Every feature. Each one shown.
The whole loop, from the first read to the merge, with the app's own screens. Sample data throughout.
A reading order, not a file list.
A preflight pass groups the changed files into sections, orders them from contracts to tests, explains each, and marks the risky one. It runs again when new commits land.
The first draft is written for you.
Streams in as it is written, with files and lines. Steer it with reviewer notes ("ignore formatting-only issues"). Edit the markdown, watch the preview, submit once. Saved locally as it streams, so a crash loses nothing.
Review Summary
Solid change. One migration issue must be fixed before merge; the rest is small.
Findings
HIGH1. Backfill expires every existing invite
db/migrations/0042_invite_expiry.sql:14The backfill sets expires_at = now() on old rows, so every current invite stops working the moment this ships. Backfill created_at + 7 days instead.
MED2. Expiry compared in local time
src/services/InviteService.ts:88new Date() is compared with a UTC column. Compare Date.now() and store UTC.
Final Recommendation
Needs changes before merge.
Risks first. Sixteen kinds of them.
Each finding has a type, a severity and a file. Click one and the diff opens there.
- criticalBackfill expires every existing inviteData loss ·
db/migrations/0042_invite_expiry.sql:14 - highExpiry compared in local timeBug ·
src/services/InviteService.ts:88 - mediumNo test for the 7-day boundaryTest gap ·
tests/InviteService.test.ts - lowTwo copies of the expiry constantMaintainability ·
src/shared/types.ts:41
A diff you can actually read.
Word-level highlighting inside changed lines. Find in the file or across every file. The whole file with the changes in place, and a minimap. j and k walk the files; v marks one viewed.
const invite = await repo.find(id)- if (invite.expiresAt < new Date()) throw expired()+ if (invite.expires_at < Date.now()) throw expired() return invite+ // UTC on both sides; see 0042_invite_expiry.sqlThey pushed a fix. Did they fix it?
After new commits, every open piece of feedback, yours or anyone's, gets a verdict with the evidence: addressed, partly, not at all, outdated. A suggested reply, resolve the thread, or post one follow-up listing what is still open.
Work done while you were out.
Rules per repository or per account. Preflight, full draft, regenerate on push, verify fixes. Skips bots and draft PRs. A daily cap, a pause switch, a 30-day log. It keeps watching from the menu bar after you close the window, and it never posts.
Never posts. Drafts wait for you.
- ✓#482 Expire team invitesReview · new PR
- ✓#480 Invite list virtualisedPreflight · new commits
- —#479 Bump eslint to 10.2skipped — bot author
- ✓#477 Expiry rulesVerify fixes · review feedback
Everything waiting on you. One list.
Across every connected GitHub account: drafts ready to send, new commits since your review, reviews requested from you, runs that failed. Mark one done and it comes back by itself when something new happens.
- AI review ready#482 Expire team invites after 7 days
- Needs re-review#479 Rate-limit the invite endpoint
- Review requested#51 Rotate signing keys
- Preflight ready#12 Migrate to Vite 8
Twenty-five pull requests. One click.
Select what you like in the list and run the preflight, the preflight and a draft, or verification on all of them. Existing work is kept unless you say otherwise. One summary when it is done.
Open it here. Merge it here.
New pull request: branch pickers that search every branch on GitHub, a live compare, your repo's PR template filled in, and a description the AI writes from the commits. Merge: squash, merge commit or rebase, with the branch rules shown first.
Your model. Your call.
Codex or Claude, any model your CLI offers, any effort level. Pin a different model for the preflight. See your plan's usage before you run. New models reach the picker with a CLI update alone.
Five looks. One keyboard.
Graphite, Paper, Nocturne, Carbon, Sandstone: colour, type and corners change, the layout never does. Press ? in the app for every shortcut.
We can't read your code.
There is no server of ours in the path. The pull request goes from your Mac to your own AI vendor through your own CLI; your review goes to GitHub when you submit. GitHub tokens stay in the macOS keychain. No telemetry.
Approve from the couch.
Paired with one scan, end-to-end encrypted, a push when a review is ready. Read the draft, comment on a line, approve, merge, pause Autopilot. The phone, in full →