# If somebody built a company on code review: what changed in v1.3.0, sgit.ai

> The changes to the article "If somebody built a company on code review" in v1.3.0, paragraph by paragraph.

*Source: <https://sgit.ai/articles/versions/if-somebody-built-a-company-on-code-review/v1.3.0.html> · site v0.7.38 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.*

---

[Home](../../../index.md) / [Articles](../../index.md) / [If somebody built a company on code review](../../if-somebody-built-a-company-on-code-review.md) / [Versions](../if-somebody-built-a-company-on-code-review.md) / v1.3.0

# If somebody built a company on code review: what changed in v1.3.0

From v1.2.0 (2026-10-05, `9e4d1cb45`) to v1.3.0 (2026-10-05, `0ad26f6e6`), paragraph by paragraph.

3 paragraphs added, 0 removed, 28 changed in place, 101 unchanged. About 214 words added and 16 removed. Insertions are marked like this, deletions like this; unchanged runs are folded to one line; figures appear as their file names.

[← v1.2.0](v1.2.0.md) · [all versions](../if-somebody-built-a-company-on-code-review.md) · [v1.4.0 →](v1.4.0.md)

3 unchanged paragraphs

> **Where this comes from, and what is behind it.** A reader of [Code review as a fractal semantic graph](../../../articles/code-review-as-a-fractal-semantic-graph.md) replied with seven questions, each of them the kind that improves the thing it questions, and a voice memo of mine on 5 October 2026 answered them with a change of frame: not what the graph is, but what you would build if the graph were the company. Behind both sits a run of earlier writing this article quotes with its dates: Who[Who should be reading the codecode](https://github.com/the-cyber-boardroom/SGraph-AI__App__Send/blob/dev/team/humans/dinis_cruz/briefs/03/21/v0.16.26__article__who-should-read-the-code.md) (March 2026), How[How vibe coded apps actually ship to productionproduction](https://github.com/the-cyber-boardroom/SGraph-AI__App__Send/blob/dev/team/humans/dinis_cruz/briefs/05/11/v0.27.32__article__explorer-villager-town-planner-vibe-coding-workflow.md) (May 2026), the[the five whys as a translator between domainsdomains](https://github.com/the-cyber-boardroom/SGraph-AI__App__Send/blob/dev/team/humans/dinis_cruz/briefs/06/26/risk-register-and-five-whys/v0.33.35__strategy-brief__five-whys-as-a-domain-translator-natural-peaks-root-cause-stories.md) (June 2026), the open source strategy briefs (June([June](https://github.com/the-cyber-boardroom/SGraph-AI__App__Send/blob/dev/team/humans/dinis_cruz/briefs/06/18/agentic-permissions/v0.33.40__strategy-brief__open-source-strategy-everything-open-line-at-the-customer-compete-on-value.md) and July[July](https://github.com/the-cyber-boardroom/SGraph-AI__App__Send/blob/dev/team/humans/dinis_cruz/briefs/07/17/open-source-strategy/v0.33.49__strategy-brief__sg-send-open-source-as-strategy-not-charity-gen-ai-startups-no-tech-moat-lock-in-in-quality-and-certification-share-across-companies.md) 2026), the[the serialised pull request briefbrief](https://github.com/the-cyber-boardroom/SGraph-AI__App__Send/blob/dev/team/humans/dinis_cruz/briefs/08/14/sgit-site-and-hub/v0.33.58__strategy-brief__sgit-serialised-pull-request-is-the-headline-publish-the-sample-vaults.md) (August 2026), and the[the architecture brief that defines fractal as a precise claimclaim](https://github.com/the-cyber-boardroom/SGraph-AI__App__Send/blob/dev/team/humans/dinis_cruz/briefs/07/12/architecture/v0.33.48__arch-brief__sg-send-fractal-semantic-graphs-agentic-operating-layer-deterministic-sovereign-open-source.md) (July 2026). All of those live in the public SG/Send team record on GitHub, as markdown. The reader is not named here because the questions, not the questioner, are the subject; they know who they are and they have my thanks. Where this article corrects the first one, it says so.

20 unchanged paragraphs, under In short, One technology, every layer, From art to science

The[Themapmap](https://wardley-maps.sgit.ai/patterns/pst/index.html) gives the first fact. We are not adding tests to this because it is an explorer project, and that is fine. We have to add them now because it has customers, and it is a villager project. We are stopping at the boundary of this component because it is a commodity and the behaviour at the boundary is what matters. Each of those is a sentence about where the code is, not about who is in the room, and each can be checked against what the code is doing and who depends on it.

