The machete the practice swings

The platform isn't the product. It's why the product ships.

Every Collective engagement runs on governed delivery infrastructure we built and battle-test on ourselves: enforced command safety, a five-gate evidence pipeline, persistent cross-session memory, and the review layer Claude Code cannot be for itself. It isn't for sale — it comes with the work. Founding Five members get it in their hands from day one.

Architecture

Four layers. One governed system.

Every layer builds on the one below it — infrastructure through governance. (Component counts move as the platform grows; these are mid-2026 figures.)

Layer 4 · Governance

Evidence pipeline

A five-gate evidence pipeline ensures every change has traceability; a nine-stage delivery pipeline runs each acceptance criterion from requirement through deployment.

EvidenceGate → ComplianceCheckpoint → DeliveryStage → AuditTrail
Layer 3 · Safety

Enforced command safety

A rules engine evaluates tool calls; safety rules define what's forbidden; alarms fire on violations; compliance checkpoints gate promotion. Blocking works at a catastrophic floor even during an outage of our own API.

RulesEngine → SafetyRule → SafetyAlarm → ComplianceCheckpoint
Layer 2 · Personas

Governed review personas

Contextual reviewer personas with required output sections and compliance tracking — each carrying its own constraints, tools, and audit requirements. This is the independent review layer the proof page's incidents demonstrate.

product | architect | engineer | ux | test | devops | security
Layer 1 · Infrastructure

Tools, hooks, memory

Seventy-plus MCP tools across a dozen modules, lifecycle hooks on both the agent and git, and persistent state — so context survives sessions, crashes, and laptop lids.

73 tools · 9 hooks · PostgreSQL + Prisma (mid-2026 count)

What it changes, concretely.

Four scenarios from real production development.

Lost-in-the-middle

AI forgets constraints mid-session
Without

"I'm not seeing auth requirements — can you restate them?" Paste the ADRs again. Break production anyway.

With

The active objective, plan phase, and constraints are queryable state — the agent re-anchors itself instead of asking you to be its memory.

Crash recovery

Session dies → everything is lost
Without

New session: "What are we working on?" Thirty minutes rehydrating context from scratch.

With

The next session picks up the orphaned session state and recovers the objective, synced plans, and in-flight work automatically.

Unsafe commands

AI executes destructive actions
Without

"To fix quickly, run: git reset --hard… wait, WHAT?" Irreversible loss.

With

Pre-execution validation blocks the forbidden class, logs the event, and the agent proposes a safe alternative. Structural, not prompted.

"What do I do next?"

AI can't see real task state
Without

"Maybe add tests? Or docs?" — the agent guesses because it can't see priorities or blockers.

With

Ready-work is a query: prioritized items, blocked items, and what unblocks automatically on completion.

> what capabilities of this MCP are you most excited about?

Most AI-tool marketing is humans explaining why the tool is good. This is the tool explaining why it likes being governed — the agent's own answer, unedited:

1

Pre-tool-use safety hook

Server-side validation that actually blocks dangerous commands (exit code 2) before they execute. The known-safe cache skips the check for git status, ls, etc. — so it doesn't slow normal work.

2

Unclean shutdown detection

When a session dies from Ctrl+C or a closed laptop lid, the next session picks up the orphaned session file and recovers context automatically.

3

Commit-completion detection

After a git commit, it cross-references the message against in-progress work items and surfaces "this might be done" suggestions.

4

Auto-sync plan files

Any edit to a plan file fires a background sync with a breadcrumb for retry — no manual sync command.

5

Traceability git hook

Work-item and plan-phase footers appended to every commit create a traceability chain from code back to requirements, with zero effort.

Why an independent review layer at all? Because context is not the same as review — the argument, and the three documented incidents behind it, live on the proof page. What the layers enforce is graded honestly on the Delivery Assurance standard and in the claims ledger.

Two ways in

You don't buy the platform. You get it.

Clients get it under every engagement — it's how the work ships. Founding Five members run their own practice on it from day one.

Bring me what you built The Founding Five →