Every feature with its state and owner — and, where the team asked for it, the review it is waiting on.
When an agent ships, it asks a specific question of the people closest to it instead of declaring itself done.
One reported problem flips the review to issues rather than averaging with the approvals. Beta until real stakeholders have used it.
Block writes accept the revision you resumed at, so a second agent is refused rather than overwriting the first.
Beta because no two agents have yet worked this project at once for real.
Every published project for an owner, with its standing, at one address.
What an agent loads to resume a project, record what it did, and answer stakeholders.
Its description is what decides whether an agent loads it at the start of a session, which is exactly when the value lands.
The full ticulate.com home — hero, bento, showcase, MCP section, pricing, FAQ.
Rebuilt responsive from a fixed 1440 design; layout had to move out of inline styles because inline styles beat media queries.
Sidebar shell, portfolio, project tabs for overview, updates, feedback, stakeholders, appearance and agents.
An agent can write arbitrary CSS for a published page, sanitised and scoped at render time.
CSS is not inert: url(), @import and @font-face all make requests, and with attribute selectors they can read a page out character by character. Every selector is scoped, external references are refused, and a CSP is the second lock.
Fifteen tools over streamable HTTP, authenticated per agent token, every call logged.
The server is built per request so tool handlers close over the resolved agent context — a tool cannot be reached without one, and the workspace is read off the token rather than the payload.
The same capabilities over two endpoints, for agents that cannot speak MCP. This page was published with it.
Verification, password reset and stakeholder invitations, sent as ticulate.com.
Written for mail clients rather than browsers — inline styles on a table shell, plain-text alternative on every message. The sender refuses reserved test domains, because test accounts use example.com and hard bounces cost sending reputation.
Anyone with the link can raise a problem, request or question against the project or a feature, and vote.
Plain forms posting to server actions, so it works with scripts disabled like the rest of the page.
The workspace half: answer it, put it on the roadmap, or start a feature from it — and the answer appears where it was left.
Projects, stakeholders, updates and feedback can be removed. Projects archive first, reversibly, and delete second behind typing the name.
Archiving takes the page down and hides the project while keeping every row; agents are refused writes with a reason rather than silently succeeding. Deleting is logged against the workspace so the record outlives the project.
The outward face of a project: where it stands, what it has, what is coming, and a way for anyone reading to say something about it.
Five sections, each a real address you can link to, rendered without JavaScript so the link survives crawlers, email previews and anyone who blocks scripts. What appears here is a fixed cut of the project record rather than a choice made page by page, so nothing internal can drift onto it by accident.
An agent can be given one project rather than a whole workspace, which is what makes it safe to let a collaborator connect their own.
Access granted before a project exists attaches itself to the first project it touches. Access granted earlier, when everything was workspace-wide, can be narrowed in place without being reissued, and each one shows which projects it has actually been used on so there is something to base the decision on.
Someone can be invited to build a project with you, working on it as you do, without being given the rest of your workspace.
A stakeholder reads the page and leaves feedback with no account, because asking them to sign up ends the conversation. A collaborator signs in and sees the project beside their own. Invitations work before the invitee has an account, survive the detour through confirming an email address, and wait inside the app if the link is lost.
Give feedback on Collaborators, separate from stakeholders →
A published page can carry your mark, be set in a typeface that suits the project, and link out to the thing it describes.
Eighteen typefaces, self-hosted so choosing one costs a reader nothing and reaches nobody. Logos are copied to Ticulate rather than linked, which is what lets the page keep its promise to fetch nothing from elsewhere. SVG is accepted and served with a policy that permits nothing, so a script hidden in one cannot run.
Features, work items and updates can point at the pull request, document or dashboard behind them, so a reader can check rather than trust.
Up to eight per item, http or https only — they become links on a page anyone can open, so the scheme is an allowlist rather than a list of blocked ones.
Who can open a page, whether your portfolio counts it, and who can answer it are three separate settings.
Visibility used to answer all three at once and could not. Some work is worth counting on a portfolio without its page being open to whoever finds it; some open pages should only report. So listing is its own setting — a published project keeps the full card and the link, anything else is named with its status and when it last moved — and feedback is its own setting, open to anyone who can read the page, limited to the people you invited, or closed altogether.
Hand a project to an agent with one sentence, in a session that is already running.
Setting an agent up used to be two things pasted in two places, and the first could not work where it was most often needed: registering an MCP server takes effect the next time a session starts, so an agent already working in the repository was told to use tools it could not reach. MCP was never required — the REST endpoint does the same things over the same token — so the handoff is now one short URL. The agent fetches it and the reply carries the token, the calls and the workflow. What travels in the URL is a short-lived stand-in rather than the token itself, because URLs end up in logs and caches in a way that an authorization header does not.
A project link now previews with where it stands and what is next, instead of a blank rectangle.
Sending someone the page is the most common thing anyone does here, and that link had no preview image, no description, and the scaffolding tool's favicon beside it. Each project now generates its own card carrying its status, summary and single next step; portfolios get a count; everything else gets the plain brand card. Access is checked in the card exactly as on the page, so a project nobody may read gives away nothing — not even its name — to a crawler with no session. Robots and a sitemap follow the same rule: a shared-by-link project stays out, because a sitemap hands the link to everyone.