Parent epic: #7. Read it for the shared product scope, architecture and operating model.
Objective
Make creation and evolution usable through Devin Cloud with shared repository context, functional validation and the enforced merge boundary.
Environment
Prepare repository setup instructions and, where appropriate, Devin environment configuration so a fresh Cloud session can install dependencies, initialize synthetic data, run the app and execute checks. Keep secrets outside git and local state reproducible.
Guided creation
Exercise the build skill from #2 during #3 with a business request such as:
We need a queue to review onboarding cases, assign responsible reviewers and record approve, reject or escalate decisions.
The workflow clarifies missing requirements, presents a short specification for confirmation and implements using shared conventions. It should not require the requester to supply source paths or an implementation plan.
Routine change
Start a fresh Cloud session using the change skill and request:
Add country as a filter to the pending KYC review queue.
The session should find the approved capability and modify only the presentation configuration. Run the existing schema/functional checks, open a PR and use the eligible merge path from #4. Verify the resulting app filters the persisted cases correctly. This is activation of an existing capability, not creation of a new data-access permission.
Outside-scope change
Use a separate branch/PR for:
Automatically approve cases with a risk score below 20.
A proposed behavior change must leave the pre-authorized surface and require human review. Keep this proposal unmerged: automatic KYC decisions are outside the product scope. The gate identifies departure from the allowed surface, not the legal or business acceptability of the requested rule.
Functional validation
Devin should run the app and verify the affected flow in its browser. Screenshots or a short native recording may help the requester inspect the outcome without running source code. They complement automated tests rather than replacing them.
Acceptance criteria
Final acceptance report and supporting results. No required criteria remain incomplete.
Dependencies
#2, #3 and #4. Guided creation is exercised during #3; fresh-session changes follow the completed gate.
Out of scope
Slack, issue-trigger automations, a custom intake UI, a second functional app and automatic KYC approval.
References
Objective
Make creation and evolution usable through Devin Cloud with shared repository context, functional validation and the enforced merge boundary.
Environment
Prepare repository setup instructions and, where appropriate, Devin environment configuration so a fresh Cloud session can install dependencies, initialize synthetic data, run the app and execute checks. Keep secrets outside git and local state reproducible.
Guided creation
Exercise the build skill from #2 during #3 with a business request such as:
The workflow clarifies missing requirements, presents a short specification for confirmation and implements using shared conventions. It should not require the requester to supply source paths or an implementation plan.
Routine change
Start a fresh Cloud session using the change skill and request:
The session should find the approved capability and modify only the presentation configuration. Run the existing schema/functional checks, open a PR and use the eligible merge path from #4. Verify the resulting app filters the persisted cases correctly. This is activation of an existing capability, not creation of a new data-access permission.
Outside-scope change
Use a separate branch/PR for:
A proposed behavior change must leave the pre-authorized surface and require human review. Keep this proposal unmerged: automatic KYC decisions are outside the product scope. The gate identifies departure from the allowed surface, not the legal or business acceptability of the requested rule.
Functional validation
Devin should run the app and verify the affected flow in its browser. Screenshots or a short native recording may help the requester inspect the outcome without running source code. They complement automated tests rather than replacing them.
Acceptance criteria
Final acceptance report and supporting results. No required criteria remain incomplete.
Dependencies
#2, #3 and #4. Guided creation is exercised during #3; fresh-session changes follow the completed gate.
Out of scope
Slack, issue-trigger automations, a custom intake UI, a second functional app and automatic KYC approval.
References