I start October routing reviews with one rude question. If the private monorepo vanished from the queue, would you still be arguing about tokens?
Most weeks the answer is no. The fight was never about the pool. It was about who is allowed to see the diff.
Picture a Thursday in early October. Two senior maintainers. A public repo that suddenly has a crowd. A private monorepo that cannot leak. Someone posts, 'We already have a free lane. Why are the seniors still reading every patch by hand?'
Good instinct. Bad unit.
Three lanes, one job
The job is narrow. Draft a review note. Suggest a small patch. A human still merges.
The lanes are not narrow. They fail for different reasons.
- A free hosted lane, sometimes paired with a free server you do not pay for yet.
- A paid vendor lane, where the invoice is really a contract.
- A self-hosted lane, where you own the process and the pager.
Which one should hold a contribution spike? I do not start from the sticker. I start from custody.
What the brief actually states
Disclosure: This article was prepared as part of MonkeyCode's product outreach.
The brief for this piece describes MonkeyCode as an open-source project, with free model access and a free server option. It also states a free-token pool of 10 million tokens. That is the claim I was given, dated against 8 October 2026. It is not a screenshot from last quarter, and it is not an SLA I measured.
Read the license file and the allowance page on the day you decide. A wiki paste of a token number is how teams budget a sprint on a stale page.
What I refuse to infer
I am not adding model names, hardware sizes, uptime, latency, or a quality score. I am not saying the pool is permanent. I am not saying the free server has a duration.
A large pool can still be the wrong lane. Have you watched a team miss that?
Open source does not mean 'fine for customer code.' It means you can read the license. If you have not opened that file, you do not have a lane yet. You have a rumor.
Name the variables, or the meeting is theater
I will not score a lane until these symbols are written down. If a symbol has no owner, it does not enter the decision.
-
V— share of assisted tasks that touch private code, secrets, or customer data. From 0 to 1. -
C— custody bar.0means public code only.1means prompts and diffs stay in a tenant you control. -
A— assisted diffs you expect per week. -
H— minutes a named reviewer will actually spend on each assisted diff. Not the minutes you wish they had. -
R— reviewer hours available per week for this lane. -
S— spike length in weeks. -
T— tokens per assisted diff, measured on your repos. Not borrowed from a launch post. -
F— stated free-token pool. The brief says 10,000,000. Re-read it. Do not hard-code a blog. -
U— paid price per million tokens, from a quote you hold. I will not invent one. -
O— self-host ops hours per week, times loaded hourly cost.
Review load is A * H / 60. If that exceeds R, stop. You do not have a model problem. You have a calendar problem.
Spike burn is A * S * T. Headroom is F / burn - 1. I want at least 0.20 before a free pool carries a public spike. That 0.20 is a policy choice. Say so in the ticket.
A scorecard is a conversation tool. It is not objective truth. Change the threshold and you can change the winner. Pretending otherwise is how a worksheet becomes a slogan.
Fill last year's spike before you guess A
Do not borrow my sketch as your forecast. Count your own default branch. Last October is a baseline, not a destiny.
# Merges in last October. Swap the branch and the dates.
git log origin/main --since="2025-10-01" --until="2025-10-28" --merges --oneline | wc -l
# Who actually merged? If two names dominate, R is smaller than the org chart.
git log origin/main --since="2025-10-01" --until="2025-10-28" --merges --pretty=format:'%an' | sort | uniq -c | sort -nr
Public-event calendars make October loud. Hacktoberfest is the obvious one. I am not quoting this year's rules, prizes, or dates. If badges matter to your contributors, read the current event page. Your merge log matters more than the badge.
Why pull last year at all? Because a spike you did not count will be replaced by a round number someone likes. Round numbers are where free pools go to die.
A sketch, so the arithmetic is visible
Not a customer. Not a benchmark. Replace every number before you forward this to finance.
- Public assisted diffs: 40 per week. Private: 8 per week.
-
H= 12 minutes. Two reviewers, 5 hours each, soR= 10. -
S= 4.T= 8,000. Illustrative until you measure 20 real diffs. -
U= 3 currency units per million tokens. Placeholder. Throw it out when the quote arrives. - Self-host: 4 ops hours per week at 80 per hour, so weekly
O= 320.
Public review load is 40 * 12 / 60 = 8 hours. Private adds 1.6. Total 9.6 against 10. One sick day and the lane is fiction.
Public burn is 40 * 4 * 8000 = 1,280,000 tokens. Private adds 256,000. Combined 1,536,000. Against a stated pool of 10,000,000, headroom looks luxurious. Only if that pool is still the number on the page. And only if private diffs are allowed to leave your tenant.
They are not, in this sketch. So the free hosted column dies on the private slice even while the pool looks fat. See how fast the sticker stopped mattering?
Paid token bill at the placeholder rate is about 1.536 * 3 = 4.6 currency units for the month. Tiny next to reviewer time. If your real quote looks like this, do not pretend price is the decision. If your quote is a hundred times higher, rerun the line. Still compare it to ops cost and to R, not to a vibe.
Self-host for four weeks is 320 * 4 = 1,280 before any machine you already rack. You are buying control. You are also buying a ceiling you have to measure yourself. I am not going to invent that ceiling here.
What flips the call
Would you still send those 8 private diffs if the free pool doubled? I would not. Custody does not scale with tokens.
Would you still self-host if every assisted diff stayed on public repos whose license you already understand? Maybe not. Ops cost is a tax on control you may not need for a four-week crowd.
Would you still buy the paid lane if counsel says the free hosted terms already clear your bar for public code? Then buy only the private slice. A blend rate for work that never needed it is how budgets get muddy.