4 unchanged paragraphs, under The grammar is fractal, the layers are yours

The word fractal gets read as "there are many levels", and that reading produces the wrong product. The precise claim is the one the[the architecture brief for the Send platformplatform](https://github.com/the-cyber-boardroom/SGraph-AI__App__Send/blob/dev/team/humans/dinis_cruz/briefs/07/12/architecture/v0.33.48__arch-brief__sg-send-fractal-semantic-graphs-agentic-operating-layer-deterministic-sovereign-open-source.md) made in July 2026: "Fractal is a precise claim, not a decoration. It means four things. Self-similarity: the same node and edge grammar describes an entity, a message, a conversation, a customer, and a tenant. Scale invariance: the same validators, the same query engine, and the same visualisation tools work unchanged at every altitude. Composition: a graph can be a node in another graph, which is the graphs-of-graphs property the corpus already runs on. Recursion: zoom into any node and it expands into a graph obeying the identical rules, with no new format and no special case."

12 unchanged paragraphs, under Build the graph from the top, before the code exists

There is a version of this already running in the way this site and the Send platform are built, and it is worth naming because it is the top half without the bottom half. The Librarian role keeps a set of reality[realityfilesfiles](https://github.com/the-cyber-boardroom/SGraph-AI__App__Send/blob/dev/team/roles/librarian/reality/README.md) whose rule is blunt: "If it's not in a domain index, it does not exist. No agent may claim a feature is 'working' or 'shipped' unless it appears in the appropriate domain's EXISTS section." The reality files are the projected graph being reconciled with the code by hand, by an agent reading briefs and checking the repository, because, as the same file explains, "Agents were confusing ideas described in briefs with features that actually exist in code." A code review company would make that reconciliation the product: the derived graph as the EXISTS section, computed, and the projected graph as the briefs, and the diff between them as the review.

6 unchanged paragraphs, under The layers the example had and the text did not walk, Stories as rules and examples

Example Mapping, as Matt[Matt Wynne described itit](https://cucumber.io/blog/bdd/example-mapping-introduction/) in December 2015, is a conversation that produces four kinds of card: the story, the rules that constrain it, the examples that make each rule concrete, and the questions nobody in the room can answer. It was designed as a way to run a conversation in twenty-five minutes, and it has the property the graph needs, which is that the story is not a paragraph. It is a small tree. The story is the root, the rules are its children, and the examples are the leaves, and a leaf is a thing a test or a run can satisfy.

7 unchanged paragraphs, under A refactor is relative to a layer

This also answers the team's own practice, which the first article's sentence would have contradicted. The[The brief that created the Villager teamteam](https://github.com/SGit-AI/SGit-AI__CLI/blob/main/team/humans/dinis_cruz/briefs/03/12/v0.13.30__brief__code-quality-explorer-villager.md) in March 2026 lists, under refactoring, "Move code to better locations (file structure, module boundaries)" and "Create classes and abstraction layers", and the[the Villager's working agreementagreement](https://github.com/SGit-AI/SGit-AI__CLI/blob/main/team/villager/CLAUDE.md) is "Never change public behavior during a refactoring, only internal structure." Those refactors move the class and module layers and hold the behaviour layer. They are refactors held at a higher altitude, which the general rule allows and the narrow sentence did not.

4 unchanged paragraphs, under Down to the deploy

The non-functional requirements live at that altitude and above it. Performance, availability, cost, security posture and recoverability are properties of the deployed system, not of the code alone, and the sibling site [nfrs.sgit.ai](https://nfrs.sgit.ai/) is this site's attempt to hold its own non-functional requirements as measured claims rather than restated ones. The rule there is "LINK THE MEASUREMENT, NEVER RESTATE IT. GENERATE OR DATE EVERY NUMBER." A review that reads a change at the deploy layer asks which measured claims it can reach, and the Cartographer[Cartographerrolerole](https://github.com/the-cyber-boardroom/SGraph-AI__App__Send/blob/dev/team/roles/cartographer/ROLE.md) in the Send team puts the standard for that layer in one sentence: "If a dependency, data flow, or security boundary exists but is not visible on a map, the Cartographer has failed."

