boundaries.
CW is a standalone, gate-driven workflow supervisor for explicit, reviewable AI-assisted development. It coordinates planning, current-phase implementation, deterministic validation, independent review and verified advancement.
No. CW is the control layer around a development workflow. Codex performs bounded planning, implementation and review roles; CW owns the state graph, validation order, permission boundaries, audit history and gate verification.
No. CW runs the approved deterministic checks configured for each phase before review. Your CI remains the repository's shared integration and delivery boundary; CW governs local phase advancement.
Implementation and approval are intentionally separated. The reviewer is a new ephemeral Codex process with read-only access, hooks disabled and a structured evidence contract.
Yes, within explicit limits. `cw run N` uses the same single-phase supervisor repeatedly and stops on human review, invalid evidence, integration failure, exhausted budgets, interruption or completion. There is no unlimited override.
CW fails closed and explains the integrity conflict. `cw repair` first creates a backup, then reconciles from validated authoritative evidence. It never fabricates an approval gate.
No. CW does not store MCP credentials, inject partial MCP server definitions or silently change `~/.codex/config.toml`. Managed processes retain your effective Codex configuration.
The final valid gate writes `COMPLETED`. CW derives completion from the full contiguous chain of valid gates and never invents a successor phase: all valid gates, no next phase.
Codex Workflow
Give AI room to work—without giving up control.
No valid gate. No next phase.