Docs
Documentation
Getting started
Get RepoOps running on your machine in under five minutes.
Download for Windows, macOS, or Linux, run the installer, point at your first repo. A one-time, free sign-in, then works fully offline.
How the in-app auto-update works, the manual override, and recovering from a blocked update.
Run the app as its own separate server on its own port and data profile, so it never attaches to a dev server you run from source.
The person-owned brain that follows you across every AI tool, your repos, and your life. Ask it locally, connect it to Claude Desktop / Cursor / ChatGPT via MCP, read it from any app with a scoped token, open it in Obsidian, share a slice.
Invited to a team? Accept, install the desktop app, bind it, and turn on streaming, in one walkthrough for the invited member.
Approve a production workload and deliver metrics, logs, traces, and events independently of developer laptops.
An orientation tab that links to the RepoOps bootstrap prompts and dashboard quickstart in the shared hosted doc-viewer.
Start with one thing
Start with one of the five product areas. Each of these is the shortest real path to a first result.
Which session, prompt and developer produced a line, and what it cost. No configuration and no API key: it reads the session logs your agent already writes.
Find out what your coding agents can reach, then arm exactly one control. Everything ships advisory, so measuring changes nothing until you decide it should.
Turn a finding into a pull request that has already proved itself against a five-check bar. Sensing runs at cents; a build needs your click or your policy's permission.
Reconcile what your provider charged against what your sessions actually used. One command, nothing installed, and useful before you add any provider key.
Start with source-backed facts, preserve reviewed lessons, and connect memory to verified fixes and recurrence evidence.
Today
Where am I, what is here, find anything fast. The daily orient surface.
The person-scope brain you own, on its own page.
Know what to do next. Spend, ship-readiness, vulnerabilities, brain pulse: the one tab to open each morning.
Pick several things off your queue and get one ordered plan: grouped by what a change touches, foundations first, and the human-gated work in its own pull request.
The Today queue when the machine builds the fixes: three bands, an editable build floor and daily cap, and one approve-or-reject decision per finished, verified pull request.
Triage-first alerts ranked by blast radius. Capped, quiet, and suppressed when a lesson already covers it.
One screen of questions, then RepoOps configures itself and verifies every step.
Universal cross-repo file index. Substring search across paths and titles.
The queued and running actions across your repos, with status and one-click open.
Every multi-step workflow run, its slices, and where each one landed.
The /team landing: connected devices, invites, budget alerts, server-owned policy.
The hosted /dashboard view: what stays in the cloud, what stays on each laptop.
Bring your own agent: the recipe for a morning team standup prompted over the RepoOps MCP server.
Your standing situation report. One signal hub for spend, ship-readiness, the queue, and what your next session will load.
Watch
Watch every run, session by session: traces, transcripts, and the record of what shipped.
Live agent sessions in flight, updated as they run.
Your app tells you why it is slow, before you have to ask. Own-runtime health, opt-in terminal capture, and a hosted fleet view of which installs are flapping.
The hosted fleet rollup of own-runtime self-audit findings, grouped per install, showing which machines in your team are flapping or wasteful and an applied fix's measured before and after.
Drill into one Claude Code run: a cost-weighted span waterfall from session to turn to tool.
Drill into a failing run to find the root cause.
The chain from prompt to edit to result, reconstructed for any change.
The filterable PR index across every tracked repo. The conversation record, indexed.
End-of-session journal entries: what got built, what is next, what slowed us down.
Whether Kong, Gravitee, Azure API Management and Apigee can feed the local OTLP receiver. One of the four can, and this says which, why, and how to tell a gateway that is not connected from one whose spans are all being dropped.
The always-on background agent that captures your Claude Code work and keeps your dashboard current with no server running: no inbound port, inert until you opt in, redaction at the point of writing, a real OS service on every platform.
Forensics
Reconstruct what an agent received, did, proved, and learned, without turning missing evidence into a conclusion.
The ordered assignment, attempt, action, verification, review, delivery, and outcome chain, with inferred joins labelled.
Versioned constraints, amendments, supersession, and exposure on the exact attempt.
Deterministic behavior checks first, cited evidence, and open categories left open.
