Consider a library maintainer with a red CI job and a thirty-minute window before a demo. A teammate pasted a .env file, a customer export, and the failing workflow into a remote agent session and asked for a deploy fix.
The diff came back tidy. The session log still held the export two hours later. The patch was not the failure. The unnamed venue was the failure: nobody had decided which bytes could leave the laptop, or which side effects a free remote runner was allowed to attempt.
This draft is a routing procedure for that decision. It classifies a job card into a venue, then names the evidence that venue can honestly produce. It does not score models, and it does not report a benchmark.
Time-sensitive product claims are limited to an operator briefing dated 2026-10-08. Figures that were not in that briefing are omitted rather than estimated.
Disclosure: This article was prepared as part of MonkeyCode's product outreach.
MonkeyCode enters only after the route is chosen. The briefing describes it as an open-source project with free model access, a stated free allowance of 10 million tokens, and a free server option. Those are availability claims, not a hardware spec, a latency number, a named model list, or a promise that the allowance will exist next month. Recheck the project docs on the day you run. Remove every product mention and the router still applies to any remote runner with the same constraints.
Glossary
Seven terms keep the later tree small. Each one is an input or an output of the router, not a slogan.
- Job card. A record with a goal, a data class, a side-effect class, and the exact files the agent may read. No card, no run.
-
Data class. One of
synthetic,public_repo,internal_code, orrestricted. Restricted covers secrets, credentials, customer records, and anything policy forbids leaving the machine. -
Side-effect class. One of
none,local_write,sandbox_write, orexternal_effect. External effect means push, deploy, email, ticket mutation, or a production API call. -
Venue. Where the prompt may be seen and where writes may happen:
local_static,free_remote_sketch,remote_text_local_rerun, orowned_sandbox. A fifth result,refuse, means the card is incomplete. - Allowance. A consumable quota for model calls. The 2026-10-08 briefing states a free allowance of 10 million tokens. It does not state a reset period, a per-model split, or a concurrency cap, so this draft does not invent them.
- Evidence packet. Job card, venue JSON, command log, diff, and test output from a machine you control. A remote string that says done is not a packet.
- Prompt residue. Any secret, customer row, or unreleased path left in a remote session. Residue fails the route even when the diff is correct.
Decision table
Read the table before the narrative tree. The first matching row wins.
| Data class | Side effect | Owned sandbox | Venue | Remote may see files | Remote may act |
|---|---|---|---|---|---|
| restricted, or a sensitive filename | any | any | local_static | no | no |
| synthetic | none or local_write | not required | free_remote_sketch | yes, listed files only | no |
| public_repo or internal_code | not external_effect | not required | remote_text_local_rerun | yes, listed files only | no |
| any non-restricted | external_effect | yes | owned_sandbox | no | no |
| anything else | external_effect | no | refuse | no | no |
Public contribution sprints make the third row common. The repo is already public. The temptation is to let the runner push the branch. The table still says no.
Internal code is not a free pass into that third row. Use it only when your own rules already allow that source to leave the machine. If they do not, mark the card restricted and the same files fall to row one.
The tree, as numbered steps
- If data class is
restricted, or the file list contains env files, key files, or customer exports, stop. Venue islocal_static. - Else if data class is
syntheticand the side effect isnoneorlocal_writeinside a fixture directory, venue isfree_remote_sketch. - Else if data class is
public_repoorinternal_code, and the side effect is notexternal_effect, venue isremote_text_local_rerun. - Else if an external effect is required and the card names a sandbox your team administers, venue is
owned_sandbox. - Else refuse the job. A missing sandbox plus an external effect is not fixed by a longer prompt.
Token balance is not a step. A large remaining allowance does not promote a card into a looser row.
Leaf 1, local static
Card: goal is to explain a login failure. Data class is restricted. Files are .env and customers.csv.
The router returns local_static. Those files do not go to a remote session, free or otherwise. You inventory the tree, scan for known secret shapes, and rewrite the question against a synthetic fixture you are willing to send later.
# Proposed commands. Not executed for this draft.
git status --short
rg -n --hidden -g '!.git' 'AKIA|BEGIN .*PRIVATE KEY|password\s*=' .
python3 venue_route.py --card cards/login_debug.json --assert-venue local_static
Worked packet: route JSON with venue local_static, the scan match count from your machine, and a statement that remote calls were zero. If the scan matches, the original card stays closed until the fixture exists. That is the whole leaf. There is no second step that tries the free server with the real export.
