Start a project →

How we build · free brief builder below

Project Factory: from idea to audited build

Every SlickLab project follows the same 12 phases. Research comes before the stack is chosen, the architecture comes before any AI agent, and nothing is called finished until an audit run by code says so.

The rules

Three rules we do not skip

1

Research first

We look at the problem, the market, what already exists and what is open source before committing to a stack. A project is allowed to stop here.

2

Architecture before agents

Identity, permissions, calculations, state changes and anything involving money are ordinary code. AI is added only where reasoning helps.

3

Two packages, not one

You get a complete private baseline. A separate public package shows what the product does without giving away how it works.

The lifecycle

Twelve phases, each with something to show for it

Coding starts at phase six. By then the problem, the scope, the boundaries and the architecture are written down and agreed.

  1. The problem, who has it, what it is worth, the business model, and what the project will not do.

  2. The market, comparable products, open-source options and integrations, each claim with a source.

  3. Users, workflows, the first version, later phases, pricing, and how success is measured.

  4. Which service owns which data, the interfaces, permissions, deployment, monitoring and rollback.

  5. Every artifact is marked public, internal, confidential or secret before more is written.

  6. The core workflows you can click through, on a phone, including empty and error states.

  7. AI agents only where reasoning helps. Each gets a written job, tools, limits and tests.

  8. Contracts, policies, evaluations and runbooks that match real permissions and real tests.

  9. Feature, security, permission, failure-path and leak checks, run by code and reported with evidence.

  10. A version, a hash of every file, the audit report, and a package you can roll back to.

  11. What it does, a safe demo, ownership and licensing. The methods stay private.

  12. Real services and integrations, a staged rollout, telemetry, and automation that stays supervised.

Authority first, intelligence second

What code decides and what AI is allowed to do

An agent can read, interpret and draft. It cannot approve, charge, book or change a record on its own. The code checks its output and has the last word.

Always ordinary codeWhere an AI agent can help
Sign-in and permissionsResearching a question
Calculations and pricesReading free text and pulling out the facts
Changes of state, such as a booking or an orderSummarising and explaining
Payments and refundsPlanning and suggesting alternatives
Secrets and the audit recordLooking into exceptions for a person to decide

The audit gate

Ten checks run by code, not ticked by hand

A checklist anyone can tick proves nothing. Each check below runs against the real project folder and reports the evidence it used. Questions that need judgment are flagged for a person and are never passed automatically.

  1. Secrets scan. No keys, tokens or passwords anywhere in the project.
  2. Credential files. No .env, key or certificate file is included.
  3. Non-goals written. The brief says what the project will not do.
  4. Research sourced. The research has real links, not placeholders.
  5. Contracts present. Tool and event contracts exist and are filled in.
  6. Agent definitions complete. Every agent lists its allowed and forbidden tools.
  7. Agent tools contracted. Every tool an agent may use has a written contract.
  8. Tool contracts complete. Each contract states inputs, outputs, permissions, side effects and failure modes.
  9. Evaluation coverage. Six kinds of test exist: normal, edge, failure, adversarial, privacy and authority.
  10. Rollback runbook. There are written steps to undo a release.

A worked example: our Inbound Lead Conversion system went through this gate. It passes all ten checks, and its baseline is frozen with a hash of every file.

Public and private

Show what it does. Keep how it works.

The public package is built from an allow list, then scanned again for secrets and private material before it leaves.

ArtifactPrivate baselinePublic package
Capabilities and outcomesYesYes
A safe demo on sample dataYesYes
High-level architectureYesYes
Licensing and how to buyYesYes
Agent instructions and promptsYesNo
Scoring rules and internal workflowsYesNo
Credentials, infrastructure and client dataSecret store onlyNo

Free tool · no email

Draft your project brief

Fill in what you know. You get a one-page brief and the questions still open before anyone should write code. It is built in this browser and nothing is sent.

Your brief

Fill in the form, then choose “Build my brief”.

Work with us

Want your project run this way?

Bring the brief, or just the idea. We will tell you plainly whether it is worth building, and what the first version should be.

Ask the agentOnline now