A later defect counts as a miss only inside the revision and scope that was reviewed.
Six bounded validation legs over one immutable prevention package version.
Versioned adapter capabilities, real receipts, and source evidence that is grant-controlled or, on a managed repository, policy-controlled.
A bounded proof pack another reviewer can verify and recount.
Guard
Guard the loop. Trust boundaries, footgun scans, and what will not ship broken.
Incoming items to triage before they reach the review queue.
The anti-pattern rule engine: list, tune, test, and author rules with no code file.
Know it will not ship broken. Trust boundaries, BYOK, threat model, plus a live footgun scan.
Review MCP server trust, permissions, and tool exposure before an agent can cross the boundary.
Turn a security detection into a case somebody works: a lifecycle, a clock your team sets, a playbook over the containment verbs that already ship, and a guard that stops the next one. Evidence never leaves the machine that observed it.
Scope a finding into a brief, build the fix as a pull request in your own checkout, verify it five ways, and decide on the evidence. A failed check stays visible with its reason. Auto-remediation is off until you turn it on: with it off, nothing merges without you.
The loop across every repo you track: one approval queue with the repo named on every item, one floor and one daily cap with per-repo narrowing, and a fix that is built, verified and merged in the repo it belongs to. What each repo can and cannot do is stated before anything runs.
The hosted Incidents tab lists every prevented incident from your team event store, with the guarding-action verb and the dollars it saved.
What each agent and tool is allowed to touch, and where the boundaries sit.
The reach of a change before you ship it: what it touches, what it could break.
The declared read and write scope for each surface, enforced at the boundary.
Runs the same checks CI would, in about 90 seconds, before the PR opens.
Review a diff line by line: brain decision rules, security checks, and blast radius on the changed hunks.
Env-var registry: which file reads what, plus the Doctor's plain-language footgun checks.
Production alerts auto-correlated to the change and the AI session that likely caused them.
The hosted Guard and Manage controls for the team.
The shared team queue of code changes and PRs awaiting human review, with reviewer and status per item.
Four report-only checks that price what running loops unattended costs you. A check with no signal reads unknown, never a fabricated pass.
The team rollup of three local scans over what your agents write: the agent's own diff, hallucinated dependencies, and secrets caught at write time.
Prove
Prove what happened. Outcomes, loop economics, and the accountability ledger.
The proof-of-work record: what shipped, tied back to the intent that asked for it.
A ranked, plain-English story per loop: a session shipped a PR, it introduced a defect, and a lesson now guards it.
The hosted rollup of prevented incidents and dollars saved from measured outcome events over the last 30 days, linked to the guarding Lessons and Decisions.
How AI-coauthored and bot-authored work attributes: one vendor identity table over co-author trailers and bot author identities.
Per-developer AI-tool usage pulled from the vendors' own admin APIs (Cursor, GitHub Copilot), surfaced as a labeled evidence source beside the local evidence.
The public verification page: paste an attestation, get an independent yes or no.
One artifact per benchmark run listing which of the eight controls actually ran, published as an open schema so any vendor's lift can be scored against it, including ours.
Spend
Use more AI, spend less. The aggregated economic view.
The cost case queue, each case's Cost section with billed and measured kept apart, and what the page does not total.
A measured before and after receipt per adopted routing proposal. Not yet measured until the window fills; never a projection.
Reconcile your Claude bill against locally captured token counts.
Know what it cost. Combined-mode Claude Code telemetry across every tracked repo.
Per-session token spend with heuristic and LLM-driven recommendations on where to save.
What a wall of AI subscription seats is producing. A seat with nothing captured reads no activity captured, never unused, and carries what would settle it.
A composite Spend-Efficiency grade over six levers: defaults, routing, caching, context, visibility, ROI.
Telemetry-vs-invoice reconciliation: expected cost recomputed from your own telemetry, joined against Anthropic's usage and cost reports, findings with an evidence bundle finance can dispute with.
A zero-model-token audit that reconciles local Claude Code telemetry against the Anthropic Admin Usage & Cost API and writes an evidence bundle for finance.