A renamed key file can miss the filename denylist. Treat the scan as part of this leaf, not as an optional extra. The denylist in the sample code is a backstop for obvious names only.
Leaf 2, free remote sketch
Card: goal is to parse fixtures/events.json. Data class is synthetic. Side effect is local_write. Files are limited to the fixture, src/parse_events.py, and tests/test_parse_events.py.
The router returns free_remote_sketch. This is the leaf where free model access and the free server option are in scope. Send the listed files only. Record reported token use if the product surfaces it. Do not fill in a remainder; the briefing did not define how usage is counted.
After the sketch returns, acceptance happens on your machine.
# Proposed. Your machine, not the remote runner.
git apply --check sketch.diff
pytest tests/test_parse_events.py -q
python3 venue_route.py --card cards/parser.json --assert-venue free_remote_sketch
Worked packet shape, with blanks you fill from your own run:
venue=free_remote_sketch
remote_calls=1
local_pytest_exit=
files_changed=
push_attempted=no
A blank local_pytest_exit means the leaf is unfinished. The allowance, stated as 10 million tokens in the briefing, is spent on this kind of fixture. It is not a reason to widen the file list.
Leaf 3, remote text and local rerun
Card: goal is to fix an off-by-one in a public sample's pagination helper. Data class is public_repo. Side effect is local_write. No deploy and no push.
The router returns remote_text_local_rerun. The free server may read the public files and return a diff. It may not push, open a pull request, or call a package registry. A contribution sprint does not move that boundary. The branch move stays on a machine that holds your credentials.
python3 venue_route.py --card cards/pagination.json --assert-venue remote_text_local_rerun
git apply --check pagination.diff
pytest tests/test_pagination.py -q
git diff --stat
Store a form, not a fabricated measurement:
venue=remote_text_local_rerun
remote_calls=1
local_pytest_exit=
files_changed=
push_attempted=no
If the only copy of the test log lives on the free server, you do not have this leaf. You have a transcript. Copy the diff back, rerun, and keep the exit code next to the card.
Leaf 4, owned sandbox
Card: goal is to apply a migration to staging. Data class is internal_code. Side effect is external_effect. The card names a sandbox host the team administers.
The router returns owned_sandbox. A free server is the wrong place to hold a migration credential, even when the token allowance would cover the prompt. Do not attach that runner. If you want a SQL draft, produce it on a machine that already has a schema fixture and does not need the DSN in the prompt. A person runs the SQL on the sandbox, with a transaction opened first and a rollback written down before execution.
python3 venue_route.py --card cards/migration.json --assert-venue owned_sandbox
# Human step on the sandbox you control. Not a free-server step.
psql "$STAGING_DSN" -v ON_ERROR_STOP=1 -c 'BEGIN;' -f migration.sql
Worked packet: route JSON, SQL diff, sandbox host name, and the transaction outcome from that host. A remote transcript is not required. If one exists and it contains the DSN, the route failed. The useful next step is rotation, not a cleaner prompt.
Refuse, the guardrail
Card: goal is to deploy a preview. Side effect is external_effect. owned_sandbox is false.
The router returns refuse. There is no extra venue called try-it-and-watch. Close the card, or name a sandbox you administer. Then the job can re-enter at leaf 4.
Router code
The classifier below is proposal code for this workflow. It was not executed against a live account for this draft. It performs no network call. It only reads a local JSON card.
#!/usr/bin/env python3
"""Classify a job card into a venue. Proposal: no model call."""
