200 ok is not an alibi. in our owned multi-tenant billing api, a quick fix corrected the price and deleted the tenant check. tenant a got tenant b's invoice with a 200, and uptime stayed green.
oopsie recovers it on its own. clickhouse confirms the violation. two guild-hosted agents investigate and decide, using senso's approved policy. six candidates are tested one at a time: two old rollbacks, a gpt-6-sol repair (openai) and three akash drafts. semgrep scans each one, then the unchanged, hash-locked checks run it in a sealed container with no network or keys. only the passing artifact goes live, and the public api is re-checked twice. mongodb keeps the receipts; elevenlabs voices the briefing.
verified run 3177f589: 5 rejected, 1 shipped, 5/5 checks twice, recovered in 3:51 with no human step. any vendor error becomes needs attention, never a fake green check.
the challenge: before writing, it knows the contract, policy, evidence and release history. it guards tenant isolation and today's schema. it leaves nothing that ships to guess.