Five decisions routed back for operator gate-1 ratification — none architect-self-ratifiable, since all five are naming choices rather than architectural ones. Gate-0 brand winner (Deck Hearth) is captured; architect's job was to scope and minimize the cost of the rename, not to re-litigate the brand. No blocking findings surfaced: no npm-package collision (we don't publish), domain ownership is already a known queued follow-up, Redis counter reset is the explicitly-accepted trade. Architecture: 2 file-disjoint briefs that can run in parallel via /multitask once gate-1 lands. ~75-110 lines net diff across 16 source files + 1 new migration script (excluding the opaque package-lock.json regen). Brief 1 is the mechanical display/comment sweep (7 files, ~7 lines) — branding notes, rule descriptions, three User-Agent product tokens. Brief 2 owns the infrastructure + email-rename blast (10 files + 1 new migration script, ~30 edits) — Redis prefix rename in lib/rate-limit.js (5 lines), package.json + lockfile regen, admin/alice/ bob email rename across seed/reset/test-user scripts + login.js fixtures + README + TESTING_GUIDE + the test-file regression-lock, plus the new scripts/migrations/2026-05-24-rename-admin-email.js (idempotent REPLACE() UPDATE with UNIQUE-constraint fail-loud semantics). D1-D5 recommendations all biased toward existing-string consistency: D1 "Deck Hearth" (matches all 7 already-correct user-facing surfaces; choosing "Deckhearth" would re-sweep them — net-negative cost), D2 `deck-hearth` (matches the existing `deck-hearth-logo-container` CSS class), D3 `deckhearth` (single token for ID use), D4 `admin@deckhearth.com` (placeholder .com pending point-domain convoy), D5 full `deckhearth` Redis prefix (the 8-byte/key savings of `dh` are negligible vs. self-documenting debuggability). Boot-the-brief findings preempted: lockfile regen is architect-verified to touch only the 2 `name` field lines (lines 2 + 8 of package-lock.json); the test-file negative regression assertion's email literal recommendation is PRESERVE the historical `admin@tcgvault.com` (the literal is a documented pre-fix-auth-bypass bug shape, not an arbitrary email value); scripts/reset-db.js line 142's CJS-in-ESM bug is OUT OF SCOPE and queued as convert-reset-db-to-esm; the in-DB migration's UNIQUE-constraint fail- loud is the intentional safety behavior. AGENTS.md Gotcha #4 / #12 updates are reserved for the doc-writer pass at convoy close (not preempted by Brief 1). Two NEW out-of-scope follow-ups surfaced beyond the convoy seed's four: convert-reset-db-to-esm (CJS-in-ESM bug in reset-db.js, may fold into purge-weak-creds-from-helpers) and update-seed-visual-baselines-on-linux- ordering (the queued seed-visual-baselines convoy MUST run AFTER pick-a-name so the first Linux baseline captures Deck Hearth strings, not TCG Vault). Co-authored-by: Cursor <cursoragent@cursor.com> |
||
|---|---|---|
| .. | ||
| add-rate-limiting | ||
| adopt-playwright-smoke | ||
| bump-next-js | ||
| cors-tighten | ||
| drop-public-setup | ||
| fix-auth-bypass | ||
| fix-layout-default-user | ||
| fix-vercel-deployment-protection-in-ci | ||
| pick-a-name | ||
| add-rate-limiting.md | ||
| adopt-playwright-smoke.md | ||
| bump-next-js.md | ||
| cors-tighten.md | ||
| drop-public-setup.md | ||
| fix-auth-bypass.md | ||
| fix-layout-default-user.md | ||
| fix-vercel-deployment-protection-in-ci.md | ||
| pick-a-name.md | ||
| README.md | ||
| ship-readiness.md | ||
Convoys
A convoy is a multi-PR work-stream coordinated by an agent pipeline. One convoy = one feature, bug fix, or epic. Each convoy is a Markdown file in this directory plus an optional sub-directory of implementer briefs.
File layout
.convoys/
├── README.md (this file)
├── <slug>.md (the convoy file — written by role-conductor)
└── <slug>/
├── brief-1-<kebab-title>.md (written by role-architect)
├── brief-2-<kebab-title>.md
└── ...
Convoy file format
Frontmatter (set by role-conductor, then appended-to by other roles):
---
name: <kebab-slug>
classification: feature | hotfix | docs-only | infra-only | server-only | config-only
success_metric: <one sentence>
skip:
- <flag1>
status: open | in-progress | merged | shipped | abandoned
created: <YYYY-MM-DD>
---
Body sections (added in order by the pipeline roles):
## Why(Conductor)## Scope(Conductor)## Roles invoked(Conductor)## Todos(Conductor → refined by Architect)## IA(IA Architect)## UX(UX Reviewer)## Architecture(Architect)
After Architect, briefs live in .convoys/<slug>/brief-N-*.md. Implementers read only their brief, not the whole convoy.
Skip flags
The Conductor sets skip: based on classification. These flags map to pipeline stages that no-op when set:
| Flag | Skips |
|---|---|
ia |
IA Architect |
ux |
UX Reviewer |
arch |
Architect |
test |
Component tests |
review |
Reviewer |
visual |
Visual diff |
a11y |
A11y auditor |
design |
Design-system auditor |
smoke |
Staging smoke |
qa |
Manual QA |
docs |
Doc Writer |
flag |
Flag rollout |
Never skipped (mandatory human gates): plan-approval, pr-merge, prod-promote.
Status lifecycle
open— Conductor created the convoy; no work started.in-progress— At least one brief has an open or merged PR.merged— All briefs merged to umbrella; release PR to develop pending.shipped— Release to main complete; flag rollout (if any) underway.abandoned— Convoy closed without shipping; reason in convoy body.
Update status by editing the convoy frontmatter as you progress.
Adding a new convoy
- Open Cursor in this repo.
- Prompt: "Start a new convoy: . Success = ."
- The
role-conductorsubagent writes.convoys/<slug>.md. - Run subsequent roles in order per the convoy's
Roles invokedlist.
See .cursor/agents/role-conductor.md for the Conductor's full spec.
Multitask + worktrees (Cursor 3.2+)
Cursor 3.2 (Apr 24, 2026) added /multitask async subagents and native worktree management in the Agents Window. The pipeline uses both:
Audit fan-out — after an implementer ships a PR draft:
/multitask role-reviewer + role-design-system-auditor + role-a11y-auditor
All three read the same diff and emit independent comments. Use group id audit-<convoy>-<pr> so analytics can compute wall-clock savings.
Implementer fleet — after architect's plan is approved (gate 1), if slice_dependencies: declares parallel-safe briefs (depends_on: [], disjoint files:):
/multitask role-implementer briefs 1, 2, 3
Use Cursor's Agents Window to create a worktree per brief — one click each. The legacy scripts/wt.sh is now a deprecation stub.
See the multitask playbook for the full guardrail set.
Self-analytics
Each L2 role appends one event to .convoys/.metrics.jsonl via scripts/log-convoy-event.sh. The file is gitignored by default — events stay local. To opt-in to commit team-shared metrics, remove .convoys/.metrics.jsonl from .gitignore.
Aggregate across repos and render a dashboard with the agent-pipeline analytics scripts:
cd ~/code/agent-pipeline/analytics
npx tsx analyze-convoys.ts <repo-path> [<repo-path>...]
npx tsx render-dashboard.ts
open ~/agent-pipeline-data/dashboard.html
Schema: analytics/schemas/convoy-event.json.