2 unchanged paragraphs, under Who reads the code

The reader's questions about depth and cost have one answer underneath them, and it is Simon Wardley's. The review a change deserves depends on where the thing it changes is on the map: being discovered, being made into a product, or running as a commodity. Wardley's names for the people who do each are explorers, villagers and town planners. He had called them pioneers,[pioneers, settlers and town plannersplanners](https://blog.gardeviance.org/2015/03/on-pioneers-settlers-town-planners-and.html) in 2015 and asked[asked people to use the new wordswords](https://x.com/swardley/status/1618298060076945414) in January 2023, writing[writinglaterlater](https://blog.gardeviance.org/2023/12/how-to-organise-yourself-dangerous-path.html) that "the colonialist overtone of those terms made it problematic for many and with good reason". I have used the new names since a[a June 2025 piece on the generative AI divide,divide](https://diniscruz.ai/2025/06/10/explorers-villagers-and-town-planners-understanding-the-generative-ai-divide.md), for the split between the people who find things, the people who make them solid and the people who run them at scale.

In March 2026 I wrote an article titled Who[Who should be reading the code,code](https://github.com/the-cyber-boardroom/SGraph-AI__App__Send/blob/dev/team/humans/dinis_cruz/briefs/03/21/v0.16.26__article__who-should-read-the-code.md), and it is the frame this company would be built on. It opens with a caveat worth keeping: "Before AI agents started writing code, you could argue that 90% of the code running in production was not being read by anyone." Then it answers by phase. "So who reads Explorer code? Mostly other agents. Agents that do security scans, basic quality checks, dependency audits. These are imperfect reviewers, but they catch the obvious problems early." Villager code is where reading begins: "This is where code needs to be read. Not glanced at. Read. Understood. Questioned. Refactored." And town planners "really read it. They debate, question, and verify at an architectural level."

1 unchanged paragraph

The graph changes what each of those sentences costs. For explorer code, map the stories, the commands and a sketch of the components, enough to see the shape, and stop; the model can propose everywhere here because nothing depends on the code yet. For villager code, map all the way down, because this is where changes reach customers and where the blast radius lives; humans read the contracts, the class shapes and the call paths that changed, and agents read the rest. For town planner code, stop at the boundary. Map a commodity's behaviour, not its insides; the checks are graph queries and they have to be deterministic, and a person reads the exceptions. A model has no place in line on a mission-critical path, and the[the skill lifecycle briefbrief](https://github.com/the-cyber-boardroom/SGraph-AI__App__Send/blob/dev/team/humans/dinis_cruz/briefs/06/04/v0.32.3__strategy-brief__sg-send-skill-lifecycle-explorer-to-town-planner-english-to-code.md) from June 2026 says why in the voice of the memo it came from: "Anybody who spends a lot of money on tokens has an engineering problem. They are using explorer-type code and solutions in a commodity environment."

This is where the company sits. In the two moves. From explorer to villager, when a guess becomes a product and needs a review it never had, and the graph has to be built for the first time from code that was written to be thrown away. From villager to town planner, when a product becomes a commodity and the review becomes a set of checks that run without anyone, and the graph has to be good enough to be the checks. The trap on both sides is the same, and the[the May 2026 article on how vibe coded apps actually shipship](https://github.com/the-cyber-boardroom/SGraph-AI__App__Send/blob/dev/team/humans/dinis_cruz/briefs/05/11/v0.27.32__article__explorer-villager-town-planner-vibe-coding-workflow.md) names it: teams discover that a model's mistakes are too risky and swing to the other extreme, reviewing everything by hand, which the volume of generated code makes impossible, and both extremes come from not knowing which stage the code is at.

4 unchanged paragraphs, under Review is not saying no

Review, in this shape, is not saying no. It is sorting what can go fast from what must go slow, and giving the slow part to people who have the context to decide well. The faster the first class moves, the more attention the third class gets. I wrote a version of this in the SecDevOps[SecDevOps Risk WorkflowWorkflow](https://leanpub.com/secdevops) book a decade ago, from the security side: "When you do a code review, you tend to visualize a slice of a model of the application. Your focus is fixed entirely on the problem at hand", so "you need systems that can flag when something is a problem, or needs to be reviewed." The graph is that system, and the slice it hands the reviewer is the method[methodstream.stream](https://diniscruz.ai/2025/02/11/o2-platforms-methodstreams-2010-open-source-sast-engine.md). And the thing that makes the whole arrangement safe is the thing the[the March article on the Villager phasephase](https://github.com/the-cyber-boardroom/SGraph-AI__App__Send/blob/dev/team/humans/dinis_cruz/briefs/03/22/v0.16.38__article__villager-phase-refactoring.md) recorded about a real review: a bug in which a model had invented an API call "would not have been caught by tests alone, because the tests would have been written against the same hallucinated API". It was caught by a person reading the code. The graph's job is to make sure that person is reading the fifty lines and not the ten thousand.