The same audit as an .mcpb extension inside Claude Desktop: per-user install for managed laptops, Admin key in the OS keychain, optional background sweep.
What your build pipeline costs, by workflow, by job, and per merged PR. Minutes are measured from each job's own timestamps and rounded up per job the way GitHub bills, then priced from a published rate table, because GitHub exposes no cost API to read for a user-owned account; the page says so above the number rather than in a footnote.
One unified cross-provider view of real metered LLM spend from two lenses that are never summed: provider-reported (authoritative, org-wide) and locally-captured (attributed to this install), each line carrying a per-token, day-level, or per-call precision band, with unconnected providers shown as not connected rather than $0.
Cross-developer activity ledger with integrity proofs. Per-binding drill-down.
Team vendor spend and budget alerts.
The hosted Today, Watch, and Spend rollups in one place.
Brain
A brain that never resets. What your AI learned, the decisions behind the code, the patterns worth keeping.
Review a lesson from its case, see where each version went, and read recurrence as a numerator over a denominator.
Explore the knowledge graph of brain files, code, and concepts.
Publish a slice of your brain as a pack other people can install: pick the memories one by one, read the redaction diff before anything leaves, and bring a published pack up to date without silently shipping what you wrote since.
Last night's lesson proposals: review, accept, reject. The reason your second project goes faster.
Ask your brain a question in plain language and get an answer grounded in your own notes.
The Telemetry mode of Ask the brain: metric questions answer free, anything else runs a bounded tool loop over your telemetry on your own Anthropic key.
One read surface over what the team knows, what it learned this week, what it prevented, and who is working on what.
The active lesson store. Every accepted lesson regenerates into CLAUDE.md and AGENTS.md on next run.
Anything you did twice becomes a proposed prevention rule you accept, reject, or snooze.
The ADR log: every architectural call with the reasoning. The receipts behind the code.
The error-learning loop: what broke, what fixed it, what rule prevents it next time.
The freshness and coverage of your brain: what is decaying, what is missing.
A hosted view over your team's persisted graph store, showing node counts by type, edge counts by source, and confidence bands from a distilled, redacted snapshot the desktop streams on its hourly brain cycle.
The memory that captures itself as you work, no manual note-taking required.
Force-directed graph of brain cross-references. Node size scales with influence.
Draft end-of-session entries generated from the work, ready to review and keep.
Cross-repo pattern library: what is shared across 2 or more repos, what is worth promoting.
The brain pulse rolled up across every connected developer.
The hosted brain read surfaces and what each one exposes.
Hosted Ask runs on your own Anthropic, OpenAI or OpenRouter key. Where to add it and what happens without one.
The team quality score and how it is computed.
Coaching signals rolled up across the team.
Brain freshness and coverage across the team.
Your brain is already a valid Obsidian vault. Point Obsidian at it, install Dataview, get a graph view plus live dashboards. Edits flow back through the write-trust guard.
Mint a scoped, revocable read token and read a slice of your brain from any external property. Copy-paste REST and JS snippets plus a Google Sheets Apps Script template.
An auto-generated descriptive wiki over your repo source.
Manage
Administer the dashboard, onboard new repos, install the brain elsewhere.
The hosted audit log across your team.
The hosted first-run checklist: connect, publish, confirm telemetry.
Add or remove tracked repos at runtime. Manage clients, accounts, BYOK keys, telemetry privacy.
Arm or disarm the advisory controls RepoOps can apply, per repository.
Ask for a change from the dashboard: submit a feature, fix, or cleanup, triage it in Manage, and let the request builder open one human-gated PR per queued request.
Every privileged action, who did it, and when. The tamper-evident record.
Answer a request to read one session's transcript, exclude cycles before you answer, and revoke a grant you gave.
The owner's end of a grant: read the one session a developer granted, see what they withheld, and leave the read on the audit log.
The local-first cryptographic governance surface: ledger verification, redaction posture, policy, file integrity.
The portable brain plus skills plus docs prompt. Port this setup to any repo in one paste.
The full gold-standard repo setup prompt: every convention this project has earned.
Run the local dashboard and read a repo's brain files in it.
The hosted admin surface: members, roles, org policy.
