Roles, isolated workspaces, acceptance checks and independent review in a single task chain, with receipts for who did what and why a run stopped.
In development and controlled validation · Acceptance currently covers macOS only
The starting point
Agents don't coordinate themselves
Work is split ad hoc in chat threads, and handoffs fall apart.
Results lack evidence
After the fact, nobody can say which agent ran, with what configuration, or where it failed.
Automation runs away or reports false success
Without budget and timeout limits, failures and rejections quietly turn into "done".
Core features
Roles & Admission
Role inspection & dry-run previewSee the effective role configuration and check the plan before anything runs. Previews never execute.Available
Agent adapters & capability viewInspect configured coding agents and what they can do through a single adapter layer.Available
Pre-publish admission checksVerify the project is ready before a task workspace is created.Available
Uncommitted role-override warningsGet an explicit warning when local role changes won't make it into the task snapshot, instead of a silent miss.Available
Execution & Independent Review
Role-based task runsRun a task as a specific role inside a scoped workspace, with results and a configuration digest recorded.Available
Implement → verify → independent reviewImplementers, reviewers and an adjudicator work one task through a single flow. Nothing is merged or released automatically.Available
Review-format recoveryIf a review comes back without a parseable verdict, retry once. A genuine rejection is never retried as a formatting error.Available
Receipts & Visibility
Actual-identity & failure receiptsRecord which seat actually ran. A stand-in never poses as the original.Available
Terminal & web status viewsFollow tasks, governance state and run traces from one place.Available
Guardrails & Roadmap
Hard budget capsOn supported orchestration paths, stop further calls and log it once the budget is exceeded.Preview
Graceful cancellationOn cancel, settle at the next applicable stage boundary and record it.Preview
Scope-violation detectionFlag changes that fall outside the allowed scope on supported paths.Preview
Transactional config rollbackA verified rollback contract when a configuration operation fails.Planned
Linux system-level validationProcess-lifecycle and delivery validation on Linux.Planned
What sets it apart
It manages the process, not just the prompt
Roles, workspaces, acceptance checks, independent review and run receipts form one task chain you can audit.
Local control, observability first
The control plane and state live in your project workspace. Task content still goes to whichever model services you call.
Honest stops, no false success
Failures, rejections and missing evidence halt the run and leave a record, and stand-ins never pose as the original seat.
Use cases
Ship a fix through independent review
Who: Engineering lead Situation: Needs to land a small, scoped code fix How: Define the goal, the allowed change scope and acceptance commands; the implementer seat submits a candidate and an independent seat reviews it Outcome: A verifiable patch plus a review record. Merging is still the lead's call
Untangle who did what
Who: Maintainer Situation: The team mixes several coding tools and handoffs get muddled How: Check effective role configs, dry-run previews and actual-identity receipts Outcome: A clear view of who ran the task, with what configuration, and where it failed. A tool's name alone doesn't qualify it as a reviewer
Explore a complex task within limits
Who: Tech lead Situation: Wants multi-stage collaboration with tight control over spend and side effects How: Set a budget and scope on a supported orchestration path, watch the status, and cancel if needed (Preview) Outcome: Real evidence of completion or of the stop, so you can decide what's next. Instant stop under every system load is not guaranteed
Architecture
A logical view only. Components do not share a single enforced sandbox.
Interface
Local CLI
Terminal & web status views
Control
Role config & admission checks
Task orchestration & isolated workspaces
Run control (timeouts, results, receipts)
Independent review & adjudication
Execution
Adapter layer & role runtime
External coding tools & model services (bring your own access)
Record & Handoff
Local state, logs & run receipts
EGC: governance records & rule checks
Delivery candidate (humans decide on merge and release)
Workflow
Failures, rejections and unknown states never count as success. Passing review is not authorization to ship to production. Preview capabilities apply per path and need separate acceptance for each release and environment. They are not global enforced isolation.
Plan
Define the goal, change scope and acceptance criteria. If project or role admission fails, the run stops and logs why.
Implement
The implementer seat produces a candidate in an isolated workspace.
Verify
Acceptance checks run. On failure, the task goes back to implementation while rework budget remains.
Review
Independent reviewers deliver verdicts and an adjudicator converges them. A missing or unparseable verdict gets one format-recovery attempt at most.
Record
The real verdict and the actual executing identity are recorded.
Hand off
A delivery candidate is ready. The owner decides whether to merge and release.
Rejected
A rejection sends the task back to implementation; once rework budget runs out, the run stops and is logged.
Over budget
On supported orchestration paths, further calls stop and the overrun is logged.
Preview
Cancelled
The run settles at the next applicable stage boundary and the cancellation is logged.
Preview
Timed out
The timeout is logged and termination and cleanup begin. Cleanup failures are reported, too.
How it differs from related products
EGC Supervisor handles orchestration and execution: it adapts coding agents, runs roles, manages task workspaces, coordinates acceptance and independent review, and produces status and receipts. EGC handles the record and the governance: the event ledger, governance records and rule checks. Neither replaces human authorization, and an approved review never turns into a merge or a release on its own.
Terminal example
Listing role assignments in a demo project (offline, read-only; no model was called. Identities and paths are redacted. The model column has been rewritten as generic descriptions to show configuration structure only; it implies no availability or partnership).
$ egc-ctl role list --project-root <demo-project>
adjudicator <identity> GLM-family model ["adjudicate"]
implementer <identity> mainstream model ["implement"]
reviewer-a <identity> mainstream model ["review"]
reviewer-b <identity> mainstream model ["review"]
reviewer-reserve <identity> mainstream model ["review"]
Showcase and promotion preparation
Not yet open source, with no public availability date promised at this stage; this page explains the product direction and the boundaries of its existing capabilities.