The[The brief on the serialised pull requestrequest](https://github.com/the-cyber-boardroom/SGraph-AI__App__Send/blob/dev/team/humans/dinis_cruz/briefs/08/14/sgit-site-and-hub/v0.33.58__strategy-brief__sgit-serialised-pull-request-is-the-headline-publish-the-sample-vaults.md) from August 2026 has the other half of this. "A serialised diff is not a missing pull request. It is a different and, for agent collaboration, better one." The review surface does not have to be a hosted page with an approve button. It can be a vault holding the change and the graph of what it reaches, read by a person on another machine with a read key, which is how the patches in that Villager phase actually moved, sixteen of them, as encrypted vaults.

2 unchanged paragraphs, under Replicate reality first

The order of operations I would build the company on is to replicate reality before having an opinion about it. Derive from the code what a parser can derive, deterministically, with no model in line, so that every node has a file and a line and every number is checkable. This is the[the rule I set out in July 20252025](https://diniscruz.ai/2025/07/06/from-large-language-models-to-small-models-and-code-the-evolution-of-ai-solutions.md) for every model-driven solution, "use LLMs to figure out the solution, then use code to execute the solution thereafter", and in a graph the rules that matter are plain to execute. The[The 2025 piece on semantic knowledge graphs for source code analysisanalysis](https://diniscruz.ai/2025/05/29/semantic-knowledge-graphs-for-llm-driven-source-code-analysis.md) gave the example: "we check that every endpoint function node has an edge to an Auth check node; the ones that don't are instantly known." Let a model propose what a parser cannot see, the story a command serves, the intent behind a module, the edge a dynamic dispatch hides, and mark every proposal as proposed. Then confront the graph with the three things that can correct it: users, who confirm whether a story holds; experts, who each read the layer they know; and tests, mapped from imports and confirmed by execution. Every correction is a commit to the graph files. Only then is the conversation about the code a conversation about facts, and the memo put it as "replicate reality first, then have a fact-based conversation".

Synthetic users are part of that, and earlier than most teams put them. The architecture review and the simulation come before the code in the order above, and the simulation is a run of synthetic users through the projected graph: characters, not scripts, as a[a brief from February 20262026](https://github.com/the-cyber-boardroom/SGraph-AI__App__Send/blob/dev/team/humans/dinis_cruz/briefs/02/12/v0.2.16__briefs__dpo-observability-tabletop-synthetic-users-playwright.md) insisted, "with realistic behaviour patterns, including getting lost, clicking wrong things, and taking happy paths." This site ran[ran that against itself in SeptemberSeptember](../../../updates/index.md#synthetic-users) and recorded forty-three steps, fifteen questions the site did not answer and ten confusions, with the rule that "a run with no confusion anywhere is treated as a run done badly." Run against a projected graph before code exists, the same synthetic users find the stories that contradict each other and the flows that go nowhere, which is the cheapest possible time to find them.

Time is the other dimension, and the graph has to carry it. Every derived layer, every proposal, every correction and every run is a version, so the review can go back to the graph as it was when a decision was taken and ask what the change reached then. That is the twin's property: a journal plus a replay. The[The one-shot approachapproach](https://github.com/the-cyber-boardroom/SGraph-AI__App__Send/blob/dev/team/humans/dinis_cruz/briefs/03/30/v0.19.7__arch-brief__oneshot-feedback-loops.md) to working with models that the Send team uses is built on it, "curate reality, send it all at once, get the answer, then use the answer to improve the reality for the next prompt", and the[the bundles it sendssends](https://github.com/the-cyber-boardroom/SGraph-AI__App__Send/blob/dev/team/humans/dinis_cruz/briefs/03/09/article__one-shot-llm-controlling-reality.md) are "versioned. They're replayable. I can load a previous bundle, change one element, and re-execute." A code review company would do that for the graph: load the repository's reality as it was, change one node, replay the review.