The hosted, tamper-evident audit log for the team.
Team governance: policy, controls, and enforcement.
Team share links and their scopes.
How team licenses work, how billing rolls up, what happens if a license lapses.
Account settings: invites, role management, the linking-code flow for bound devices.
A one-shot launch-readiness audit prompt you can run against any repo.
Workspace tools
Guides for the utilities outside the six sections: connecting sources, installing, recovering the local app and fixing a failed connection.
What each install, binding and source-health failure means, in the words the app uses, and the one check that settles it.
Require enrolled capture on an organization repository, read each installation's coverage, retrieve a case's missing evidence, and gate pull requests on the managed evidence check.
Pages that open from prepared reads and say their age, capture that keeps running when the window closes, and what the app does when the service stops, the network drops or an update lands.
Two optional collectors, what each records, why every browser host reads not claimed, and how each one fails.
Reference
How the system is built, and the direction it is headed. The durable reference docs.
One searchable index over every brain and docs reference for this repo.
Bring your own embedding key: how vector indexing uses it and the fallback when it is missing.
How outbound email meets compliance: unsubscribe, sender identity, and rate rules.
The Partner Proof Spec v1 for vendors: emit your enforcement decisions as NDJSON and they land in the accountability ledger as tamper-evident receipts.
A flat index of every dashboard tab and the doc that covers it.
Every HTTP endpoint the local dashboard and the hosted app serve, with its shape and what reads it.
Every repoops command, grouped, with the invocation you type. Generated from the same registry the binary reads, so the page and the CLI cannot disagree.
The hosted reference index for the team scope.
Which sources each app reads, in which role, which families they observe, and which reads are blocked and on what.
What leaves a developer's machine, what a transcript grant covers, what redaction does before storage, and who can delete a team's rows.
How each home tells a source that observed nothing from a source that observed zero, and why a quiet window never reads as protection.
From a verified incident to a package a second person reviews, a pilot that warns before it blocks, and receipts that say what reached a session.
The eight checks a remedy passes before a case is resolved, the exact-scope approval that lets a fix apply, and what a cost receipt may and may not say.
One case, its identity, the seven sections in one order, the seven statuses and the moves between them, and who may make each move.
The three receipt kinds, the four bases, shares of a shared bill, estimates with their method, what unknown means, and the exact-scope approval.
How a lesson is admitted, the five delivery receipts and six guard outcomes, and how a recurrence is decided against the versioned signature.
The same case on the desktop app, what it pushes and pulls, how a team decision comes back, what stale means, and what the app keeps offline.
Every narrated 30-second feature story with captions and a transcript, one per canonical feature, labeled synthetic, each linking to its guide.
A labeled synthetic walkthrough from Today to the next session: understand the change, verify the remedy, improve the next session, with the missing link named.
Common questions
Do I need an account to use RepoOps?
No account to run the app. The free desktop app runs locally and your code and telemetry stay on your machine. We ask for your email before we show you the download link, and we mail you a one-time link to it. An account is only needed for the paid hosted, team, and enterprise tiers.
How do I install RepoOps?
Download the desktop app for Windows, macOS, or Linux from the download page, or install it from the terminal with npx repoops. It signs you in first. On Windows it then downloads the signed installer, verifies its hash and launches it. On macOS and Linux it opens your build in the browser: those are early, unsigned builds, so your OS asks you to confirm the first launch.
Is there a walkthrough for each feature?
Every surface in the dashboard has a focused doc page, organized around Attribution, AI Security, Remediation, LLM Cost Metrics and Memory, with setup and team administration alongside them. About half of those pages also carry a 30-second video walkthrough, and the docs index shows which guides include video. New walkthroughs ship every release.
Maintenance evidence
- Supported product version
- RepoOps v0.3.2
- Last verified
- 2026-09-26, read against origin/main at e5bb5297b; the index renders DOCS_SPINE and takes its video chips from lib/docs-video-index
- Example fixtures
- None. The page renders DOCS_SPINE and the published video index; it reads no workspace data.
- Video review
- No video by design. The index lists guides; each guide carries its own walkthrough where one exists.
Last updated