# Gift Graph Build Log > Where Agent planned well, where it guessed, and where it needed steering. One entry per session, oldest first, mirrored from `docs/build-log.md` in the repo. Untagged entries are mine; entries tagged Agent were written by Replit Agent. Each session closes with Product notes · FDE feedback, the note I would hand to Replit's product team, in three parts: where, what happened, what would help. > Last Updated: 2026-10-01 · The Replit side of this story is told in [[Replit Case Study]]. **2026-09-30 · Import** ![[gift-graph-replit-01-import.png]] *Agent reads the zip, finds no code, and asks before touching anything · the plan gate holding on the first turn* **Asked:** Imported the zip with the brief and spec. It held no code yet. **Agent did:** Read the README and replit.md, saw no application code, and stopped to ask what I wanted before changing anything. Offered build, change, or leave as imported. **Read me right:** Honored the plan-before-build rule on the first turn. Named the project correctly from the README. **Steered:** Updated replit.md with the build log format and installed my voice rules as a project skill before approving any work. ![[gift-graph-replit-02-voice-skill.png]] *The voice skill written into `.agents/skills/aleks-voice/SKILL.md` from the Shell, the stray zip removed* **Product notes · FDE feedback** - **Where:** The import task for a zip holding only docs. - **What happened:** Agent framed the zip as possibly a library, a fork, or an app, which is the right uncertainty for a docs-only upload. The app kept the zip name, gift-graph.zip, as its title. - **What would help:** Suggest a clean app name from the README heading when the import holds a README. **2026-09-30 · First impressions** **Noticed:** I am really liking the tab navigation. It is easy to add context, invoke tools and skills, open a console, and reach just about anything else I might want to do. The processing states are very clean, and the notification prompt is well integrated with the operating system I am working on, which makes it easy to step away while Agent works. I am absolutely loving the ability to drag tabs down and work with them side by side in the app. I am enjoying the opinionated take on the thinking animation, the three dots that spiral in the Replit logo. There is a lot here I am excited to discover. **Approach:** I worked from first principles. I wrote the brief and scope before the first prompt, held the plan for approval before any code, and installed my voice rules as a project skill. ![[gift-graph-replit-06-action-icons.png|300]] *The row of action icons under a step · no tooltips* **Product notes · FDE feedback** - **Where:** The rows of action icons in the Agent panel, such as the row marked 35 actions. - **What happened:** An icon shows nothing on hover, and a single row can hold many icons. - **What would help:** A tooltip on each icon naming the action it represents, such as a file read, a shell command, or an edit. **2026-09-30 · Plan** ![[gift-graph-replit-03-plan.png]] *The six-step plan beside the voice skill · approve or revise* **Asked:** Build and run the initial version, plan first. **Agent did:** Proposed six steps covering a TypeScript server on the MCP SDK, Replit PostgreSQL, seeded credentials, the consent handshake, drop and pull tools, and privacy tests. Deferred everything the backlog lists. **Read me right:** Kept scope exactly. Chose explicit owner-written category and vibe text over model summaries, which closes a privacy leak the spec did not name. **Steered:** Added Secrets for credentials, decision records, and named test cases before building. **Product notes · FDE feedback** - **Where:** The revise option on the plan approval card. - **What happened:** Revise opens a blank text field. The chat composer has a mic and a Plan toggle, and the approval card has neither. - **What would help:** Suggested revisions drawn from the plan, with freeform text still available, and a mic in the card. Dictation works at the operating-system level, and having it in the card keeps the review inside Replit. **2026-09-30 · Agent · Build v0.1** **Changed:** Built and started the TypeScript MCP server with PostgreSQL storage, per-user bearer authentication from Replit Secrets, directional consent controls, and tier-limited drop and pull tools. Recorded the architecture decisions and client setup; all 12 integration tests passed, including identity isolation, silent drops, immediate revocation, and pulls before approval, alongside type checking, compilation, the health check, and preview verification. **Unsure:** The spec leaves prompt matching and the effect of default-tier changes open. v0.1 matches literal terms against disclosed text and snapshots the default when a drop is created; renewed approval restores access to existing drops, while semantic matching, batching, and per-drop editing remain deferred. **2026-09-30 · Build** ![[gift-graph-replit-04-revise-card.png]] *Revise selected, text opening with "Approved" · Agent read the text* **Asked:** Revise the plan with three additions covering Secrets for credentials, decision records, and named privacy tests. **Agent did:** Read my text as approval and built v0.1 without showing a revised plan. It collected both bearer