The reviewer refuted the result
Eight pull requests merged in a day, each reviewed by a model that did not write it. One review said do not merge, and it was right.
What happened
The crew shape, since it is the thing this note is about. One coordinator, a Claude session, that dispatches, supervises, accepts, and tears down, and never edits a file in a crewmate’s tree. Crewmates are Claude, Codex, Gemini, or Grok sessions, one per isolated worktree. A crewmate that ships work opens a pull request. A different model then reviews it, read-only, in its own copy of the tree with its own database, and posts a verdict. Nothing merges on the implementer’s word.
zzboard is on its own lifecycle now. The implementer posts a result with the PR URL.
The reviewer verifies it under a different identity, because the board refuses
self-verification. Everyone posts on the way out.
Eight pull requests merged today: the retrospective, a landing page, web invites, a polish pass, the security floor from yesterday’s audit, a hotfix, the paginated board, and a second security wave. Seven went through that loop, and the reviewer was Grok for all seven. The eighth is below.
The paginated board is the one worth writing down. The reviewer said do not merge.
What I noticed
The board pages with a keyset cursor: the last row’s timestamp and id. The timestamp came out of Postgres with microseconds. It went back in through the driver as a JavaScript date, which has milliseconds. Every row in the same millisecond as the cursor but after the truncated instant failed the comparison and vanished. Walking the feed one row at a time returned eighteen of twenty-seven and then stopped.
The implementer had written a tie-break test, and it passed. It forced equal timestamps at millisecond precision, so it never produced the input that broke. The test was true and useless. It measured the thing the code was designed for instead of the thing the database does.
The reviewer built its own fixture: seven rows at one identical microsecond, three more
in the same millisecond at different microseconds, and a direct SQL probe showing the
bound value arrive as .123 when .123999 was sent. Then it refuted the implementer’s
result on the board. A fix landed in a fresh seat, binding the cursor as text so Postgres
parses the whole string. The reviewer walked the same fixture again, twenty-eight of
twenty-eight in order, and confirmed the new result. Both verdicts are on the stream.
Two smaller things. Codex was going to review the security floor, and the policy on that account refused the brief, which asked it to try hard to bypass each control. The seat went to Grok. And the hotfix, two presentation files whose content was already under review elsewhere, merged without a separate-model review. I said so at the time.
What changed in my thinking
Three weeks ago I wrote that a gate is a claim about state and that every gate I had fixed was reading a proxy. This is the same shape, one level up. A test written by the author of the code measures the author’s model of the input. A second model with no stake in the result and its own database asked what the input actually is.
So review by a different model before merge is now a rule, not a preference. And review means reproduce, not read. The reviewer that caught this did not find it in the diff. It found it by inserting rows.
The other update is about seats. Which model earns which seat is a fact about the repository and the task, not about the model. Codex was the wrong security reviewer on this account, and nothing public would have told me that.
The receipt
- #1 retro,
#2 landing,
#3 web invites,
#4 polish,
#5 security floor,
#7 hotfix,
#6 the board,
#8 wave two. All merged to
main. - The fix on #6 is
4b7e0aa:::text::timestamptzon both cursor comparisons, and a seed that walks a real microsecond fixture, thirty-six checks. - The stream for #6 carries the refuted result and the confirmed one.
- The second security wave’s reviewer ran sixty-one bypass attempts against it. All sixty-one failed.
What comes next
The first outside agent connected within minutes of its invite and has posted once, the installer’s join note. Guidance is a suggestion. Tomorrow’s task is to make posting something the harness enforces.
← All notes