One repository. Two ways to work.
Humans get ordinary Git and an editor that never hides commits behind “AI magic.” Agents get isolated Attempts, explicit roles and durable workflows. Both converge on the same review and Integration Queue rules.
Same Git, different interaction
| Concern | Human path | Agent path |
|---|---|---|
| Repository access | Normal git clone/fetch/push or browser editor. | Role-scoped execution against an isolated Attempt branch. |
| Working state | Local working tree or recoverable browser draft. | Attempt branch plus execution/provenance records. |
| Review | Pull Request conversation/checks/files. | Same PR plus structured Review Findings and execution evidence when relevant. |
| Canonical write | Normal policy may permit direct human Git; queued PR integration is available. | Agents do not receive canonical-write authority; integration goes through policy/queue. |
| Conflicts | Familiar Git/textual resolution. | Deterministic repair, semantic contract checks and escalation can run before asking a human. |
Interactive Agent assistance in the editor
The editor now has an interactive assistance mode distinct from autonomous Attempts. The Agent proposal is anchored to a draft revision, so it cannot silently replace newer human edits.
open src/router.go at draft revision 12
│
├─ human asks Agent: "tighten this error path"
│
├─ Agent proposes against revision 12
│ └─ if draft is now revision 13 → stale proposal is rejected
│
├─ proposal applies to the draft
├─ human inspects diff / edits / reverts
└─ human explicitly commits
This is intentionally different from a formal Attempt. Interactive assistance behaves like another editor participant; a formal Attempt is autonomous engineering work with its own branch, executions and PR.
Formal autonomous Attempts
Explicit capabilities
Implementer, reviewer and conflict-resolver roles describe intent/capabilities separately from provider credentials.
Secrets are not authority
A provider secret lets a runner call a model; Switchyard role/policy decides which repository actions are permitted.
Durable by design
Agent/check/review/integration steps survive process death and retain durable evidence.
Humans when necessary
Needs Attention packages the unresolved choice instead of requiring somebody to reconstruct an Agent log.
Why the boundary matters
Many “AI editor” designs blur suggestion, workspace mutation and source-control commit into one action. Switchyard keeps those boundaries explicit. A draft is recoverable working state; a commit is Git history; an Attempt is isolated autonomous work; an integration is a policy/freshness decision. That makes concurrent humans and Agents easier to reason about because each layer has a clear authority model.