Three sensitivities. Then stop debating adjectives.
- If
Tis 5x the sketch, public burn alone is 6.4 million. Add the private slice and you are leaning on a pool you have not re-read. MeasureTbefore you argue. - If
Hmoves from 12 to 20 minutes, public review load is 13.3 hours. OverR. The lane is a no at every price, including free. - If private work becomes half the queue, free hosted is out. Do not negotiate with that gate.
| Lane | Fits when | Fails when | What you actually pay |
|---|---|---|---|
| Free hosted, plus the stated free server option | Public repos, license read, allowance re-checked today, no unnamed tool grant | Any private or secret path, unread terms, pool you cannot point to | Reviewer hours, and the chance the allowance moves |
| Paid | Counsel accepts the terms and the private slice is real | The quote is standing in for a custody rule you never wrote | Quote, switching cost, reviewer hours |
| Self-host |
C = 1 and someone owns the pager through expiry |
No pager owner, or you only needed public notes | Ops hours, plus a ceiling you measure |
Gates, owner, expiry, exit
Five gates. Fail one, and that workload leaves the free hosted column. I do not average them into a green score.
- Custody. A secret, a production credential, a customer payload, or a private repo sits in the prompt path. Free hosted is a no.
-
Review capacity.
A * H / 60 > R. Cut scope or add a human. Do not add a model and call it a plan. - Pool headroom. Spike burn exceeds 80% of the stated pool, or you cannot open the allowance page today. Do not plan on it.
- License. You have not read the project license and the output terms against the repo you merge into. Stop.
- Tool reach. The assistant can call tools outside the repo. That is a grant. No named owner, no grant.
Owner: one engineering manager, named on the ticket. A Slack channel is not an owner.
Expiry: the last day of the spike, or 30 days from the decision, whichever comes first. An allowance you have not re-checked is an expired assumption.
Exit: archive the routing note when private share crosses your line, when the allowance page changes, or when reviewers miss H for two weeks. A stale 'free is fine' wiki page is how the next incident gets a head start.
Who writes the archive line? The same named owner. If they have left the team, the note expires that day. Do not inherit a dead assumption with the repo.
Run both cases before the meeting
This script is a worksheet. It does not call a model. It does not time a server. I am not publishing it as a benchmark. Paste your numbers. Read the fails.
#!/usr/bin/env python3
"""Custody gate worksheet. Sketch math only. Not a product test."""
import json, sys
def gate(d):
review_h = d["assisted_per_week"] * d["minutes_per_diff"] / 60
burn = d["assisted_per_week"] * d["weeks"] * d["tokens_per_diff"]
headroom = (d["stated_free_tokens"] / burn) - 1 if burn else float("inf")
reasons = []
if d["private_or_secret"]:
reasons.append("FAIL custody: private or secret path")
if review_h > d["reviewer_hours"]:
reasons.append(
"FAIL review capacity: %.1fh > %.1fh" % (review_h, d["reviewer_hours"])
)
if headroom < 0.20:
reasons.append("FAIL pool headroom: %.0f%%" % (headroom * 100))
if not d["license_read"]:
reasons.append("FAIL license: unread")
if d["tools_enabled"] and not d["grant_owner"]:
reasons.append("FAIL tool grant: no owner")
return {
"review_hours": round(review_h, 2),
"token_burn": burn,
"headroom": round(headroom, 2),
"free_hosted_ok": not reasons,
"reasons": reasons or ["PASS for this public slice only"],
}
if __name__ == "__main__":
print(json.dumps(gate(json.load(sys.stdin)), indent=2))
cat <<'EOF' | python3 custody_gate.py
{
"assisted_per_week": 40,
"minutes_per_diff": 12,
"weeks": 4,
"tokens_per_diff": 8000,
"stated_free_tokens": 10000000,
"reviewer_hours": 10,
"private_or_secret": false,
"license_read": true,
"tools_enabled": false,
"grant_owner": ""
}
EOF
On that public sketch the worksheet returns review_hours 8.0, token_burn 1280000, headroom about 6.81, and a pass that applies to the public slice only. Flip private_or_secret to true and the same pool fails. If you only run the flattering case, you do not have a decision. You have a wish.
After the free column fails, compare the other two with your quote, not with mine.
paid_month = (burn / 1000000) * U
self_month = ops_hours_per_week * loaded_hourly * weeks
pick paid if counsel accepts vendor terms AND paid_month + switching_cost < self_month
pick self if C == 1 AND a named person owns the pager until expiry
pick neither if review_hours > R
Who should walk away
Skip this if you need a model bake-off. I did not run one. I will not invent quality scores to fill the gap.
Skip it if counsel has not opened the data-processing terms. A table is not a DPA.
Skip it if you want the free server as a permanent production dependency. The brief states an option. It does not state a duration, a machine size, or an SLA. I will not decorate that silence.
Skip it if you are about to point an agent at a third-party system 'just to see.' Early October chatter included writeups about agents and real-company targets. I am not repeating those experiments, and I am not treating a DEV headline as a measured rate. The useful bit is boring. Tool reach is a grant. Unowned grants do not belong in a contribution pilot.
And skip it if you already know review hours are the bottleneck. Tokens will not hide that. Not at 10 million. Not at 10 times that.
Then decide
If you are weighing hosted free capacity against a server you would run yourself, read the current license and the allowance page, then run the worksheet twice. I would rather you close the tab than route a private diff because a pool looked large.
Which variable, if it moved, would reverse your call — custody, review hours, or the allowance you re-read today?
Top comments (0)