3 unchanged paragraphs, under Constraints keep it in control, the five whys make it cheaper

The first part is constraints, decided before anything runs. Agents keep going; that is what they do, and one agent handing work to another looks efficient while it spends. The way to stay on the right side of diminishing returns is a budget per altitude and per change, declared in advance, which is the same move the[the Send team's workflow briefbrief](https://github.com/the-cyber-boardroom/SGraph-AI__App__Send/blob/dev/team/humans/dinis_cruz/briefs/08/06/voice-debrief/v0.33.56__dev-brief__sg-send-workflows-as-state-machines-budget-on-the-step-disagreement-is-the-product.md) made in August 2026: "a per-step ceiling declared before execution" that "makes a workflow's maximum cost knowable before it runs rather than discovered afterwards." Deterministic checks over the derived layers cost compute and no tokens, and always run. The delta re-derives the files the change touched and what depends on them, never the repository. A model summarising what moved against what was intended gets a small budget and a hard stop. A model proposing edges and stories gets a larger budget and every output marked proposed. Work handed from agent to agent carries its budget with it and never widens it, and the cost of a change becomes one more thing the graph can show about it.

2 unchanged paragraphs

The second part is what makes the whole thing cheaper every time, and it is the five whys. Every finding at one layer is a question about the layer below. Why did the story stop holding? A command's behaviour changed. Why did the command change? A method on its path was edited to satisfy a test elsewhere. Why was the reach not seen? The call went through a base class and the review read the diff, not the graph. Why did no check catch it? There was no rule that a change reaching a customer-facing command needs a human. So the fix is below the bug: add the rule, as a graph query, and the next change like it is caught for the price of a query, not a review. I wrote about the[the five whys as a translator between domainsdomains](https://github.com/the-cyber-boardroom/SGraph-AI__App__Send/blob/dev/team/humans/dinis_cruz/briefs/06/26/risk-register-and-five-whys/v0.33.35__strategy-brief__five-whys-as-a-domain-translator-natural-peaks-root-cause-stories.md) in June 2026, and the point there holds here: the chain "is just as powerful aimed downward, into causes", capturing "the second, third, and fourth stories". The[The March article on who reads the codecode](https://github.com/the-cyber-boardroom/SGraph-AI__App__Send/blob/dev/team/humans/dinis_cruz/briefs/03/21/v0.16.26__article__who-should-read-the-code.md) said the same thing about process: when an issue reaches the town planner that the villager phase should have caught, "that is an incident. Why did this reach the Town Planner? What was missing in the Villager's review process? Fix the process, not just the code."

9 unchanged paragraphs, under What to compare the blast radius to, and how long the report should be, The company

So the only model I would consider is open[opensource,source](https://open-source.sgit.ai/), in the way the[the Send team's strategy briefsbriefs](https://github.com/the-cyber-boardroom/SGraph-AI__App__Send/blob/dev/team/humans/dinis_cruz/briefs/06/18/agentic-permissions/v0.33.40__strategy-brief__open-source-strategy-everything-open-line-at-the-customer-compete-on-value.md) have put it this year. "Everything the company does, code, logic, functionality, and schemas, is open source, with no proprietary core and no bait model where the best features are locked away, and the only line is at the customer boundary." The commercial hook is the customised deployment: the layers configured for this company's culture, languages and stack; the loop run and tuned for them; the rules that accumulate from their findings; and the record, versioned, that shows what every change reached and who decided what. The[The brief from June 20262026](https://github.com/the-cyber-boardroom/SGraph-AI__App__Send/blob/dev/team/humans/dinis_cruz/briefs/06/18/agentic-permissions/v0.33.40__strategy-brief__open-source-strategy-everything-open-line-at-the-customer-compete-on-value.md) says why that is a business rather than a service: "one model is that we host customisations and mass-customised deployments, because it is cheaper for the customer to pay us than to run it themselves." And the[the July briefbrief](https://github.com/the-cyber-boardroom/SGraph-AI__App__Send/blob/dev/team/humans/dinis_cruz/briefs/07/17/open-source-strategy/v0.33.49__strategy-brief__sg-send-open-source-as-strategy-not-charity-gen-ai-startups-no-tech-moat-lock-in-in-quality-and-certification-share-across-companies.md) says what open source does to the moat: it "removes technology as the moat, and relocates the lock-in somewhere more durable and more honest". The sibling site [open-source.sgit.ai](https://open-source.sgit.ai/) says where that is: "the lock-in is in the quality and the services and the new versions and the maintainability and the certification", and puts the offer to a customer in one line, "You can take it. It will cost you that. Or you can pay me, and have it next week." For a code review company the thing they can take is the grammar and the tools, and the thing they pay for is the layers configured, the loop running and the rules accumulated for them.

