DEV Community

Morgan Xu
Morgan Xu

Posted on

Seal an Envelope Before Free Bench Time

Free model seats never replace a written handoff. A free server never replaces a named owner. Teams should seal an envelope before the first prompt.

Many teams now generate code faster than they review it. Speed feels like progress until a shared bench mixes secrets. The quiet failure is an unlabeled run with no exit.

Generated code can look finished before anyone owns the result. A portfolio demo and a shared bench fail in different ways. The bench fails when the next person cannot see the stop rule.

Treat free compute like a borrowed bench

This playbook treats free compute like a borrowed lab bench. The bench stays useful only while the log stays attached. That log is a one-page envelope inside the team wiki.

The envelope holds purpose, data class, stop time, and a close stamp. A missing field keeps the bench dark until someone fills it. A filled field still needs a human name beside it.

Keep a named relay

The Desk Editor accepts or refuses the job before any prompt. The Run Witness watches the session and records what changed. The Closer stamps keep, hold, or discard after the diff.

A small team may let one person wear two hats. The same person must not edit, witness, and close one run. Split the close onto a second engineer when headcount is thin.

Work starts only after the editor files the envelope. Work moves when the witness links the diff and the log. Work ends when the closer stamps that same envelope.

Handoffs fail when chat threads become the only record. Chat scrolls away, while a wiki page stays searchable. Paste the envelope under a stable wiki slug before the run.

The one-page run has four beats and no extra ceremony. The beats are file, check, prompt, and stamp, with names attached. If any beat lacks a name, the relay stops and the bench stays dark.

The witness handoff can read: diff linked, data class unchanged, clock intact. The closer handoff can read: tests rerun, secrets absent, stamp is keep. Hold means the diff stays unmerged until a named person returns.

Stop when the data class drifts

The next scene is a composite failure, not a measured incident. A parser spike starts public, then an internal log gets pasted. The free server then holds data the envelope never allowed.

The witness should stop the moment the data class changes. A class change is a new job, not a quiet continuation. The editor must refile the envelope before the next prompt.

Some teams reach this bench through MonkeyCode. Disclosure: This article was prepared as part of MonkeyCode's product outreach. The operator reports free model access and a free server option.

Those two claims are availability notes, not a capacity contract. This article does not name models, quotas, hardware, or duration. Copy any live limit the product shows into the envelope.

If the product shows no number, write unknown and cap locally. A local cap is a team rule, not a vendor promise. Stop the run when the cap or the clock hits first.

Free access can change without a long public notice. A free server can be shared, slow, reset, or withdrawn. The envelope should say what the team will do if access ends.

Pick a throwaway repository for the first sealed run. Keep production secrets and customer data off that repository. Treat the free server like a hallway whiteboard, not a vault.

Data class belongs on the first line a stranger will read. Use public, internal, or forbidden as the only three labels. Forbidden means the editor refuses the job before any prompt.

Purpose should fit in one sentence a stranger can audit. A bare try-the-model line is not a purpose and should fail. A purpose like rewrite the parser and keep tests green can pass.

Stop time is a clock, not a mood. Write an absolute timestamp in UTC plus a maximum minute count. The witness closes the session when either bound is reached.

Local work and free-server work are not the same risk. Use local mode when the sample never leaves the laptop. Use the free server only when the card names that mode.

A shared server adds neighbors, restarts, and unclear retention. The witness should record restart, timeout, and empty response. Those notes belong on the envelope before the closer stamps it.

Paste a gate, not a slogan

The artifact below is an unexecuted example for a wiki page. Adapt names and paths before anyone trusts the checker. It refuses a run when required envelope fields are blank.

The card format is a flat key file, not a full YAML parser. Values may contain spaces, but each key stays on one line. Do not wrap values in quotes, because this parser keeps them.

#!/usr/bin/env python3
'''Unexecuted example: refuse a free-bench run with a blank envelope.'''

import sys
from datetime import datetime, timezone

REQUIRED = [
    'purpose',
    'data_class',
    'vendor',
    'server_mode',
    'owner_editor',
    'owner_witness',
    'owner_closer',
    'stop_at_utc',
    'max_minutes',
    'repo',
    'secret_policy',
    'fallback_if_access_ends',
]

