Code that was retired,back in the build.
The agent found it, decided it looked useful, and wired it in. The decision to kill it lived in a thread, in a call, in somebody's head. Never in the code.
Governance for coding agents Prevent upstream, verify downstream.
Get early access →Your team already agreed how things get built. bibup hands those decisions to the agent before it writes a line.
Ten years ago, whether code came out well depended on who wrote it. Now anyone can produce code, and building it the way this team already agreed still fails. You have seen at least two of these. Probably this quarter.
The agent found it, decided it looked useful, and wired it in. The decision to kill it lived in a thread, in a call, in somebody's head. Never in the code.
Four repos, four people, four different patches. You find out which one was right when production tells you.
Nobody on that branch knew what the flag was actually for. Somebody three teams over did. The agent said the change was logically correct. It was. Logically.
All of it, dependencies and all, because somebody needed one file-upload module.
If it helps to know it is not just you: duplicated blocks are up 81% since 2023, and moved code, the proxy for refactoring, fell from 21% to 3.8%.
GitClear, 623M code changes analysed, 2023 to 2026
Get early access →No editor, no plugin, nothing new in anyone's day. Two things get installed once, by your platform team: an MCP server your agents already know how to call, and one signed binary in the CI you already run. Your code never leaves it.
We are building it to be the layer, not the app.
what bibup adds what you already run
They are the one who remembers what got rolled back two years ago, so every change waits on them. They never asked for the job.
Every one of those was knowable before the first line was written. It just was not anywhere the person writing the code could get to it.
We are building the thing that speaks up the second time somebody goes to write it.
The same change all the way through, the way it goes once the rules are already there. Every word this product uses is introduced where it is needed, once.
Monday. Bibu asks her agent for a rate limiter on the payments API.
Designing it properly against the system means a week of digging. She is not going to. She describes what she wants and reviews what comes back.
Her agent already has what this team decided, resolved for this repo, before she writes a line.
golden path a pattern somebody here ratified, with their name and the date.
She has a reason to do it differently. She says so.
She does it anyway, and somebody catches it at review. Or nobody does.
The agent names the rule and its owner, and she asks for an exception right there.
detour a signed exception, with a reason, a scope and an expiry date.
Somebody above her signs it, never her. An exception you approve for yourself is how a set of rules turns into a list of things people clicked through.
Thursday. The change is ready to merge.
You find out here, or in production, which is later and costs more.
Things she slipped on, not two hundred things nobody told her.
on path and a receipt, which is what stays after everyone forgets.
A quiet check is the working state, not the idle one. It is also the one that leaves evidence behind.
The ADR nobody reopened, the design doc from two years ago, the contribution guide, the deprecation note, the rules file your agents read. Thin, out of date, and honest about intent.
Every fix, every revert, every 2am hotfix, every import. Complete and impossible to argue with, and it never tells you why anyone did it.
Every tool reviews the code in front of it.
This one remembers what this company already paid to learn.
Get early access →It will block in exactly one case: a rule this organisation ratified, broken with no detour signed. If the context did its job upstream, there is nothing left to block.
And when we are unreachable, your merges are not. The check concludes on its own for up to an hour on the last signed rules it holds, then fails closed. That is the whole promise, including the ceiling on it.
Names, not policies. Every line says who ratified it and when.
The gaps are in it. What expired and what was never covered, on the cover.
It outlives the people. The reason survives the person who had it.
We are writing the first version now. The people on this list are the ones we ask before we decide anything, and the first with their hands on what comes out.
You are in. We will come to you with questions first, and the build right after.