Aerospace and automotive grade: assurance practices inherited from safety-critical software, made affordable by code agents.
The project’s rules are tests, and the tests tighten in one direction only. Every corrected mistake leaves a test behind, and nobody loosens it.
The practices that have made the software in aircraft, cars and medical devices dependable for thirty years (numbered requirements confirmed by whoever answers for them, every requirement proven by a test, impact analysis before every change, verification independent from whoever wrote the code, configuration management, an authority that signs the release, monitoring in service) were too expensive for everyday software. Code agents make them affordable: here they are applied to an app for going to the sea. The ratchet adds the rule those industries do not have in this form: constraints can only tighten, and they hold taste and copy too. No app here is safety-critical; the lineage of the rules is.
Write a brief · RiftSeed and no-code platforms
The brief becomes a spec whose requirements its author confirms. Agents build against it, and every requirement they cite must exist.
Deciding what to build stays with whoever writes the brief.
supabase/functions/generate-brief/index.ts
Each count of distinct shapes (pills, radii, text sizes) has a ceiling. The ceiling drops with every cleanup, and the commit that exceeds it fails.
Whether a screen looks good stays out of it; the test only counts.
src/winds-and-seas/lib/livrea.test.ts
Two parts that must agree are tied by a test. The first changelog entry must be the current version.
Whether the line tells the truth is up to whoever writes it.
src/winds-and-seas/lib/novita.test.ts
Playwright scripts replay real scenarios on the production site, from desktop and phone. They count errors, blank pages and crash screens.
A bundle wired to the wrong backend, while the page still answers, slips past them.
scripts/sonde/caccia-crash.mjs
Every fix leaves the date, the incident and the reason in the code. Whoever opens the file reads the reason before the rule.
A comment only explains; keeping the mistake from coming back takes a test.
scripts/guardia-backend-seantral.mjs
Release is a push to main: typecheck and tests run first, and the deploy depends on them. A red gate stops everything, and no agent approves a release.
A manual deploy from the terminal skips the gate; a guard inside the build covers that case.
.github/workflows/deploy.yml
Seantral is the project in production the method is applied to. The blog tells how it went, post-mortems included.