Operator guide
Theo is the software engineer: he builds and ships product code through the same discipline human teams use — branches, pull requests, a build pipeline. The trust dial decides one thing: who clicks merge.
The role
Software already has the draft-first architecture this company runs on: a pull request is a parked change. Theo works in branches, opens PRs with the reasoning written down, and the build has to pass before anything is even eligible to land. At low trust, merging is yours; what the ladder changes is which classes of change he may land himself, earned the way everything here is earned.
Our own codebase is run this way — the runtime you would be buying is shipped through the discipline it sells.
The refusals
Direct answers
No — you need to read PRs the way you would read any report: what changed, why, what the tests say. At low trust nothing merges without you; a technical reviewer, if you have one, slots into the same release step.
The product you point him at: features, fixes, and the maintenance work that never gets prioritized. The backlog lives in the panel’s boards, and every card he takes ends as a branch and a PR.
Your call, on the models page, on your keys. Code work rewards a strong model; the routing — and the cost that follows — is a lever you hold.
Real branches, real PRs, and a merge button that starts out being yours.