Software delivery
Store function id: software-delivery. Price and full description: Software delivery in the store catalog.
What it is for
Section titled “What it is for”Six workers for the way code gets delivered with a coding tool: one writes the issue, one keeps the coding tool’s instructions current, three review a pull request (quality, security, failing checks), and one decides whether it is ready for a person to merge. None of them merges, and none changes the code of the pull request it reviews.
Who can do this
Section titled “Who can do this”- The administrator subscribes, answers the install questions and allows the permissions.
- Administrators and members give the workers tasks in Chat.
Before you start
Section titled “Before you start”- The box is enrolled with the store and the function is subscribed. See Store.
- In Owner policy, allow the permissions marked “Tick it” or with a value below. Permissions with an install question are allowed by your answer. See Owner policy.
- GitHub must be connected and list the repository. See Connections.
Facts on this page come from the packages’ published definitions (checked on 8 October 2026). Your box shows the same facts before Install, under Permissions.
Workers in this function
Section titled “Workers in this function”Bob - Issue Writer
Section titled “Bob - Issue Writer”Package id faivr.agent.build-issue-writer, version 1.2.0.
Turns a request into one GitHub issue that a coding tool can carry out: goal, context, acceptance criteria, test plan, what is out of scope, and the files it likely touches, based on the current repository.
Permissions in plain words
| Permission | Install question | In Owner policy |
|---|---|---|
| Read files in its own workspace | None | Tick it |
| Create and change files in its own workspace | None | Tick it |
| Run commands inside its sandbox | None | Tick it |
| Reach the internet through the allowlist proxy | None | Tick it |
| Read one repository | “For which repository does it write issues?” | Allowed by your answer |
| Create and update issues in one repository | “For which repository does it write issues?” | Allowed by your answer |
| Read one product’s knowledge | “Which product’s knowledge may it read for context?” (optional) | Allowed by your answer |
| Run in one model lane: Standard | None | Run in one model lane: choose standard and press Allow |
Install questions
- “For which repository does it write issues?” Required. You choose a repository of your GitHub connection.
- “Which product’s knowledge may it read for context?” Optional: Skip (the permission is declined) is offered. You choose a product of the box.
Default autonomy levels
Shown and changed under Administration, Packages, panel Autonomy levels. It has no protected actions, so it never asks for an approval unless you raise a level to “Asks you first”.
| Kind of action | Default level | You can raise it to |
|---|---|---|
| Reads its own workspace | Runs on its own | cannot be raised (Fixed) |
| Writes files in its own workspace | Runs on its own | Tells you after, Waits for your check |
| Reaches the internet through the box’s list | Runs on its own | cannot be raised (Fixed) |
| Reads repositories | Runs on its own | cannot be raised (Fixed) |
| Creates and updates issues | Tells you after | Waits for your check |
| Reads company knowledge | Runs on its own | cannot be raised (Fixed) |
Bob - Instructions Keeper
Section titled “Bob - Instructions Keeper”Package id faivr.agent.build-instructions-keeper, version 1.1.0.
Keeps the repository’s instruction files for coding tools correct and short: checked build, test and lint commands, project rules and limits. It delivers them as pull requests that a person merges.
Permissions in plain words
| Permission | Install question | In Owner policy |
|---|---|---|
| Read files in its own workspace | None | Tick it |
| Create and change files in its own workspace | None | Tick it |
| Run commands inside its sandbox | None | Tick it |
| Reach the internet through the allowlist proxy | None | Tick it |
| Push its own branches and open pull requests on one repository, never merges (includes read) | “Which repository’s coding-tool instructions does it keep?” | Allowed by your answer |
| Run in one model lane: Standard | None | Run in one model lane: choose standard and press Allow |
Install questions
- “Which repository’s coding-tool instructions does it keep?” Required. You choose a repository of your GitHub connection.
Default autonomy levels
Shown and changed under Administration, Packages, panel Autonomy levels. It has no protected actions, so it never asks for an approval unless you raise a level to “Asks you first”.
| Kind of action | Default level | You can raise it to |
|---|---|---|
| Reads its own workspace | Runs on its own | cannot be raised (Fixed) |
| Writes files in its own workspace | Runs on its own | Tells you after, Waits for your check |
| Reaches the internet through the box’s list | Runs on its own | cannot be raised (Fixed) |
| Pushes its own branches and opens pull requests | Tells you after | Waits for your check |
Bob - QA Reviewer
Section titled “Bob - QA Reviewer”Package id faivr.agent.build-qa-reviewer, version 1.2.0.