5 unchanged paragraphs, under What the first article got wrong, and what this one leaves open

## The article as one page, by another model

As with the two articles before it, Dinis fed the published text to ChatGPT and asked for an infographic, and it is below after a check against the article. The layers, the before and after, the grammar and layers distinction, the projected and derived graphs with the three outcomes of the join, the held layer, the deploy, the three stages, the sorting by reach, the budgets, the five whys and the company are all as the article has them, and nothing was invented. Two lines in quotation marks, "same reader, every altitude" and "standardise the grammar, not the customer's worldview", are the other model's condensations of sentences here rather than sentences from here; they are fair ones.

[figure cr2-one-page-by-another-model.webp] The article as a one-page state, generated with ChatGPT from the published text on 5 October 2026 and credited by it to the source. The style and the slogans in the margins are the other model's, kept as they came, because who made a condensation is part of its provenance.

9 unchanged paragraphs, under Threads woven here, Sources

• Dinis Cruz, Who[Who should be reading the code,code](https://github.com/the-cyber-boardroom/SGraph-AI__App__Send/blob/dev/team/humans/dinis_cruz/briefs/03/21/v0.16.26__article__who-should-read-the-code.md), March 2026; and The[The Villager phase: what happens when you actually read the code your agents wrote,wrote](https://github.com/the-cyber-boardroom/SGraph-AI__App__Send/blob/dev/team/humans/dinis_cruz/briefs/03/22/v0.16.38__article__villager-phase-refactoring.md), March 2026. Both in the SG/Send team record, [the-cyber-boardroom/SGraph-AI__App__Send](https://github.com/the-cyber-boardroom/SGraph-AI__App__Send), underwhichteam/humans/dinis_cruz/briefs/03/21isand 03/22.public.

• Dinis Cruz, How[How vibe coded apps actually ship to production: the Explorer, Villager, Town Planner workflow,workflow](https://github.com/the-cyber-boardroom/SGraph-AI__App__Send/blob/dev/team/humans/dinis_cruz/briefs/05/11/v0.27.32__article__explorer-villager-town-planner-vibe-coding-workflow.md), May 2026, same record, briefs/05/11.record.

4 unchanged paragraphs

• Dinis Cruz, SecDevOps[SecDevOps Risk Workflow,Workflow](https://leanpub.com/secdevops), Leanpub, [source on GitHub](https://github.com/DinisCruz/Book_SecDevOps_Risk_Workflow), the chapters Can't do security analysis when doing code review, Feedback loops are key, and Every bug is an opportunity.

2 unchanged paragraphs

• SG/Send architecture brief, Fractal[Fractal semantic graphs as the agentic operating layer,layer](https://github.com/the-cyber-boardroom/SGraph-AI__App__Send/blob/dev/team/humans/dinis_cruz/briefs/07/12/architecture/v0.33.48__arch-brief__sg-send-fractal-semantic-graphs-agentic-operating-layer-deterministic-sovereign-open-source.md), July 2026, same record, briefs/07/12/architecture;2026; the four-part definition of fractal quoted above.

• SG/Send strategy brief, The[The five whys as a translator between domains,domains](https://github.com/the-cyber-boardroom/SGraph-AI__App__Send/blob/dev/team/humans/dinis_cruz/briefs/06/26/risk-register-and-five-whys/v0.33.35__strategy-brief__five-whys-as-a-domain-translator-natural-peaks-root-cause-stories.md), June 2026, briefs/06/26;2026; and Dinis Cruz, [Second stories: from Three Mile Island to cybersecurity](https://diniscruz.ai/2025/02/10/second-stories__from-three-mile-island-to-cybersecurity.md), diniscruz.ai, 10 February 2025.

