Design-system verification for agent-built UI

Your coding agent is quietly changing your interface.

Ledgermachine checks what shipped against the design rules you approved, explains every mismatch with inspectable evidence, and remembers intentional exceptions for the next agent pass.

Enable JavaScript to scan a public website, local folder, or ZIP. Local source never leaves this browser.

One prompt at a time

Nobody decided to have 31 grays.

An agent needed a border color and wrote one that looked close enough. Then it happened again. Nobody can see a two-percent difference is invisible in review, right up until near-duplicates become the interface.

The working loop

Review. Share. Check again.

Ledgermachine stays read-only. Your editor or coding agent makes the change; the next scan checks the result.

Review what changed

Ledgermachine isolates the visual choices that need you. Decide one at a time with source evidence available when you want it.

Findings → Review

Share the rules

Copy approved decisions into the instruction file used by your coding agent.

Rules → Coding agent

Check the next edit

Scan again after the next coding session to confirm the rules held and catch anything new.

Next edit → Changes
CSSSCSSHTMLJSX / TSXVueSvelteAstroTailwindDTCG JSON

The verification loop

Your decisions become the next agent's rules.

Review once, share the rules, then check the next edit.

  1. Review findings
  2. Share rules
  3. Agent edits source
  4. Check changes
AGENTS.mdDESIGN.mdCLI
AGENTS.md
# Ledgermachine system rules

## Tokens
- Use var(--ink) for primary text.
- Use var(--surface-2) for secondary fields.
- Keep spacing on the declared --space-* scale.
- Keep controls on --radius-control.

## Components
- Reuse the shared Button implementation.
- Preserve the accepted compact-card exception.
- Do not introduce new near-black values.

## Verification
- New drift: 0
- Minimum coverage: 92%
- Rescan after every agent pass.

Questions before source access

The practical details.

The short version: local, deterministic, read-only, and designed to hand decisions back to the tools already editing your code.

Does my code get uploaded anywhere?

No. Folder and ZIP imports are read inside this browser and never uploaded. A live website scan sends only the public HTTPS URL you enter to the bounded scanner; it never receives local source, credentials, cookies, or browser storage.

Does Ledgermachine execute imported code?

No. Supported source files are parsed as text in a Web Worker. Imported JavaScript, build scripts, components, and configuration are never evaluated.

What does it cost?

Ledgermachine is free to use locally. There is no account, trial, cloud workspace, or telemetry SDK.

Will it work without design tokens?

Yes. Ledgermachine reconstructs the visual vocabulary already present in the source and can propose a token set for review.

How is this different from stylelint?

Stylelint enforces declarations. Ledgermachine compares decisions across the project, keeps history, and exports durable agent guidance.

How is this different from visual regression testing?

Visual regression tools compare rendered pixels. Ledgermachine identifies source-level causes without rendering or executing the project.

Which coding agents can use the exports?

AGENTS.md, DESIGN.md, tool-specific instruction files, repair briefs, the CLI gate, and local MCP cover common agent workflows. Requested MCP results become available to the connected AI client and may be processed by its provider.

What happens if I clear browser storage?

The ledger lives in IndexedDB. Export a portable project archive for backup or transfer.

After the next agent pass

Check what the last coding session changed.

Enable JavaScript to scan a project or open the sample. Analysis is local and read-only; imported source is never uploaded or executed.