Gate every merge with a review panel
A developer builds each change on a branch, three reviewers check it for security, tests and API shape at once, and only three passes merge.
One reviewer looks at everything a little. Three reviewers each look at one thing hard.
- security
- tests and API shape
- performance
- accessibility and copy
- one reviewer per service a change touches
A single reviewer tends to skim. In this playbook a team manager runs a panel: a developer builds each change on its own branch, then three reviewers read the same diff at the same time, each for one thing only, and each answers pass or fail with reasons. The manager merges only when all three pass, sends failures back to the developer, and gives you one table.
Steps
Our repository, notes, is a small Python notes API with unit tests.
- In the repository, run
codeafand send any first message. A team is made from conversations, so it needs one that has run. - Press Alt+2, then N. In the New team card, clear the name, type
releaseand press Enter. - Press Esc, then Alt+2 for the teams page, and with
releasechosen press Shift+M to give it a manager. - Send the manager the panel's rules and the first change:
You manage release, the review panel for notes. Call team_start four times now to hire @dev, @security, @tests and @api. @dev builds each change on a new branch from main with unit tests and reports the branch. Then the three reviewers read that branch's diff against main at the same time, each for one thing only: @security (injection, unsafe input handling, secrets), @tests (runs python3 -m unittest and checks the new behaviour is tested) and @api (status codes and JSON shapes match the existing endpoints). Each answers PASS or FAIL with reasons. Merge the branch into main with --no-ff only when all three say PASS. On any FAIL, send the reasons to @dev and repeat, at most 2 rounds. Then give me one table: reviewer, verdict, main reason. First change: PUT /notes/<id> with a JSON body {"title", "body"} updates the note; 404 for an unknown id, 400 for a body that is not valid JSON.What you see
The header grows to ● release ◆ Manager 5 members. In the Traffic column (Alt+3) the manager starts the four members, tells the three reviewers to hold until the branch exists, then sends each its review. The chat collects @tests @api answered and @security answered, waits for @dev's merge, checks it, and writes the table. In our run all three passed: @security had probed the endpoint with '; DROP TABLE notes;-- and found it stored as plain text, @tests counted 26 of 26 passing with 8 new tests, and @api matched the shapes and the error envelope. The branch was merged with a merge commit.
@security also flagged two problems outside the change, and the manager listed them as follow-ups instead of widening the change.
If the manager answers with verdicts while the header still reads 1 member, nobody was hired. In our first round the manager did the change and the reviews itself through a helper. Say so, and ask it to call team_start.
In our run
The change went from the message to a merged branch in under three minutes, for about $0.50.
Make it yours
- Pick your reviewers. Any three concerns work: performance, accessibility and copy for a web app, or one reviewer per service a change touches.
- Keep the gate strict. The merge rule is in the manager's brief, so write it exactly: which verdicts, how many rounds, what happens after the last fail.
- Ask before it hires. Press Alt+A in the manager's conversation and each
team_startwaits on a card you allow or deny. See Managers.
Go further
Managers: An agent whose job is other agents, including other managers, and who asks you only what it cannot decide.
Coming soon: describe the org you want and CodeAF builds it: teams, managers, budgets, standing orders.