Built with Claude, reviewed by an expert

The model did the typing; the gates, tests and review kept it honest.

StockScore and Wattlas ship through the same operating model. Claude writes the tickets, the mockups, the code and the tests. A human makes two decisions, the plan and the release, and no other step waits on one. Everything moves in small vertical slices, each one gated, each one readable in a diff.

2
human gates: the plan & the release
0
JSON keys in CI
2,921
tests · 2,568 Python, 353 JS
2
products shipped this way
Operating model

From intent to production

Work enters where teams would raise it and leaves as a promoted release. Claude Cowork structures the ticket while Claude Design supplies the mockups, in parallel. Two of the five steps need a human.

1 · INTAKE
Jira & Notion

Where work is raised: an idea, a bug, a request.

2 · IN PARALLEL
Cowork ∥ Design

Claude Cowork turns the idea into a clean ticket; Claude Design supplies mockups, tokens and specs.

3 · ISSUE
GitHub issue

Links the ticket and the design together, the contract for the coding session.

4 · CLAUDE CODE ⚑
One issue, one worktree

One branch per issue; parallel sessions can't collide. You approve the plan.

5 · RELEASE ⚑
develop → staging → main

Promoted through protected branches. You approve the release.

Configuration

Configured for Claude Code

A CLAUDE.md file and project settings define how every coding session behaves. The rules live in the repo, not in anyone's head.

CLAUDE.mdrepo root

Loaded every session: the project's standing instructions.

Branch modelWORKFLOW.md

issue-N → develop → staging → main; a hook refuses direct commits to main.

Worktree isolationgit worktrees

One issue, one worktree, so parallel sessions can't collide.

Six-block promptissue contract

context · task · refs · constraints · success · halt.

Autonomy + haltCLAUDE.md

Self-execute by default; escalate on risk.

Testing gatesettings.json

Failing-first tests · pre-commit hooks · detect-secrets.

De-risking

Challenged before any code

A second model attacks every significant approach, twice, before anything is built. A human then makes the call.

01
Propose

The approach takes shape in the Claude Project.

02
Challenge

A second model attacks it, for two rounds.

03 ⚑
Decide

A human weighs the trade-offs and makes the call.

04
Crystallize

The decision becomes a brief; the brief becomes the build.

CI/CD × 2

Two pipelines, one standard

A cloud product and a static site need different pipelines. What they share: nothing secret sits in either one.

StockScore: no keys in the pipeline
PR checks → Gemini-call guard → deploy → Cloud Run

Cloud Run serves the front end and the API, Cloud SQL sits behind a VPC, and every secret lives in Secret Manager. The pipeline authenticates through Workload Identity Federation, so there is no JSON key to leak. Every deploy passes the PR checks and a guard on Gemini calls first; in production Gemini runs Flash before Pro, bounded.

Wattlas: a cron, a commit, a redeploy
open APIs → pipeline → data/*.json → redeploy

A scheduled job reruns the Python pipeline on the 1st and 15th at 05:17 UTC and commits only what changed; the static site redeploys. The heavy MaStR bulk download runs weekly, isolated and non-fatal. The whole "backend" is a scheduled job that writes files.