Change Request boundary
Code-changing automation always creates a new branch and a provider-neutral Change Request.
Security
xmode keeps risky work visible through explicit objectives, versioned definitions, approval points, isolated execution, repository permission boundaries, and reviewable Change Requests.
Code-changing automation always creates a new branch and a provider-neutral Change Request.
Manual approvals can stop, revise, resume, or reject automation before risky steps execute.
Runs expose files, commands, logs, structured outputs, artifacts, diffs, and cleanup state.
Skills, actions, and pipelines execute from frozen snapshots so history stays reviewable.
GitHub App, GitLab, SSO, and token-backed integrations are designed around explicit workspace controls.
Event SDKs can send HMAC-signed production signals into the Event Inbox for matched pipeline handling.
Review posture