Solumbe¶
Independent trust infrastructure for agents and reviewers¶
For teams that want any coding agent to produce evidence a human can trust before merge.
v4.0.0 is published to npm, GitHub Releases, and the official MCP Registry. Solumbe is a Bashbop Ltd product, MIT licensed.
Formerly Òtítọ́ (@bashbop/otito), renamed in 4.0.0.
About Solumbe
Solumbe is a local-first trust harness for coding agents. It maps repository context before a change, then produces deterministic impact, validation, ownership, and review evidence before merge. It complements model-native agent loops instead of replacing them.
Its command-line and package identity is solumbe.
See the How It Works visual walkthrough: the loop from context before the edit, to a verdict before the merge, to an attestation after it, with every shipped MCP tool in its place.
What's New¶
v4.0.0 published (2026-09-30)
Òtítọ́ is now Solumbe. Behaviour is unchanged from 3.5.0; every name moves, with no fallback to the old ones.
- Install
@bashbop/solumbeand runsolumbe; the MCP server isio.github.BASHBOP/solumbe, so point host configs at the new package and name the serversolumbe(tools becomemcp__solumbe__*). - Rename
.otitorc.jsonto.solumberc.jsonandotito.gate.jsontosolumbe.gate.json, move.otito/and~/.otito/to.solumbe/and~/.solumbe/, and renameOTITO_*variables toSOLUMBE_*. - The CHANGELOG has the full rename map. Releases before 4.0.0 stay on npm as
@bashbop/otito.
v3.5.0 published (2026-09-30)
Model routing can make a share of requests follow the tier it picks, not only recommend it. No command, field or schema was removed.
SOLUMBE_ROUTE_MODE=delegateturns on enforce mode: a share of requests (SOLUMBE_ROUTE_DELEGATE_SHARE, default 0.5) is told to do its tool work in a subagent on the routed tier, and the rest are a control.solumbe routeshows the arm and the subagent model, androute-outcomes.mjs --armgrades each arm separately.- On Claude Code, the premium tier names
claude-opus-5-5, the model that actually runs.
v3.4.0 published (2026-09-29)
One context pack can span a web app and its API, and the router says when it has nothing to go on. No command, field or schema was removed.
context_packandsolumbe contextreadcompanionsfrom a repository's.solumberc.json("companions": ["../api"]), so a web bug whose cause is in the API gets one pack covering both. Explicitpathsstill win; a companion that is not checked out is skipped.change_impactraises risk only from required and supporting files, plus any changed file, not from a domain that only an advisory lead touches.solumbe routeshows each Score question's own confidence next to its score, display only, and says no recommendation when solumbe matched no files, while still naming the fail-safe tier. docs/18 has the detail.context_packreads "bug", "broken" or "crash" as debugging, and ranks the repository a multi-repo request names first;change_impactkeeps a UI page as a required owner without API wording.version:checkfails when the site banner or What's New lags the released version.
v3.3.0 published (2026-09-27)
The terminal output gets colour and shape it didn't have before. No command, field or schema was removed.
- The default terminal look is plain Unicode (
✓ ! ✗, box drawing, arrows) with no emoji; CI,NO_EMOJI,--no-emojiandTERM=dumbkeep ASCII, and--emojiopts back in. Tables, trees and lists come from shared primitives, and every command that prints for a person ends with one closing line such asVerified.orRuns without errors. solumbe installasks a person at a terminal how to install, while--yes,--json, CI and agents get the same output as before.context_packandchange_impactstop ranking translation catalogs, file extensions and test notes ahead of the code a request names; a path or symbol named in the request is pinned as a required owner.- A version bump that reaches
mainis tagged and released by the newTag releaseworkflow, without a hand-pushed tag.
v3.2.0 published (2026-09-26)
The gates gate what they are given. No command, field or schema was removed.
solumbe gateandsolumbe reviewtake the repository from the positional or--path, in local and PR mode alike, and every gate, CLI or MCP, reads policy and governance from the.solumberc.jsonof the repository it gates, not the directory it runs in.- The GitHub PR gate reads whether a PR is open, merged or closed and reports it as
pr.stateandpr.mergedAt, so a merged PR is no longer gated as if it were still open. - A
--pror selector that names no PR is refused rather than gating the wrong thing. Over MCP a blankprreads as no PR, andpr_merge_readinesswith no selector gates the checked-out branch's PR again. - Repair hints name the
@nugehspackages that exist, andsolumbe helpno longer says the legacy MCP tool names stop working at 3.0; docs/02 maps each one to its canonical tool.
v3.1.0 published (2026-09-26)
The router gets graded, and the answer so far is that nothing can grade it yet. Nothing was removed or renamed.
solumbe regretreplays a repository's history and grades the tier each half of the router would have given against the samerepairedoutcomesolumbe calibrateuses;--rescoregrades a new arithmetic on frozen model answers, with no checkout and no model call.- On three repositories no variant orders outcomes, and offline audits of the join and of a same-session outcome say why, so
solumbe routestays advisory. docs/18 has the tables. - The route-prompt hook now keeps every decision it makes (
~/.solumbe/route-decisions.jsonl, never the prompt text), so the router can be graded once enough real requests exist. solumbe attestandsolumbe attest --verifymove post-merge attestation into the CLI, with versioned records and a reusable workflow.
v3.0.0 published (2026-09-25)
The first major since the Solumbe cutover. It follows 1.15.0 directly; the v2.x tags belong to earlier solumbe releases, from before the cutover.
