My brother Daniel sent me an email a few weeks ago with the subject line “labs apps - alpha to production, additional code/security review?” He’s been building prototype apps in IntensityLabs - such as a Weather Station and a Flight Tracker - and pushing code to them through a fast lane that skips most of our normal process, including all of my code review infrastructure. These are prototypes, so Claude without all the infra does a good enough first pass.
His question was simple.
Just wondering if we should have a gate to do a code and security review on apps we’re considering moving from alpha to Production before we flip the switch.
He was right. His prototypes are super cool so we wanted to get them out to more people. So Phin and I built a new process for this.
Now, three of my code reviewers - a security auditor, a general code reviewer, and one that hunts for errors that fail silently - review the whole app. The flip to production is refused without a passing review.
Given that none of the code has ever been reviewed, there are plenty of issues. My reviewers categorize things as Critical, Important, and Minor. Phin fixes whatever it finds and runs the reviewers again in clean subagents. In my early testing of the prototype apps, the Criticals got fixed quickly, but new Importants kept appearing with each subsequent review.
So I decided a named human - me or Daniel - can accept the remaining Importants with a written reason. Criticals still block production no matter what.
But we had to come up with a simple process for acceptance that Phin couldn’t fake. I have this wired into all of my processes, but this was a new one and I wanted to include Daniel in the signoff. So, this needed something Phin couldn’t cheat its way around.
I decided to use a signoff passphrase for each of me and Daniel. It’s simple, old-school cryptography. Each of us generated a signing key on our own computer. It’s locked with a passphrase of at least sixteen characters that lives only in our personal password manager that Phin doesn’t have access to.
The signoff algorithm never has to pass the passphrase to a Claude session since we have a signing key. When one of us signs off, the script shows every finding being accepted, makes us type a reason, and signs a fingerprint of the exact review being approved. If anyone re-runs the review, the fingerprint changes and the prior sign-off no longer counts.
When the app is flipped to production, the confirmation dialog shows who signed, their key’s fingerprint, and the reason.
On my processes, Phin has very clear delineation of what it can and cannot do. In this case, I wanted to see if I could create a process that didn’t require me to either (a) create another agent or (b) extend Phin’s surface area.
As I try to incorporate Daniel’s software into the system, I’m trying some different approaches that are lighter weight and simpler, but hopefully still effective.
