toolkit

Workstreams · real client evidence

One request becomes a review-ready job.

An employee asks for an outcome in OpenCode. Toolkit selects the standard workstream, runs every safe check locally, packages the report, and stops before a qualified person must review or record the result.

Audit this client website. Run the full checklist and package the report.

Available now · v1.0.0

Full client website audit

Run the approved end-to-end website audit and package one standard, evidence-backed client deliverable.

macOSLinuxWindowsOpenCoderead-onlyreport-ready
awaiting peer review38verified evidence references

2 real client runs · 58 locally recorded events

Open the sanitized receipt JSON →

2 clients. The same company standard.

These are sanitized recordings of OpenCode sessions against client domains explicitly selected for this internal proof—not a scripted fixture and not a forced green demo.

Rau Plastic Surgery

rauplasticsurgery.com

report ready
OpenCode running the full client website audit for rauplasticsurgery.com
8 automated steps18 evidence6m 59s elapsed

Real read-only OpenCode run against rauplasticsurgery.com. No client configuration or content was changed; the audit made normal web requests that may appear in analytics. The run stopped before peer review, approval, ticket updates, or Activity Logs write-back.

Captured Sep 5, 2026 · OpenCode · work item DEMO-RAU-RECAPTURE-004

Integrity check: 18/18 file references matched their recorded SHA-256 digests.

Sherber & Rad

sherberandrad.com

report ready
OpenCode running the full client website audit for sherberandrad.com
9 automated steps20 evidence14m 30s elapsed

Real read-only OpenCode run against sherberandrad.com. No client configuration or content was changed; the audit made normal web requests that may appear in analytics. The run stopped before peer review, approval, ticket updates, or Activity Logs write-back.

Captured Sep 5, 2026 · OpenCode · work item DEMO-SHERBER-002

Integrity check: 20/20 file references matched their recorded SHA-256 digests.

What the runs actually found

A failed check is useful evidence. Toolkit preserves it, packages it, and routes it for review.

FAIL

Rau Plastic Surgery

162 URLs discovered · 6 quality lanes · 3 browser-QA pages.

  • Local browser: desktop PASS · iphone-17 PASS
  • PageSpeed: mobile 36 · desktop 56
  • Analytics: REVIEW · published GTM: NOT_APPLICABLE
  • 6 normalized records · JSON, HTML, PDF
FAIL

Sherber & Rad

707 URLs discovered · 8 quality lanes · 3 browser-QA pages.

  • Local browser: desktop PASS · iphone-17 FAIL
  • PageSpeed: mobile 44 · desktop 60
  • Analytics: REVIEW · published GTM: REVIEW
  • 7 normalized records · JSON, HTML, PDF

The standard lifecycle

Both sessions followed this same version-pinned definition. The first nine steps resolved through automation or an explicit non-applicable reason; the final two remained human-controlled.

  1. 01Confirm scope, client, and work recorddone3 evidence
  2. 02Discover the website and select representative pagesdone2 evidence
  3. 03Run the full site quality and technical checklistdone2 evidence
  4. 04Measure local browser performancedone2 evidence
  5. 05Measure PageSpeed and real-user performancedone2 evidence
  6. 06Inspect Cloudflare and edge configurationdone2 evidence
  7. 07Audit analytics and tag coveragedone2 evidence
  8. 08Audit published Google Tag Manager behaviornot applicable — the analytics audit found no Google Tag Manager container, no GTM tag, and no dataLayer across 162 discovered pagesskippedreason recorded
  9. 09Check the AI-crawler discovery filenot captured — this required coverage step was added after the recorded read-only sessionskippedreason recorded
  10. 10Generate the standard client audit reportdone3 evidence
  11. 11Qualified peer reviews coverage, findings, and deliverablesreadyhuman gate
  12. 12Write completion and evidence links to the system of recordpendingafter review

Where automation stops

automated locally

  • Discovery, QA, PageSpeed, analytics, GTM, and edge checks
  • Evidence hashing and standard reports
  • Resume after interruption

qualified peer

  • Coverage and findings review
  • Deliverable approval
  • Ticket or Activity Logs write-back

human locked

  • DNS and cutovers
  • Publishing and external sends
  • Destructive changes

Start with the safe plan

The friendly Toolkit command performs no checks and makes no changes. Starting a run also requires a named employee and an originating ticket or Activity Logs fallback.

./toolkit run "Full client website audit" --url https://sherberandrad.com/

Windows uses .\toolkit.ps1 with the same friendly name and arguments.

Install Toolkit → · Find a recorded session →