How I Built a Deploy Gate So My Autonomous Coding Agent Can Ship to Prod Safely A developer built a three-stage deploy gate that lets a fully autonomous Claude Code-based coding agent merge and ship its own pull requests safely, after an early incident where a currency-blind cache took down a checkout endpoint for 11 minutes. The gate combines a pre-flight contract requiring blast radius and canary metrics, a 5% canary with hard metric thresholds, and an automatic rollback the agent cannot override, and has since shipped 340+ production deploys with zero human-paged incidents. I let a fully autonomous coding agent built on Claude Code merge and ship its own pull requests. The first time it took down a checkout endpoint for 11 minutes, I built a three-stage deploy gate : a pre-flight contract, a canary with hard metric thresholds, and an automatic rollback the agent cannot override. Six months later it has shipped 340+ production deploys with zero human-paged incidents . Here's the design, the code that matters, and five lessons about what an agent should never be allowed to touch. 🚀 My fully autonomous implementation system does the whole loop: it picks up a task, plans, implements, runs tests, opens a PR, and if the verifier sub-agent approves, merges. That part has been solid for a while. The part that wasn't solid was what happens after merge . For the first few weeks, "deploy" meant the same thing it meant for humans on the team: CI goes green, the pipeline pushes the container, done. That workflow was designed around an unspoken assumption: a human just read the diff and has a mental model of what might break. An agent doesn't carry that model into the deploy. It carries a green checkmark. The agent was asked to "reduce p95 latency on the cart summary endpoint." It did. It added a cache in front of a pricing lookup. Tests passed, because the tests mocked the pricing service. The verifier approved, because the diff was small and the benchmark improved. In production, the cache key didn't include the currency. Customers in the EU saw USD prices for 11 minutes until an alert fired and a teammate rolled back by hand. Nobody did anything wrong by the rules we had. The rules were the problem. So I wrote new ones, and I wrote them as code. The gate has three stages. Each one can stop the deploy, and the agent can't skip or edit any of them. That last part is the whole design, so I'll come back to it in the lessons. php flowchart LR A PR merged by agent -- B{Stage 1