October 6, 2026
citepath.ai is a live GEO SaaS: enter a domain, get a free “share of answer” scan across ChatGPT, Claude, Gemini and Perplexity, and subscribe for monitoring plus a fix feed that tells you exactly why the answer engines cite your competitors instead. Nobody wrote it. The product spec was one paragraph; everything since — the repo, the infrastructure, the schema, the marketing site, the MCP endpoint, the brand assets — was built by a LiveGraph bootstrap run and the improvement loop it installed.
Our modelright post showed a bootstrap run shipping a product. CitePath is the harder claim: the loop didn't just land the skeleton, it kept building — thirty-three pull requests merged as reviewed, CI-gated work, with the whole run visible the entire time. This post is the honest version, because the honest version is the better pitch.

Open citepath.ai · Findefend, the previous build · Modelright, the first bootstrap
The bootstrap run asked for exactly two approvals up front — Stripe product creation and nameserver delegation, the two calls that move money and control DNS — then provisioned unattended end to end: the GitHub repo, the Railway project and Postgres, the Cloudflare zone and apex redirect, citepath.ai's delegation at the registrar, the mcp.citepath.ai subdomain, every declared secret, and a deploy-verify pass before it called anything live.
Then the loop took over: every ten minutes a tick reads the repo's QUEUE.md, the engineer picks the top item onto a branch, CI runs, a reviewer reads the real diff, and a publisher merges through a human gate. The queue it's working was drafted from the product brief — nobody hand-wrote the work items either.
Every failure below is real, happened on camera-adjacent infrastructure, and is now a platform feature or a queue item. That mapping is the actual product story: a build system you can trust isn't one that never fails, it's one whose failures are visible, fixable, and never the same twice.
.env.example — the starter's provisioning manifest — declared RESEND_API_KEY=, OPENROUTER_API_KEY= and eight Stripe vars as bare names, which the manifest parser correctly read as “generate random hex.” Signup failed on a dead email key; scans ran on a dead model key. The fix ran the app's own provisioning path with real sources declared (@resend-key, @vault:, @app-url) — and it bit a second time when a loop merge re-added a bare DATABASE_URL=. Lesson now enforced in the queue: .env.example is executable config, and a bare name is a write of random hex to production.PGDATA pointed at the volume mount root, and initdb refuses a non-empty directory — while /health kept passing because Next.js booted fine. Deploy verification now has to care about more than “the app answers.”ci_infra_failure webhook fails over to it.rate_limits rows until the per-IP signup cap rejected the test's registrations. The per-run schema reset that fixed it hit a subtler bug first: dropping the public schema left Drizzle's migration journal behind, so migrations reported themselves applied to an empty database. Both schemas drop now.queued forever while the cron reported claimed: 0. Peeling it took four deploys: Drizzle's raw-SQL path rejecting Date params (raw postgres-js accepts them — the unit tests never saw a real driver), then an OpenAI rule that json_object requests must say the word “json” somewhere, then prompts that never named their schema's keys so the model invented its own, then two engine model IDs that had been retired upstream and returned 404. Every layer was real, every layer invisible to CI, and all of it only surfaced because we tried to take a screenshot of the feature working.Most “AI built this” stories end at the screenshot. This one doesn't have to: the loop is still running, and every round is an ordinary LiveGraph run on an ordinary canvas — you can open it, watch the hop trail, and reroute it while it works. The run trails, the PR history, and the per-item loop reports in the repo are the receipts; the product is the proof.
The coda is the product turning around. CitePath's own job is a scanner for AI visibility — so we ran it on its maker. Verdict on livegraph.ai: 80/100 on machine readiness, 0% share of answer across twenty real queries on four engines. The engines name Jenkins, GitLab CI, Cursor and Amazon Q Developer instead — which is, of course, the entire point of the product: a concrete gap list instead of a vibe. The loop closing the loop, and filing tickets about it.

The same template that built CitePath is the App Bootstrap flow in your workspace: connect GitHub, Railway, Cloudflare and Stripe, describe the product in one paragraph, approve the money calls once, and watch the loop go to work. The failures above aren't reasons to hesitate — they're the list of things that already went wrong so they won't for you, and the queue items that made each one impossible to repeat.