Not a promise. Widen agent authority only as the track record earns it.
Agent narrative is untrusted input. Every run ends in a handoff — branch, SHA, PR — reconciled against the worktree, not the model’s word.
What changed, where it landed, what was explicitly not done.
HEAD, dirty state, PR status — read mechanically. Agents never grade their own homework.
Stated confidence vs. how that band actually held up. Recomputed from merge outcomes, not vibes.
Authority widens one rung at a time, per agent, per repo — and every rung is a setting your admins control, not a default we chose for you.
Read-only. The agent maps the codebase, builds memory, proposes nothing.
Diffs and plans for human review. Nothing lands without a person saying so.
Commits to its own branch only. The lane's git truth is reconciled every run.
PRs that pass tests, checks, and your gate policy. Deploy stays human unless you flip it.
Why the agent chose what it chose — recorded at decision time, not reconstructed after.
Every run ends with what changed, where it landed (branch · SHA · PR), and what was explicitly not done.
Every session pinned to its run id and lane — replayable, reviewable, exportable.
No. OAuth is fully server-side — tokens live in the connector vault and API calls are made on the agent's behalf. Prompts contain intent, never secrets.
Not by default. Agents start read-only and earn write access one rung at a time; merges require your gate policy to pass, and deploys stay human unless you decide otherwise.
Kiwi’s default model is included in your plan. If you bring your own keys (OpenAI, Anthropic, and more), model traffic goes to your provider under the data agreement you already trust — Kiwi Code only orchestrates the run.
In isolated, disposable sandboxes — created per run, destroyed after, no residue on your machine and no cross-run contamination.
Kiwi Code is onboarding enterprise teams now.
› Contact Us