- Breaking: solumbe stops interpreting the request and leaves that to the model.
intent.hints,patternsandagentPromptleave the context pack,implementationPlanleaves impact, andreviewPromptsandnextStepsleave PR review. The ranked files, hotspots, risk flags and review targets they were derived from are unchanged. See Migrating from 1.x. solumbe converge --head <ref>andsolumbe gate --head <ref>score exactlybase..head, so a dirty checkout no longer counts as scope drift. A confirmed owner's own siblings and tests are in scope, not drift; on a 25-file commit that moved convergence from 55 to 84.- Working-tree convergence no longer scores untracked files by default (
--include-untrackedrestores it). - Fixed: post-merge attestation attested the wrong commit, the context pack reported a working tree that no longer existed, and a manual run can now reset an orphaned audit ledger.
v1.15.0 published (2026-09-23)
model_routeis now an MCP tool, so every MCP host (Cursor, VS Code, Claude Desktop, Codex, Gemini) can ask for a tier, not only the CLI.- A request read rides the same System One call: what kind of work it is, which solumbe tool answers it, and which ranked files it needs. It is reported, never scored; the tier is identical with and without it.
solumbe context --online/context_pack { online: true }applies that read to a context pack: it relabels a confident intent and demotes files the model judges irrelevant. Off unless asked.- Any MCP host can appear on a local Realtime Canvas via
SOLUMBE_CANVAS_URLandSOLUMBE_HOST, sending the request text only.
v1.14.0 published (2026-09-20)
- A
UserPromptSubmithook routes every request before any work starts, not only the ones a skill remembers to route. It advises the session and binds the model on delegated subagents; it cannot switch the session's own model, and says so. - Markdown is now indexed, so skills and docs pages can be found. A request naming a skill used to rank unrelated library files; it now ranks the skill first.
- Fixed: a stale stored index kept serving after the indexer changed, including on offline workspace search. Indexes now carry a capability signature and are rebuilt when it moves.
- Fixed: a doc about an auth-like area escalated a typo fix to premium; the router escalated two thirds of requests because it bumped on a model's self-reported confidence (now 0% escalation over nine requests); post-merge attestation died on
exit 128and reported green when it had done nothing.
v1.13.1 published (2026-09-20)
- The documentation pack is rewritten for a reader rather than its author: seven overlapping pages become one deterministic verification page, and navigation is grouped by what you are trying to do.
- The model router skill can offer a realtime canvas, at most once per session.
v1.13.0 published (2026-09-20)
solumbe route <repo> "<request>"scores a coding task before tokens are spent on it and recommends a cheap, mid, or premium tier. solumbe answers the repository half deterministically; a System One model answers the request half with calibrated probabilities. It ships advisory, because the weights have never been graded against an outcome.- The router is not the gate and cannot become one. It runs before work starts; the gate runs after the diff exists. An unreachable or unkeyed model costs a tier, never a verdict.
- Fixed: zero matched files read as a contained change, so the request a repository understood least was routed to the cheapest model. Absence now fails safe to the ceiling.
- Nineteen report commands moved onto the shared document renderer, so every command reads like
reviewandimpact.
v1.12.0 published (2026-09-19)
- Model routing arrived as a prototype alongside the routing doc, dogfooded on a production application where the first pass routed every request to premium and surfaced two defects worth recording.
- A question whose answer never moves carries no information however well calibrated it is: asked as a yes/no, "is this request ambiguous?" returned 0.57 to 0.81 for every request including a typo fix.
v1.11.0 published (2026-09-19)
solumbe calibrate <repo>grades the risk flags against the repository's own history, joining fix commits to the commits they repair by line overlap rather than by filename. Pointed at a small corpus it declines to answer most rows, which is the honest result.configurationwas two signals under one name: manifest-only commits were repaired at 0.42x the base rate, real config files at 2.03x. Merged, they cancelled out and inverted the risk bands, leavingmediumchanges less likely to be repaired thanlowat every window.- A zero-weight flag could gate a merge on its own; gating now requires a flag that scores.
See CHANGELOG.md for the full history.
Documentation¶
Getting started¶
| Document | What it covers |
|---|---|
| Local Core, Optional Hosted | The three core commands, what the optional hosted pieces send and where, and the rules that do not change with a paid plan |
| Context Foundation | Repository inspection, maps, search, context packs, and harnesses |
| MCP and Agents | MCP tools and agent-facing workflows |
| Publishing to npm and the MCP Registry | How Solumbe itself is released |
| Codespaces and Tutorials | Setup and MCP onboarding alongside a tutorials repository |
| Herdr Integration | Context and merge evidence inside persistent agent workspaces |
Using it¶
| Document | What it covers |
|---|---|
| Trust-Layer Demo | Solumbe as a repeatable review workflow |
| Contributor Governance | Protected review, CODEOWNERS, required checks, and merge authority |
| Release Readiness | SemVer, changelog discipline, CI, and release gates |
| Usage Dashboard | Local usage logging and performance trends |
| Builder-Founder Loop | Session rhythm, evidence ledger, and governance ladder |
How it works¶
| Document | What it covers |
|---|---|
| Deterministic Verification | Why merge evidence is computed from the repository, never from the model that wrote the change |
| AX Score Spec | How agent experience is scored |
| Convergence Score Spec | How intent is measured against the diff that appeared |
Measurement¶
| Document | What it covers |
|---|---|
| Calibration | Grading risk flags against a repository's own history |
| Model Routing | Spending a calibrated model on the request side without touching the gate |
Reference¶
| Document | What it covers |
|---|---|
| Evaluation Guide | The accuracy, harness, and gate-effectiveness evals |
| Glossary | Terms used across these pages |
Context Flow¶
Quick Start¶
Prove the deterministic merge gate against the committed valid and adversarial corpus: