One local runtime
The Build and Engineer lenses sit over the same project runtime. The switch preserves mounted terminals and previews rather than exporting to another platform.
A guided lens for people who want the app, not the tooling ceremony. It uses the same local repository and runtime as Engineer mode, with Canopy as the single interaction point.
A declined payment no longer loses the cart or the next attempt.
The title bar already exposes a Build/Engineer switch and an explicit component/run-command target. Missing or stale configuration stops at needs setup; it never guesses the first directory.
The Build and Engineer lenses sit over the same project runtime. The switch preserves mounted terminals and previews rather than exporting to another platform.
A SQLite task-and-attempt store owns transcripts, route snapshots, artifacts, milestones, verification, and recovery ancestry.
Missing evidence and agent declarations cannot become a verification pass. The policy covers checks, navigation, console, network, and visual evidence.
Shared, dirty, contested, moved, incident-affected, or unverified work is refused automatic checkpoint eligibility.
one conversation of record
Build mode does not ask the user to choose a terminal personality for every turn. Canopy owns the conversation while an eligible agent route does the bounded work underneath.
Questions, confirmations, activity, verification, recovery, and outcomes keep one voice even when the executor route changes.
Build mode is designed around a durable TaskEnvelope: the goal, acceptance criteria, target project, risk, verification plan, baseline, and attempt history. A CLI session is one disposable attempt, not the durable identity of the job.
acceptance / target / risk / verification / baselineThe merged verification policy treats an agent's "done" as a declaration, not evidence. Required checks must carry observed pass, fail, or unknown results. The merged checkpoint policy permits automatic history only when work is independently verified, clean, isolated, uncontested, and secret-scanned.
Exact command, exit result, and bounded output.
Server readiness plus an actual navigation result.
DOM state, console, failed network, and screenshot when appearance matters.
Only after every required observation passes and ownership is safe.
Every observation is recorded separately. Partial evidence stays partial instead of collapsing into a green check.
The complete Build story extends beyond chat. Canopy manages the ceremony while the repository, provider resources, and approval boundaries stay yours.
Describe the capability; Canopy proposes and connects the resource through a policy boundary, with credentials kept out of the repo.
Build, evidence, secret checks, environment readiness, and explicit production confirmation before publish.
A provenance-bearing map of pages, routes, data, auth, and services, derived from the real project and observed runtime.
Fleet eligibility first, then a visible retry or replacement attempt from portable state. No invisible model roulette.
Free, MIT licensed, local-first, and built in the open.