import argparse
import json
import sys
RESTRICTED_NAMES = {".env", ".env.local", "id_rsa", "customers.csv", "secrets.json"}
def route(card: dict) -> dict:
files = set(card.get("files") or [])
data = card.get("data_class")
effect = card.get("side_effect")
reasons = []
if data == "restricted" or files & RESTRICTED_NAMES:
reasons.append("restricted payload or sensitive filename")
venue = "local_static"
elif data == "synthetic" and effect in {"none", "local_write"}:
reasons.append("synthetic fixture, no external effect")
venue = "free_remote_sketch"
elif data in {"public_repo", "internal_code"} and effect != "external_effect":
reasons.append("text may leave; effects stay local")
venue = "remote_text_local_rerun"
elif effect == "external_effect" and card.get("owned_sandbox"):
reasons.append("effect required; sandbox is team-owned")
venue = "owned_sandbox"
else:
reasons.append("no safe leaf")
venue = "refuse"
return {
"venue": venue,
"reasons": reasons,
"remote_may_see_files": venue in {
"free_remote_sketch",
"remote_text_local_rerun",
},
"remote_may_effect": False,
}
def main() -> int:
parser = argparse.ArgumentParser()
parser.add_argument("--card", required=True)
parser.add_argument("--assert-venue")
args = parser.parse_args()
with open(args.card, encoding="utf-8") as handle:
decision = route(json.load(handle))
json.dump(decision, sys.stdout, indent=2)
sys.stdout.write("\n")
if args.assert_venue and decision["venue"] != args.assert_venue:
return 2
return 0 if decision["venue"] != "refuse" else 3
if __name__ == "__main__":
raise SystemExit(main())
Leaf-2 card:
{
"goal": "parse fixtures/events.json",
"data_class": "synthetic",
"side_effect": "local_write",
"files": ["fixtures/events.json", "src/parse_events.py"],
"owned_sandbox": false
}
Proposed checks, not run for this draft:
# tests/test_venue_route.py
from venue_route import route
def test_four_leaves_and_refuse():
assert route({"data_class": "restricted", "side_effect": "none", "files": []})["venue"] == "local_static"
assert route({"data_class": "synthetic", "side_effect": "local_write", "files": ["fixtures/events.json"]})["venue"] == "free_remote_sketch"
assert route({"data_class": "public_repo", "side_effect": "local_write", "files": ["src/page.py"]})["venue"] == "remote_text_local_rerun"
assert route({"data_class": "internal_code", "side_effect": "external_effect", "files": ["migration.sql"], "owned_sandbox": True})["venue"] == "owned_sandbox"
assert route({"data_class": "public_repo", "side_effect": "external_effect", "owned_sandbox": False, "files": []})["venue"] == "refuse"
def test_filename_backstop():
card = {"data_class": "synthetic", "side_effect": "none", "files": [".env"]}
assert route(card)["venue"] == "local_static"
assert route(card)["remote_may_effect"] is False
python3 venue_route.py --card cards/parser.json --assert-venue free_remote_sketch
python3 venue_route.py --card cards/login_debug.json --assert-venue local_static
python3 venue_route.py --card cards/pagination.json --assert-venue remote_text_local_rerun
python3 venue_route.py --card cards/migration.json --assert-venue owned_sandbox
python3 venue_route.py --card cards/deploy_preview.json --assert-venue refuse
Exit code 3 on the last command is success for the guardrail. Exit code 2 means the card and the expected venue disagree. That is a bug in the card or in route, not a reason to override the tree by hand.
Runbook
- Write the job card before opening any session. Data class, side-effect class, file list, and sandbox flag are required fields.
- Run the router. Store the JSON in the evidence packet beside the card.
- On
local_staticorrefuse, stop. Build a synthetic fixture or name a sandbox. Do not negotiate the leaf inside the prompt. - On
free_remote_sketchorremote_text_local_rerun, attach only listed files. Free model access and the free server option are sufficient for the sketch, inside the stated token allowance. Do not grant push credentials to that runner. - Apply with
git apply --check, then rerun the narrow test on a machine you control. Store the exit code. - On
owned_sandbox, a person performs the effect inside that sandbox. The free server never receives the credential. Record the sandbox outcome, not the chat summary.
Limits of the method
The router does not measure patch quality. It does not compare products. It does not claim the 10 million token figure is permanent, per-organization, or tied to a named model. The briefing stated the allowance and stopped there.
It also does not claim the free server meets a specific isolation standard. If policy requires a residency region, a retention window, or a subprocessor list, those facts have to come from current project documentation, not from this article.
The filename denylist is short on purpose. Extend it from your own secret inventory, then keep that list in the repo that runs the router. A green local test still says nothing about files the remote runner saw outside the card. If you cannot reconstruct the file list from the session, discard the sketch and start from a new card.
Who should skip it
Skip the remote leaves when a contract forbids source leaving a named network boundary. Skip them when the only failing test needs production rows to reproduce. Skip the tree entirely if you wanted a model leaderboard. It will not produce one.
Teams that already block outbound copy of secrets can still adopt the card. The review gate then receives a venue field and a local exit code, which is a smaller artifact than a full transcript.
If you already have a synthetic leaf-2 card, the free model access and free server option from the 2026-10-08 briefing are enough to draft the first patch, after you recheck the current allowance and server terms. Keep the evidence packet on your machine either way.
Top comments (0)