I am experimenting with separating writing code from authorizing code. The coding agent can push a branch and open a pull request. It cannot produce the cryptographic evidence required to merge that pull request, and it does not hold the merge credential.
This is the smallest useful version of the design behind Herdacat. The included demo is deliberately local and forge-independent so you can run it without creating bots, apps, or cloud infrastructure.