Skip to content
All work

Sentinel: code review with approval gates

Claude Code, n8n, Bitbucket, Jira and Discord run first-pass reviews and diagnose failed pipelines. A person approves every fix.

Status
Status: Production
Role
Design and engineering
When
2026
Credit
Built at Silvatron Pty Ltd
Stack
  • Claude
  • n8n
  • Node.js
  • Bitbucket
  • Jira
  • Confluence
  • Discord
  • Cloudflare

Sentinel is a code review and pipeline-diagnosis tool I designed on Claude Code, n8n, Bitbucket, Jira, Confluence and Discord. It reviews pull requests with the full project in view, diagnoses failed pipelines and drafts fixes. Anything that changes code or creates a ticket waits for a person to approve it. My estimate is that it saves the team about 20 to 40 developer hours a month.

The problem

The team works across three stacks at once: Salesforce (Apex and Lightning Web Components), React Native and web. Each has its own review conventions, platform limits and anti-patterns. A reviewer switching between them several times a day loses time and misses things.

Junior developers felt it most. Without fast feedback on platform limits or lifecycle patterns, small mistakes reached integration and were caught late. Senior developers spent their review time on routine issues.

Failed pipelines were the second problem. To diagnose one, an engineer pulled the log, matched it to recent changes and checked known patterns by hand. The context sat in three places: the pipeline log, the pull request diff and the knowledge base.

How it works

n8n is the backbone. A Cloudflare Tunnel gives Bitbucket and Discord stable webhook endpoints into an always-on machine, so code never leaves that host. For each review, n8n checks out the pull request into its own git worktree and runs the Claude Code CLI inside it.

The review loop

Nothing changes code until a person approves it.Select a step to see what it does.

Connections: Pull request opened to Assemble context; Assemble context to Claude Code review; Claude Code review to Comments on the PR; Comments on the PR to Person approves; Person approves to Fix branch and ticket.

When a pipeline fails

  1. 1Catch the failureA Bitbucket pipeline webhook tells n8n which build failed.
  2. 2Gather the evidenceSentinel pulls the log, the recent diff and the matching knowledge-base entries into one context.
  3. 3DiagnoseClaude Code reads it all and proposes a cause and a fix.
  4. 4Ask before actingThe diagnosis goes to Discord. A person approves the fix branch or the Jira ticket, or rejects it.

Each project carries two git submodules that load into every review: a knowledge base of coding standards and architecture decisions, and an org audit holding Salesforce org metadata refreshed from the sandbox. Claude Code reads the project's CLAUDE.md automatically when it starts in the worktree, so the review sees what a senior developer would.

Decisions

n8n instead of a custom scheduler

A custom Python service would have given full control, but I would have had to build persistence, retries, queues, credential storage and monitoring myself. n8n has all of these. Stepping through an execution in its UI is also the quickest way to see why a particular pull request behaved oddly. Sentinel's workflows are mostly linear with branches, which n8n handles well.

The cost is a single point of failure. Moving n8n to a cloud VM is on the list.

The Claude Code CLI instead of raw API calls

Calling the API directly would have meant assembling file contents, managing the context window and writing multi-turn logic myself. The CLI does this already: started inside a worktree, it reads the project instructions and can open any file by path. n8n runs it as a subprocess and parses its JSON output.

javascript
const cmd = `claude -p "${escapedPrompt}" \
  --output-format json \
  --max-turns 50 \
  --cwd "${worktreePath}"`;
A person approves every consequential action

Sentinel can create tickets, generate fix branches and open pull requests. Doing that unattended would fill Jira with noise and push unreviewed code. So every such action waits for one click from a person. That keeps Sentinel an assistant, and every automated action has a matching approval in the thread.

Bash: one worktree per review

A single bare clone of each repository stays on disk. Each review gets its own worktree from it, which takes about a second and lets reviews run in parallel without touching each other's branches.

bash
#!/bin/bash
# Called by n8n for each review
set -euo pipefail

REPO_NAME="${1}"
PR_NUMBER="${2}"
PR_BRANCH="${3}"
BASE_PATH="/repos/${REPO_NAME}"
WORKTREE_PATH="${BASE_PATH}/worktrees/pr-${PR_NUMBER}"

# Bare clone, once per repository
if [ ! -d "${BASE_PATH}/bare" ]; then
  git clone --bare "git@bitbucket.org:<workspace>/${REPO_NAME}.git" "${BASE_PATH}/bare"
fi

git -C "${BASE_PATH}/bare" fetch origin

# Clear a stale worktree from a retried run
if [ -d "${WORKTREE_PATH}" ]; then
  git -C "${BASE_PATH}/bare" worktree remove "${WORKTREE_PATH}" --force 2>/dev/null || true
  rm -rf "${WORKTREE_PATH}"
fi

git -C "${BASE_PATH}/bare" worktree add "${WORKTREE_PATH}" "origin/${PR_BRANCH}"

# Load review standards and org metadata
git -C "${WORKTREE_PATH}" submodule update --init --remote @knowledge-base 2>/dev/null || true
git -C "${WORKTREE_PATH}" submodule update --init --remote @org-audit 2>/dev/null || true

echo "${WORKTREE_PATH}"

Results

Developer time saved a month
20–40 h
Estimate
Source: My estimate, not measured.

This is my estimate of review and triage time saved. It has not been measured.

Status

In production at Silvatron Pty Ltd, across Salesforce and React Native codebases, with pipeline diagnosis and Jira integration running. Per-client settings live in one configuration file, so the same workflows can serve another team's repositories.

Want this on your team's repos?

If pull request review and pipeline triage are eating your week, I can set up a similar assistant against your tools, with a person approving every change.

Book a call (opens in a new tab)

wihithat@gmail.com

  • Status: ProductionVia Silvatron Pty Ltd

    For an Australian state government client

    Document pipeline

    A 12-node LangGraph pipeline extracts compliance documents row by row and links each value to its source page.

    Evidence: 90% F1 on one named benchmark; larger document sets varied

    Stack: LangGraph · Python · Pydantic · FastAPI

  • Status: Prototype

    A Monash team prototype that turns receipts and bank statements into matched, tax-ready records using Mistral OCR and GPT-4o-mini. Demo offline.

    Evidence: Prototype with a tested OCR and matching pipeline; public demo offline

    Stack: React · TypeScript · Supabase · n8n