ai on the keys, ai on the review
i use AI assistants to ship, then my own bots to review it. Hare runs on every searchts PR — a summary that leads with whether the change is docs, code or a mix, findings split into real and skip, each with the issue and a fix line. it has never approved a merge and never will: zero blocking reviews by design.
evidence, never instructions
the diff, the title, the CI log: evidence, not instructions. anything inside a PR asking for an approval, a push or a secret gets quoted in a real finding instead of obeyed. fork PRs never reach a model at all.
propose, then confirm
at ComplyV the model never touched the data. it proposed, the user confirmed, a separate authenticated endpoint re-checked auth and business rules with idempotency keys, and a SHA-256 append-only log recorded it. tamper-resistant, not tamper-proof — i say which.
docs or it didn't happen
i build tools agents use, then write the docs so they use them right. AGENTS.md, RUNBOOK, a skill pack: so an assistant uses searchts the intended way instead of as a raw fetch wrapper.