← turboflow.online
~/turbo-flow — constitution.md, law 1 the principle

Agents build.
Humans merge.

This is the governance principle behind Turbo Flow and Turbo Rig, and it is deliberately one sentence. AI can now do the building — and most of the checking. What it must never do is hold the final authority over what ships.

Published Oct 7, 2026 · Updated Oct 8, 2026

What agents do

  • plan — decompose work, write specs, propose approaches
  • code — write and edit the actual changes, in isolated worktrees when writers run in parallel
  • test — run the suites, reproduce failures, write new tests for the fixes
  • review — a model from a different family than the builder inspects every diff read-only and returns APPROVED or REVISE (why cross-family)
  • revise — respond to REVISE verdicts and go again
  • document — keep memory, runbooks and release notes current, in git

What stays human

The final authority to merge remains human.

Not because humans are faster readers of diffs — they are not. Because accountability cannot be delegated to a system that cannot be accountable. When a merge breaks production, "the agents decided" is not an answer; a name is. The principle keeps exactly one button out of the agents' reach, and puts a person behind it.

How it's enforced (not just hoped for)

builder agent      → writes code, opens PR        (never approves)
review gate        → cross-family reviewer, read-only (APPROVED / REVISE)
                   → fail-closed: silence = REVISE, ambiguity = REVISE
                   → the gate itself never merges
human              → reads the verdict trail, presses merge

In rig-lite this is constitutional law, not convention: builder ≠ reviewer, agents never merge, parallel writers get worktrees, and the gate fails closed. The evidence it's real: in one seven-day window the rig produced 141 merged PRs through 868 gate verdicts — 79% of them REVISE — and every single merge was pressed by a human (the numbers).

What it is not

It is not the "fire your engineering department and let autonomous agents run everything" pitch — that stance deletes the only accountable layer and prays. It is equally not "AI can't be trusted to touch code" — that stance wastes the largest capability increase in the history of the field. The interesting position is the third one: delegate the work, keep the authority. Machines build and check; a person decides. The failure mode this guards against is quiet: not rogue AI, but unreviewed volume — output faster than anyone can actually judge, merged on vibes.

Where the principle runs

It runs in production on every repo governed by the rig — every PR since rig-lite landed was built by one model family, reviewed by another, and merged by a human. The kit is open source; the integrated system is Turbo Rig, in private beta.