Skip to main content

Agent Team

Cornerstone is built by 11 specialized Claude Code agents, each with a distinct role. The team uses opus (largest models) for high-judgment decisions, sonnet (mid-tier) for implementation, and haiku (efficient) for mechanical tasks. Spend follows judgment density -- expensive models only on decisions that matter.

AgentModelTierRole
product-ownersonnetmid-tierDefines epics, user stories, and acceptance criteria; manages the backlog
product-architectopuslargeTech stack, schema, API contract, project structure, ADRs, Dockerfile
dev-team-leadopuslargeSpec-writer, reviewer, and committer: decomposes work into implementation specs, reviews agent output, commits and creates PRs
backend-developersonnetmid-tierAPI endpoints, business logic, auth, database operations
frontend-developersonnetmid-tierUI components, pages, interactions, API client
translatorhaikuefficientNon-English translations, glossary enforcement
qa-integration-testersonnetmid-tierUnit tests (95%+ coverage), integration tests, performance testing
e2e-test-engineersonnetmid-tierPlaywright E2E tests, page objects, multi-viewport testing
security-engineersonnetmid-tierSecurity audits, vulnerability reviews, auth/authz validation
ux-designersonnetmid-tierVisual specifications, design tokens, dark mode, accessibility
docs-writerhaikuefficientDocumentation site, README.md, user-facing guides

The Agents​

Product Owner (Sonnet)​

Owns: Backlog management and user stories.

  • Breaks requirements into actionable user stories with clear, testable acceptance criteria
  • Maintains the GitHub Projects board (Backlog, Todo, In Progress, Done)
  • Validates completed work against acceptance criteria
  • Reviews PRs to ensure requirements are met

Product Architect (Opus)​

Owns: System design, schema, API contract, ADRs.

  • Designs database schema changes and Drizzle migrations
  • Defines REST API endpoints and contracts
  • Maintains the GitHub Wiki (Architecture, Schema, API Contract, ADR Index)
  • Reviews PRs for architectural compliance and code quality
  • Makes trade-off decisions on tech stack and major structures

Dev Team Lead (Opus)​

Owns: Specifications, review, and commits.

  • Writes implementation specs from acceptance criteria and architecture
  • Reviews all agent-produced work (code, tests, security findings)
  • Stages files, commits with appropriate agent trailers, pushes, and creates PRs
  • Returns work for fixes if review finds issues; fix loops continue the same implementing agent
  • Final gate before a PR is created

Backend Developer (Sonnet)​

Owns: Server-side implementation.

  • Implements Fastify API endpoints and business logic per spec
  • Writes database queries using Drizzle ORM
  • Handles authentication, authorization, and session management
  • Does NOT write tests (owned by QA)

Frontend Developer (Sonnet)​

Owns: Client-side implementation.

  • Builds React components, pages, and interactions per spec
  • Implements the typed API client layer
  • Uses CSS Modules and design tokens per UX specs
  • Does NOT write tests (owned by QA)

Translator (Haiku)​

Owns: Non-English translations and glossary compliance.

  • Translates new English i18n keys into German and other supported locales
  • Proposes new glossary terms for domain concepts
  • Audits existing translations for parity and term compliance
  • Launched only after frontend-developer adds English keys

QA Integration Tester (Sonnet)​

Owns: Unit and integration tests.

  • Writes Jest unit tests targeting 95%+ coverage on all new code
  • Writes API integration tests using Fastify's app.inject() method
  • Validates performance budgets and accessibility
  • Reports bugs with structured reproduction steps

E2E Test Engineer (Sonnet)​

Owns: End-to-end browser tests.

  • Writes Playwright E2E tests covering user flows and acceptance criteria
  • Manages testcontainers (app, OIDC provider, proxy) for test environments
  • Tests across desktop, tablet, and mobile viewports
  • Confirms all E2E tests pass before UAT proceeds

Security Engineer (Sonnet)​

Owns: Security audits and vulnerability reviews.

  • Reviews PRs touching auth, API routes with data access, Dockerfile, dependency manifests
  • Audits for OWASP Top 10 vulnerabilities (injection, XSS, broken auth, sensitive data exposure, etc.)
  • Scans dependencies for CVEs
  • Maintains the GitHub Wiki Security Audit page

UX Designer (Sonnet)​

Owns: Visual specifications and design system.

  • Creates visual specs for UI stories (token mapping, states, responsive behavior)
  • Maintains the GitHub Wiki Style Guide (tokens, color palette, typography, components)
  • Reviews frontend PRs for token adherence, visual consistency, dark mode, and accessibility

Docs Writer (Haiku)​

Owns: User-facing documentation.

  • Maintains the documentation site (docs/ workspace, Docusaurus)
  • Updates README.md as a project overview
  • Writes feature guides after each epic ships
  • Does NOT write architecture or wiki documentation (product-architect owns that)

Communication Patterns​

Commits: Every commit includes a Co-Authored-By trailer for each agent that contributed:

feat(work-items): add tag filtering to list page

Implements tag-based filtering with multi-select dropdown.

Co-Authored-By: Claude frontend-developer <noreply@anthropic.com>
Co-Authored-By: Claude qa-integration-tester <noreply@anthropic.com>

Note: trailers include agent name only, no model version. Models are selected via aliases (haiku/sonnet/opus) in agent definitions and resolve to the latest model of that tier.

GitHub comments: Agents prefix their comments with agent name in bold brackets:

**[backend-developer]** This endpoint should return a 404 for non-existent items per the contract.

Specifications: The dev-team-lead writes implementation specs that carry the full context: acceptance criteria, reference files to read, and expected output format. Implementing agents execute the spec without re-reading the issue or wiki.

Fix loops: When review finds issues, the fix loop continues the same implementing agent (via SendMessage) instead of launching a fresh agent. This preserves context and speeds iteration.

Attribution Enforcement​

The system enforces agent attribution automatically:

  • A bash hook (scripts/hooks/bash-guard.mjs) pre-checks commit messages at commit time. If production files changed, the required agent trailers must be present.
  • CI runs scripts/check-trailers.sh on every PR touching production code to verify trailers are present.
  • The orchestrator verifies trailers before committing (dev-team-lead [MODE: commit] step) and rejects commits with missing trailers.

This ensures accountability and traceability across the codebase.