tokens through a Secrets form, handed test writing to a subagent, and finished in about five minutes with 12 passing integration tests, a health check, and a client setup guide. ![[gift-graph-replit-05-secrets-form.png]] *The Secrets form for the first token, the spec and this log open beside it* **Read me right:** All three additions landed. It asked for the tokens through a secure form and told me to keep them out of chat. **Steered:** I did not steer during the build. I rotated both tokens afterward because a screenshot exposed them. ![[gift-graph-replit-07-build-complete.png]] *v0.1 running after five minutes · 12 tests, /health ok, the publish panel waiting* **Product notes · FDE feedback** - **Where:** The plan approval card. - **What happened:** I selected Revise, and my text opened with "Approved with three additions." Agent read the text as approval and built without showing a revised plan. - **What would help:** Restate how Agent read the card before building whenever the selected option and the text disagree. That keeps the plan gate firm. **2026-09-30 · Security review** ![[gift-graph-replit-08-security-center.png]] *The Security and Privacy Center · no issues, four Auto-Protect layers, no code sent to the scanners* **Noticed:** The security review is very compelling from an enterprise perspective. Replit Auto-Protect turns on firewalls, SSL and TLS encryption, and automatic dependency patching, which feels like it marries well to compliance. The first scan found no issues, and the panel states that no code is sent to Semgrep, Socket, or HoundDog.ai, the scanners behind it. I see this coming up as a requirement from many of the enterprise customers I work with today, where integration and use-case scoping run into security review early. **Product notes · FDE feedback** - **Where:** The Security and Privacy Center. - **What happened:** Scan results, Auto-Protect, and the scanners' data handling each sit in their own panel. - **What would help:** An exportable security summary that pulls all three into one document a builder can hand to a customer's security review. **2026-09-30 · Publish attempt** ![[gift-graph-replit-09-run-command.png]] *"Could not find run command" · the preview ran on the dev workflow, and publishing wanted its own* **Asked:** Publish v0.1 to gift-graph.replit.app with public access, protected by the bearer tokens. **Decided:** Turned the feedback widget off for v0.1, since the server has no pages for a person to use. **Noticed:** I am very excited by the prospect of the widget for feedback capture. Feedback capture, data, and sentiment analysis are areas of activation I have worked in deeply as a partner to product teams. **Product notes · FDE feedback** - **Where:** The publish flow, after a build where the preview ran. - **What happened:** Publish failed with "Could not find run command." The preview used the dev workflow, and no deployment run command had been set. - **What would help:** Have Agent set the deployment commands whenever it builds a server, or offer to set them from the error. **Product notes · FDE feedback** - **Where:** The publish panel. - **What happened:** The panel offers the feedback widget beside the access settings for every app, including a server with no human-facing pages. - **What would help:** Detect apps with no human-facing pages and explain when the widget applies. **2026-10-01 · Agent · Deployment config** **Changed:** Configured Autoscale with `npm run build` and `npm start`, and recorded the stateless transport reason in technical decisions. The compiled server started locally; `/health` returned HTTP 200 with `{"status":"ok"}`, the root returned HTTP 200, and an unauthenticated MCP request returned HTTP 401. **Unsure:** Replit reports no active deployment and cannot return build history yet. Required production secrets exist, but published startup and the live health check remain pending the owner's Publish action. **2026-10-01 · Deploy** ![[gift-graph-replit-10-plan-mode-task.png]] *Plan mode turns the fix into a task card · build here, in the background, revise, or cancel* **Asked:** Fix production publishing, with Plan mode on. **Agent did:** Found that .replit had no deployment section, which explained the missing run command. It confirmed the server creates a fresh transport per request with session IDs disabled, chose Autoscale for that stateless design, and wrapped the fix in a task card I could build here, build in the background, revise, or cancel. **Read me right:** Checked whether the server holds session state before choosing a deployment type, and recorded the reason. **Steered:** Agent asked to use Power mode for the fix, and I accepted. ![[gift-graph-replit-11-publish-progress.png]] *The publish progress bar · North America, Autoscale, 2 vCPU and 4 GiB* ![[gift-graph-replit-12-promote-logs.png]] *Promote, the last stage · the security stage explains itself on hover, the others say "success"* **Noticed:** I love the publish progress bar, which shows each stage as it runs with the logs one click away. Plan mode turned the fix into a reviewable task card, and the "Free · No credits used" badge on earlier steps makes cost visible at every turn. The infrastructure panel lists the region as North America and the scaling as Autoscale