Professional
Triagent — AI Code Review
A platform that runs AI code reviews on GitHub pull requests and gives people and AI agents one place to work through what they find. I built v1 on my own as an internal tool; v2, Triagent, is a ground-up rebuild as a self-hostable, multi-workspace app.
01
Version 1
An internal tool for one organisation. It picked up work from GitHub webhooks (with polling as a fallback), ran reviews on a model chosen through OpenRouter, streamed progress to a dashboard over server-sent events, and had an MCP interface so AI coding tools could start a review and read the results.
02
Version 2: Triagent
Triagent turns that single-organisation prototype into a self-hostable app that anyone can run.
- Every pull request is reviewed automatically through a GitHub App (or a fine-grained token) using Open Code Review, with a summary comment and a commit status on the PR.
- A triage board per branch: filter findings, assign them, correct the reviewer's ratings, mark duplicates and add notes.
- Built for agents as well as people, with an MCP server, a REST API described by OpenAPI, and Markdown views. An agent can claim the most urgent open finding, fix it and mark it resolved, and two agents never get the same one.
- Personal workspaces and organisations, each with their own projects, members, API tokens and model keys. Each workspace picks its own model and pays with its own key.
03
Engineering
- One permission table, shared by the server, the web app and agents. Every route and MCP tool declares the permission it needs, and the tests fail if one doesn't.
- Workspace isolation is tested directly: a test calls every route as an outsider and expects the same 404 as for a workspace that doesn't exist.
- API tokens can never touch secrets, members or other tokens, so a leaked token can't escalate and secrets never pass through an agent.
- Every write is a single transaction, logged for audit. Concurrent edits are caught with revision numbers, and Postgres runs at SERIALIZABLE isolation with automatic retries.
- Live updates over server-sent events, shared across server processes with Postgres LISTEN/NOTIFY. The web app never polls, and never overwrites a form someone is halfway through editing.
04
Where it is now
An early rebuild. The server, the Postgres store and the web app are in place, along with a contract test suite that any Triagent server has to pass. It's licensed under the AGPL-3.0, and v2 will be deployed soon. The code isn't public yet.
05
Stack
TypeScript on Node 24 (the server runs without a build step), Hono, PostgreSQL, React with TanStack Router and Query, shadcn/ui and Vite, Playwright for end-to-end tests, and Open Code Review for the reviews themselves.