ALLOWED_CLASS = {'public', 'internal', 'forbidden'}
ALLOWED_SERVER = {'local', 'free_server', 'unset'}


def load_flat_card(path):
    data = {}
    with open(path, encoding='utf-8') as handle:
        for raw in handle:
            line = raw.strip()
            if not line or line.startswith('#') or ':' not in line:
                continue
            key, value = line.split(':', 1)
            data[key.strip()] = value.strip()
    return data


def refuse(message):
    print('REFUSE:', message)
    return 1


def main(path):
    card = load_flat_card(path)
    missing = [key for key in REQUIRED if not card.get(key)]
    if missing:
        return refuse('missing ' + ','.join(missing))
    if card['data_class'] not in ALLOWED_CLASS:
        return refuse('data_class must be public, internal, or forbidden')
    if card['data_class'] == 'forbidden':
        return refuse('forbidden data never reaches the bench')
    if card['server_mode'] not in ALLOWED_SERVER:
        return refuse('server_mode must be local, free_server, or unset')
    if card['owner_editor'] == card['owner_closer']:
        return refuse('editor and closer must be different people')
    if card['secret_policy'] != 'no_secrets_in_prompt_or_repo':
        return refuse('secret_policy must block prompts and the repo')
    if len(card['purpose'].split()) < 6:
        return refuse('purpose is too thin to audit')
    try:
        stop = datetime.fromisoformat(card['stop_at_utc'].replace('Z', '+00:00'))
    except ValueError:
        return refuse('stop_at_utc must be ISO-8601')
    if stop.tzinfo is None:
        return refuse('stop_at_utc must include a timezone')
    if stop <= datetime.now(timezone.utc):
        return refuse('stop_at_utc is already past')
    try:
        minutes = int(card['max_minutes'])
    except ValueError:
        return refuse('max_minutes must be an integer')
    if minutes < 10 or minutes > 90:
        return refuse('max_minutes must stay between 10 and 90')
    stamp = card.get('close_stamp', 'open')
    if stamp != 'open':
        return refuse('a new run must start with close_stamp open')
    print('PASS: envelope is complete; a human closer is still required')
    return 0


if __name__ == '__main__':
    if len(sys.argv) != 2:
        print('usage: python3 check_envelope.py envelope.card')
        sys.exit(2)
    sys.exit(main(sys.argv[1]))
Enter fullscreen mode Exit fullscreen mode
purpose: Rewrite the sample parser and keep the tests green
data_class: public
vendor: MonkeyCode
server_mode: free_server
owner_editor: desk.editor
owner_witness: run.witness
owner_closer: close.reviewer
stop_at_utc: 2026-10-10T18:00:00Z
max_minutes: 40
repo: example/throwaway-parser
secret_policy: no_secrets_in_prompt_or_repo
fallback_if_access_ends: stop and finish locally or wait
close_stamp: open
Enter fullscreen mode Exit fullscreen mode
date -u +%Y-%m-%dT%H:%M:%SZ
python3 check_envelope.py envelope.card
cat > blank.card << 'EOF'
# empty on purpose
EOF
python3 check_envelope.py blank.card
echo blank_exit:$?
sed 's/^data_class: .*/data_class: forbidden/' envelope.card > forbidden.card
python3 check_envelope.py forbidden.card
echo forbidden_exit:$?
Enter fullscreen mode Exit fullscreen mode

Save the checker beside the wiki export or inside the repo. Run it in trusted CI before a shared bench job starts. A failing check is a hard stop, not a note for later.

The minute bounds in the checker are team policy, not a product limit. Change 10 and 90 if the team already has a tighter rule. Do not treat those integers as a vendor quota or a promise.

The first test uses a blank card and expects a non-zero exit. The second test uses a full card and a future stop time. That complete card should return a zero exit from the checker.

The third test marks data class forbidden and expects refusal. A past stop time should fail even when the other fields look fine. These checks are the minimum before a shared bench opens.

The sample card uses a fake repo and fake owner names. Replace both before the first real session on a free server. Edit the stop time so it still sits in the future.

Read the checker output as a gate, not as a score. Pass means the envelope is complete, not that the code is safe. A human closer still reads the diff before any merge.

The sample commands stay small so a new teammate can audit them. Python 3 is enough for the field check shown here. No network call belongs inside this local checker.

A checker that phones home can leak the envelope itself. Keep validation on the laptop or in the trusted runner. Do not paste live keys into the card or the script.

Build the stop clock with a UTC command before the edit. Paste that timestamp into stop_at_utc and then add the minute cap. If the date command is missing, take UTC from a trusted clock.

Leave these jobs outside the envelope

Limitations sit next to the benefit, not in a buried footnote. The card cannot detect a prompt that smuggles a secret later. The card cannot prove a free server isolated the workload.

Reviewers can rubber-stamp a close after a long day. Rotate the closer when the same pair ships every shared run. A weekly sample of closed envelopes keeps the habit honest.

Skip this playbook for a solo notebook with no shared server. Skip it when legal counsel already owns the data path. Skip it if a public wiki would leak the card contents.

Also skip it when the task needs a named production runtime. Unknown model identity is acceptable only for a throwaway spike. Production merges need a pinned runtime the team can retest.

The method is slower than pure chat-driven coding on purpose. That slowness matters when several people share one bench. A sealed envelope costs minutes and can prevent a bad merge.

A team with a wiki can trial the reported free path next. Use a throwaway repo and wait for a pass from the checker. Keep that first run inside the stop time written on the card.

Top comments (0)