with 2 vCPU and 4 GiB RAM. **Verified:** The live health check at gift-graph.replit.app/health returns `{"status":"ok"}`, and /mcp refuses a request without a token. ![[gift-graph-replit-13-live.png]] *Live · Replit offers a slide deck and an animation from the publish screen* **Product notes · FDE feedback** - **Where:** The stages of the publish progress bar. - **What happened:** On hover, the security stage explains what it checks and where to go deeper. Every other stage shows only "success." - **What would help:** Give every stage the same treatment, naming the stage, what it did, and how long it took. **2026-10-01 · Slide deck** ![[gift-graph-replit-14-deck-card.png|420]] *Seven slides proposed in one sentence · the deployment called pending a minute after it went live* **Asked:** Pressed Create a slide deck from the publish screen, and Replit asked me to confirm the scope before building. **Agent did:** Proposed a seven-slide deck in one sentence and described the deployment as pending a minute after it went live. **Steered:** Cut it to five slides for an engineer reviewing the build, drawn only from the spec, technical decisions, and build log. I asked for a slide-by-slide outline before building, the deployment presented as complete, my voice skill on every slide, and no names of real people. ![[gift-graph-replit-16-restructure-card.png]] *After the outline was approved, Agent asked to move the live server into a multi-artifact layout before it could add the deck* **Product notes · FDE feedback** - **Where:** The confirmation card before Agent builds a slide deck. - **What happened:** Agent named the deck's topics without showing what each slide would hold. Its summary also described the deployment as pending a minute after it went live. - **What would help:** For a deck, outline each slide with a title and a few bullets before building, and refresh project status before summarizing it. **Product notes · FDE feedback** - **Where:** Create a slide deck, offered from the publish screen of a live app. - **What happened:** After I approved the outline, Agent reported the deck needs a multi-artifact layout and asked to move the deployed server into it first. - **What would help:** Flag the structure change at the moment the feature is offered, before scoping the deck, and offer to build the deck as a separate project that leaves the live app untouched. **2026-10-01 · GitHub** ![[gift-graph-replit-20-git-shell.png]] *Replit had been committing every checkpoint · the ignore lines, the log, and a clean tree* ![[gift-graph-replit-21-create-repo.png|520]] *The create repository dialog · Personal or Organization, Private or Public, selected states hard to read* **Asked:** Connected GitHub and created a private repository, gift-graph, from the Git pane. **Verified:** The repo shows the private badge and 13 commits. `.cache` and `.local` were never tracked. GitHub suggested a Datadog Synthetics workflow for the repo, which means my old product found me. ![[gift-graph-replit-22-github-repo.png]] *gift-graph on GitHub, private, 13 commits, the multi-artifact layout already in main* **Product notes · FDE feedback** - **Where:** The create repository dialog in the Git pane. - **What happened:** The selected options in the paired controls, Personal or Organization and Private or Public, were hard to tell apart from the unselected ones. - **What would help:** A stronger selected state, such as a filled background or a check mark, especially on Privacy, since choosing Public by mistake exposes the code. **2026-10-01 · Demo** ![[gift-graph-replit-17-mcp-list.png|700]] *Both identities connected from PowerShell* ![[gift-graph-replit-19-tools.png|640]] *Seven tools under gift-graph-aleks · request, list, approve, set tier, revoke, and below the fold, drop and pull* **Asked:** Drove the live server from Claude Code as both users, with gift-graph-aleks and gift-graph-justin connected through their bearer tokens. ![[gift-graph-replit-24-demo-drop.png]] *Request, approve, drop · the server refuses vibe text on a category drop* ![[gift-graph-replit-25-demo-privacy.png]] *Pull, fish, revoke · the category text surfaces, the verbatim text never does, and revocation cuts access at once* **Verified:** - I requested a connection as the requester, and my partner's agent approved it with category as the default tier. - My partner's agent dropped "wants a license for Söhne" with the category text "type and lettering." - A pull for "type and lettering" returned only the category text. - A pull for "Söhne" returned nothing, which means a requester cannot fish for private text by guessing words. - After the revoke, the same pull returned nothing. **Noticed:** The server rejected vibe text on a category drop, which keeps unused private text out of storage. Drops are scoped to a single requester, a stricter reading of the spec than I wrote. A pull for "gift ideas about fonts" returned nothing, since v0.1 matches literal words against disclosed text only. Holding both identities in one session let Claude repeat the private text from its own context, though the server never sent it to the requester. **Next steps:** Semantic matching built only from disclosed text, and a decision on whether a drop belongs to one connection or to the owner.