Pimp My IDE / garage dispatchBack to dispatches
Agent deployment / account custody / 29 SEP 2026

A live URL is not the handoff.

An agent can wire hosting, data, email, DNS, auth, and payments. The release still needs a title record for who owns each account, what changed, what can be reversed, and what remains manual.

The alpha worth reading

Deployment needs custody, not magic

GoLive is an early-alpha agent skill and command-line tool for deploying an app through the user's own provider accounts. Its current README lists tested routes for hosting, databases, custom-domain DNS, transactional email, test-mode payments, Supabase authentication, and teardown. The project also labels unbuilt and untested routes instead of hiding them behind a broad launch claim.

The useful idea is not one command that owns the whole release. GoLive divides the job into detection, a plan, explicit confirmation, application, verification, drift checks, handoff, and teardown. The plan carries an identity. A changed release, configuration schema, or approved step content invalidates that identity before a write.

The control is still local to the tool. The trust document says an agent can pass the approval flags. It does not record a human signature or second factor. Existing provider logins can also write outside GoLive. A plan gate is useful, but it is not an account-wide policy.

Treat the deployment record like a vehicle title. Keep destination, authority, recovery, and evidence attached when the keys change hands.
01 / DESTINATION

Name the account

Record the provider, organization, project, environment, and public route before any write.

02 / AUTHORITY

Bind the write

Keep the approved plan identity, required confirmation, credential scope, and unresolved spend separate.

03 / RECOVERY

State the inverse

Say whether the change can be re-applied, re-pointed, removed, or only repaired by a person.

04 / EVIDENCE

Read it back

Attach provider state, live behavior, leftovers, and checks that could not run.

Interactive makeover / launch custody binder

Turn the launch key with the title attached

A green Deploy button compresses intent, account access, mutation, and proof into one click. This control separates the release stage from four custody pages. It writes a review packet. It does not log in, approve a plan, deploy, verify, or remove anything.

CHOOSE STAGESELECT PAGESATTACH VALUESRUN AND PROVE

Launch key

The native radio group owns the stage. The checkboxes choose which custody pages the packet requests.

Release stage
Include custody pages
2 of 4 custody pages selectedPlan selected

Draft the title before the transfer.

Destination and authority pages are selected. Recovery and evidence remain open. No approval or provider evidence is attached.

Where the boundary bites

Rollback is not one thing

GoLive's recovery guide separates a production re-point from teardown. A re-point works only for an earlier deployment that the tool recorded. The current guide says Netlify supports that path. Vercel does not expose the needed production read and re-point through this implementation, so the dashboard remains the correction route.

Other changes have different inverses. The tool can re-apply declared DNS records. It cannot restore old database data because it keeps no backup. Teardown removes only resources it can prove it created. Supabase and Neon projects, a Resend sending domain, adopted resources, and unreadable provider state can remain as manual handoffs.

This is why a single ROLLBACK=YES field is weak. Recovery must be recorded per resource. The handoff should say what the tool can reverse, what it can remove, what it can only inspect, and what the next owner must do by hand.

Source log / read 29 SEP 2026

Claims stay with the publisher that made them

Evidence boundary. The repository, trust guide, recovery guide, and validation record come from the same project publisher. They document the design and the publisher's own tests. They are not an independent security audit. This garage installed npm package golive@0.1.0-alpha.7 in a disposable directory, ran version --json and help, confirmed the expected commands, and removed the directory. It did not connect provider accounts, approve a plan, deploy, verify, or test teardown.