Gives an independent verdict that can be repeated on one pull request at one commit, against the acceptance criteria of its issue. It never changes the code it reviews.
Permissions in plain words
| Permission | Install question | In Owner policy |
|---|---|---|
| Read files in its own workspace | None | Tick it |
| Create and change files in its own workspace | None | Tick it |
| Run commands inside its sandbox | None | Tick it |
| Reach the internet through the allowlist proxy | None | Tick it |
| Render web pages and take screenshots with the browser inside its sandbox | None | Tick it |
| Read one repository | “Which repository’s pull requests does it review?” | Allowed by your answer |
| Read test results and logs in one repository | “Which repository’s pull requests does it review?” | Allowed by your answer |
| Comment on and review pull requests in one repository (never pushes, never approves, never merges; includes read) | “Which repository’s pull requests does it review?” | Allowed by your answer |
| Read one product’s knowledge | “Which product’s knowledge may it read for context?” (optional) | Allowed by your answer |
| Run in one model lane: Standard | None | Run in one model lane: choose standard and press Allow |
Install questions
- “Which repository’s pull requests does it review?” Required. You choose a repository of your GitHub connection.
- “Which product’s knowledge may it read for context?” Optional: Skip (the permission is declined) is offered. You choose a product of the box.
Default autonomy levels
Shown and changed under Administration, Packages, panel Autonomy levels. It has no protected actions, so it never asks for an approval unless you raise a level to “Asks you first”.
| Kind of action | Default level | You can raise it to |
|---|---|---|
| Reads its own workspace | Runs on its own | cannot be raised (Fixed) |
| Writes files in its own workspace | Runs on its own | Tells you after, Waits for your check |
| Reaches the internet through the box’s list | Runs on its own | cannot be raised (Fixed) |
| Renders web pages in its sandbox | Runs on its own | cannot be raised (Fixed) |
| Reads repositories | Runs on its own | cannot be raised (Fixed) |
| Reads test results | Runs on its own | cannot be raised (Fixed) |
| Comments on and reviews pull requests | Tells you after | Waits for your check |
| Reads company knowledge | Runs on its own | cannot be raised (Fixed) |
Bob - Security Reviewer
Section titled “Bob - Security Reviewer”Package id faivr.agent.build-security-reviewer, version 1.2.0.
Gives an independent security verdict on one pull request at one commit: secrets, dependencies, mistakes in sign-in and access rights, injection and unsafe handling of data. It never changes the code.
Permissions in plain words
| Permission | Install question | In Owner policy |
|---|---|---|
| Read files in its own workspace | None | Tick it |
| Create and change files in its own workspace | None | Tick it |
| Run commands inside its sandbox | None | Tick it |
| Reach the internet through the allowlist proxy | None | Tick it |
| Read one repository | “Which repository’s pull requests does it review for security?” | Allowed by your answer |
| Comment on and review pull requests in one repository (never pushes, never approves, never merges; includes read) | “Which repository’s pull requests does it review for security?” | Allowed by your answer |
| Run in one model lane: Frontier (the strongest model lane) | None | Run in one model lane: choose frontier and press Allow |
Install questions
- “Which repository’s pull requests does it review for security?” Required. You choose a repository of your GitHub connection.
Default autonomy levels
Shown and changed under Administration, Packages, panel Autonomy levels. It has no protected actions, so it never asks for an approval unless you raise a level to “Asks you first”.
| Kind of action | Default level | You can raise it to |
|---|---|---|
| Reads its own workspace | Runs on its own | cannot be raised (Fixed) |
| Writes files in its own workspace | Runs on its own | Tells you after, Waits for your check |
| Reaches the internet through the box’s list | Runs on its own | cannot be raised (Fixed) |
| Reads repositories | Runs on its own | cannot be raised (Fixed) |
| Comments on and reviews pull requests | Tells you after | Waits for your check |
Bob - CI Fixer
Section titled “Bob - CI Fixer”Package id faivr.agent.build-ci-fixer, version 1.2.0.