• SG/Send strategy briefs on open source: The[The open source strategy, everything open, the line at the customer,customer](https://github.com/the-cyber-boardroom/SGraph-AI__App__Send/blob/dev/team/humans/dinis_cruz/briefs/06/18/agentic-permissions/v0.33.40__strategy-brief__open-source-strategy-everything-open-line-at-the-customer-compete-on-value.md), June 2026,2026;briefs/06/18; Open[Open source as strategy, not charity,charity](https://github.com/the-cyber-boardroom/SGraph-AI__App__Send/blob/dev/team/humans/dinis_cruz/briefs/07/17/open-source-strategy/v0.33.49__strategy-brief__sg-send-open-source-as-strategy-not-charity-gen-ai-startups-no-tech-moat-lock-in-in-quality-and-certification-share-across-companies.md), July 2026, briefs/07/17;2026; and Dinis Cruz, The[The moat on an open source stack,stack](https://github.com/the-cyber-boardroom/SGraph-AI__App__Send/blob/dev/team/humans/dinis_cruz/briefs/05/02/v0.27.5__article__moat-on-open-source-stack.md), May 2026, briefs/05/02.2026.

• SG/Send strategy brief, The[The serialised pull request is the headline,headline](https://github.com/the-cyber-boardroom/SGraph-AI__App__Send/blob/dev/team/humans/dinis_cruz/briefs/08/14/sgit-site-and-hub/v0.33.58__strategy-brief__sgit-serialised-pull-request-is-the-headline-publish-the-sample-vaults.md), August 2026, briefs/08/14;2026; and the dev brief, Workflows[Workflows as state machines, budget on the step,step](https://github.com/the-cyber-boardroom/SGraph-AI__App__Send/blob/dev/team/humans/dinis_cruz/briefs/08/06/voice-debrief/v0.33.56__dev-brief__sg-send-workflows-as-state-machines-budget-on-the-step-disagreement-is-the-product.md), August 2026, briefs/08/06.2026.

• SG/Send strategy brief, Skill[Skill lifecycle from explorer to town planner,planner](https://github.com/the-cyber-boardroom/SGraph-AI__App__Send/blob/dev/team/humans/dinis_cruz/briefs/06/04/v0.32.3__strategy-brief__sg-send-skill-lifecycle-explorer-to-town-planner-english-to-code.md), June 2026, briefs/06/04;2026; the Librarian's reality[realityfiles, team/roles/librarian/reality/README.md;files](https://github.com/the-cyber-boardroom/SGraph-AI__App__Send/blob/dev/team/roles/librarian/reality/README.md); the Cartographer[Cartographerrole, team/roles/cartographer;role](https://github.com/the-cyber-boardroom/SGraph-AI__App__Send/blob/dev/team/roles/cartographer/ROLE.md); the one-shot[one-shot feedback loops brief, briefs/03/30;brief](https://github.com/the-cyber-boardroom/SGraph-AI__App__Send/blob/dev/team/humans/dinis_cruz/briefs/03/30/v0.19.7__arch-brief__oneshot-feedback-loops.md) and the synthetic[one-shot article on controlling reality](https://github.com/the-cyber-boardroom/SGraph-AI__App__Send/blob/dev/team/humans/dinis_cruz/briefs/03/09/article__one-shot-llm-controlling-reality.md), March 2026; the [briefing packs for agents](https://github.com/the-cyber-boardroom/SGraph-AI__App__Send/blob/dev/team/humans/dinis_cruz/briefs/02/16/v0.4.4__briefs__briefing-packs-for-agents.md) brief with the method streams principle, February 2026; and the [synthetic users brief,brief](https://github.com/the-cyber-boardroom/SGraph-AI__App__Send/blob/dev/team/humans/dinis_cruz/briefs/02/12/v0.2.16__briefs__dpo-observability-tabletop-synthetic-users-playwright.md),briefs/02/12.February 2026.

1 unchanged paragraph

• The[The Villager team brief, Code quality: explorer and villager,villager](https://github.com/SGit-AI/SGit-AI__CLI/blob/main/team/humans/dinis_cruz/briefs/03/12/v0.13.30__brief__code-quality-explorer-villager.md), 12 March 2026, in the sgit CLI repository under team/humans/dinis_cruz/briefs/03/12;repository; and the[the Villager team's CLAUDE.mdworkingand architect role, team/villager.agreements](https://github.com/SGit-AI/SGit-AI__CLI/blob/main/team/villager/CLAUDE.md).

1 unchanged paragraph

[← v1.2.0](v1.2.0.md) · [all versions](../if-somebody-built-a-company-on-code-review.md) · [v1.4.0 →](v1.4.0.md)


---

*[Site index for agents](../../../llms.txt) · [HTML version](https://sgit.ai/articles/versions/if-somebody-built-a-company-on-code-review/v1.3.0.html)*
