AI Engineering Pipeline

Autonomous Engineering Methodology

Cosmos Genesis is built with production-grade autonomous AI engineering — not AI-assisted code generation. Three AI identities and one human architect write, review, verify, and approve every code change. The system detects and corrects its own errors before a human ever sees the diff.

Public reference. This page explains what Cosmos Genesis does and the science it's based on. Implementation details, such as exact algorithms, tuning values and infrastructure, are kept in our internal documentation.

AI-Human Hybrid Team

Each member of the team operates with a distinct role and is deliberately isolated from the others. Isolation is the structural guarantee that review is genuinely independent — not a self-review with a different prompt. Human architectural oversight is not optional: no change reaches the main branch without explicit human approval.

AI — Developer

Claude Code

Implements features, writes production code, and creates merge requests. Operates against the current codebase and Asterion Canon. Produces diffs that are immediately subject to independent review — the developer identity has no visibility into the audit criteria it will be evaluated against.

Feature implementationUnit & integration testsMerge request authorship

AI — Reviewer

Codebase Auditor

Reviews every merge request independently — without access to the developer identity's session, reasoning, or intermediate states. Evaluates code against architectural standards and Canon entries. Raises violations and prescribes corrections. The auditor and developer share no session context.

Architectural standards reviewCanon violation detectionCorrection prescription

AI — Knowledge

Asterion Canon

The living knowledge base that persists project decisions, physics concepts, and architectural history across sessions. Validates Canon entries through a draft → review → activation cycle. Certifies provenance for every item promoted to active status — and surfaces that knowledge to all other identities.

Canon entry validationProvenance certificationKnowledge base integrity

Human — Architect

Shawn Edwards

Human architect and final approver. Sets architectural standards that the auditor enforces, reviews Canon promotions, and approves merge requests. No AI identity can merge to the main branch without human approval. Oversight is structural — not optional.

Architectural directionCanon promotion approvalMerge request sign-off

Pipeline Cycle

Every feature follows a structured cycle that enforces review before integration. The developer does not control whether its work passes review — that decision is made by a separate identity against published architectural standards. The governance CI jobs that run this review are deliberately configured so their pipeline outcome measures whether a review happened and produced feedback, not whether it approved; approval state is tracked separately and is what actually gates whether a change can merge.

Write
↓
Audit
↓
Architectural Guard
↓
Self-Correct

When the auditor identifies a Canon violation, the developer corrects the issue in the same pipeline cycle — without human prompting. The correction is then re-audited before the change is eligible for integration.

By the Numbers

The pipeline emits structured telemetry at every stage, not just a pass/fail signal. These figures are pulled from that telemetry, not estimated — each is reproducible against the underlying event log.

Independent review is a real gate, not a formality

The reviewer identity blocks a merge by revoking approval on the request itself — the same mechanism a human reviewer uses — rather than by failing a CI job. This matters because CI job exit status and merge eligibility are deliberately decoupled: a review that finds nothing to flag still produces a visible, timestamped record that the review happened, and a review that cannot run at all (an upstream outage, for example) fails open with a visible warning attached to the request rather than silently approving it.

Autonomous merge rate

Across a recent two-week measurement window, 73 merge requests reached merge with no human intervention, against 8 that required a human hand-back — categorized by reason (a repeated pipeline failure, an ambiguous product decision, or a review finding the developer identity could not resolve on its own). Every hand-back is logged with its reason, so the intervention rate is a measured figure, not a self-report.

Event pipeline, corrected

Merge and review events reach the pipeline through a GitLab webhook into a serverless event router, which emits structured logs that drive the metrics above. The autonomous session itself does not wait on that push path — it polls for the next actionable event directly, a deliberate simplification adopted after evaluating (and retiring) an earlier push-based notification hop that added infrastructure without a measurable time saving.

Process maturity is incident-tracked

The pipeline's operating procedures are revised in response to documented incidents, not ad hoc. To date, 8distinct incidents — misattributed commits, a race in review polling, a telemetry gap during an infrastructure outage, among others — have each produced a specific, committed procedural fix. The pipeline's current shape is the accumulated result of that record, not a one-time design.

Asterion AI Knowledge Platform

Canon architecture, the six-auditor corps, metadata-first retrieval, and the five user-facing personas — full public documentation.

Read →

Engineering Maturity Signal for Grant Reviews

NSF and NASA SBIR program reviews increasingly evaluate software engineering methodology — not just technical claims. The three-identity pipeline is a verifiable, reproducible methodology: it produces structured audit trails, provenance-certified knowledge, and a documented record of autonomous self-correction. These are auditable outputs, not process assertions.

  • ✓Structured review gates on every code change
  • ✓Provenance chains for all generated physics outputs
  • ✓Documented autonomous error correction cycles
  • ✓Living knowledge base with certified Canon entries
  • ✓Human architectural oversight at all stages
← Back to docs