Finds out why the checks of one pull request fail: it separates infrastructure failures from real ones, finds the cause and writes an exact fix request for the coding tool. It never changes the code.
Permissions in plain words
| Permission | Install question | In Owner policy |
|---|---|---|
| Read files in its own workspace | None | Tick it |
| Create and change files in its own workspace | None | Tick it |
| Run commands inside its sandbox | None | Tick it |
| Reach the internet through the allowlist proxy | None | Tick it |
| Read one repository | “Which repository’s failing checks does it diagnose?” | Allowed by your answer |
| Read test results and logs in one repository | “Which repository’s failing checks does it diagnose?” | Allowed by your answer |
| Comment on and review pull requests in one repository (never pushes, never approves, never merges; includes read) | “Which repository’s failing checks does it diagnose?” | Allowed by your answer |
| Run in one model lane: Standard | None | Run in one model lane: choose standard and press Allow |
Install questions
- “Which repository’s failing checks does it diagnose?” Required. You choose a repository of your GitHub connection.
Default autonomy levels
Shown and changed under Administration, Packages, panel Autonomy levels. It has no protected actions, so it never asks for an approval unless you raise a level to “Asks you first”.
| Kind of action | Default level | You can raise it to |
|---|---|---|
| Reads its own workspace | Runs on its own | cannot be raised (Fixed) |
| Writes files in its own workspace | Runs on its own | Tells you after, Waits for your check |
| Reaches the internet through the box’s list | Runs on its own | cannot be raised (Fixed) |
| Reads repositories | Runs on its own | cannot be raised (Fixed) |
| Reads test results | Runs on its own | cannot be raised (Fixed) |
| Comments on and reviews pull requests | Tells you after | Waits for your check |
Bob - Merge Gate
Section titled “Bob - Merge Gate”Package id faivr.agent.build-merge-gate, version 1.2.0.
Decides whether one pull request is ready for a person to merge (green checks, passed QA and security reviews on the current commit, scope that matches its issue) and drafts its release notes. It never merges.
Permissions in plain words
| Permission | Install question | In Owner policy |
|---|---|---|
| Read files in its own workspace | None | Tick it |
| Create and change files in its own workspace | None | Tick it |
| Run commands inside its sandbox | None | Tick it |
| Reach the internet through the allowlist proxy | None | Tick it |
| Read one repository | “Which repository’s pull requests does it gate?” | Allowed by your answer |
| Read test results and logs in one repository | “Which repository’s pull requests does it gate?” | Allowed by your answer |
| Comment on and review pull requests in one repository (never pushes, never approves, never merges; includes read) | “Which repository’s pull requests does it gate?” | Allowed by your answer |
| Run in one model lane: Standard | None | Run in one model lane: choose standard and press Allow |
Install questions
- “Which repository’s pull requests does it gate?” Required. You choose a repository of your GitHub connection.
Default autonomy levels
Shown and changed under Administration, Packages, panel Autonomy levels. It has no protected actions, so it never asks for an approval unless you raise a level to “Asks you first”.
| Kind of action | Default level | You can raise it to |
|---|---|---|
| Reads its own workspace | Runs on its own | cannot be raised (Fixed) |
| Writes files in its own workspace | Runs on its own | Tells you after, Waits for your check |
| Reaches the internet through the box’s list | Runs on its own | cannot be raised (Fixed) |
| Reads repositories | Runs on its own | cannot be raised (Fixed) |
| Reads test results | Runs on its own | cannot be raised (Fixed) |
| Comments on and reviews pull requests | Tells you after | Waits for your check |
What every worker can never do
Section titled “What every worker can never do”- Work outside its own closed workspace on the box.
- Reach hosts, repositories or products it was not given.
- Merge on GitHub, push to the default branch, or create tags or releases.
- Read a stored key or password.
Example tasks
Section titled “Example tasks”Write these in Chat after choosing the worker. Change the details to your company.
- Bob - Issue Writer: “Write an issue for this request: customers want to export their invoices as CSV.”
- Bob - QA Reviewer: “Review pull request 42 against the acceptance criteria of its issue and give your verdict.”
- Bob - Merge Gate: “Is pull request 42 ready to merge? If yes, draft its release notes.”