Skip to content
LiveGraph

A loop wrote a complete SaaS for $23.85 — then handed over the keys.

October 6, 2026

findefend.com is a subscription-spend defense product: upload a CSV or bank statement and it finds the recurring charges you're still paying — price hikes, upcoming renewals, zombie trials — and recommends what to cancel. It has Stripe billing, email digests, an admin console, a status page, and a login that works. Nobody wrote it. A LiveGraph bootstrap run created the repo, provisioned Railway, Cloudflare, Stripe, and delegated the domain at GoDaddy — and an improvement loop then built the entire product through fourteen queued items, each one a reviewed, CI-gated pull request.

The total model spend for the entire product backlog: $23.85. This is the honest version of that story — including every place it broke, because the breakage is where the product actually lives.

The Findefend Engineering graph running live on the canvas: the Lead has dispatched the Engineer node, which is mid-hop with a thinking indicator, while the Reviewer, Planner and publisher lanes idle below
The actual engineering loop, mid-tick: Lead dispatches, the Engineer works a queue item through the GitHub MCP, the Reviewer waits on CI. Nothing simulated.

Twenty-five minutes of model work, then a loop

The bootstrap run did the plumbing a founder would otherwise spend a week on: seeded a private repo with a 50-file SvelteKit starter and a 14-item QUEUE.md; armed CI and the required build check; stood up Railway with Postgres and push-to-deploy; created the Cloudflare zone, DNS records and Stripe test products; and delegated findefend.com's nameservers at GoDaddy. Two steps paused for a human: the registrar delegation is a money-risk tool gate (the first API attempt actually 404'd, the Provisioner corrected the call shape and re-gated), and the Deploy Verify gate is the last checkpoint before the run declares anything live.

Its last output was honest rather than triumphant: “the app is pending — DNS propagation in flight.” The domain resolved an hour later.

The queue built the product

A ten-minute tick then worked QUEUE.md top to bottom — one branch per item, every push runs CI, a reviewer reads the real diff, a human gate watches protected paths. Fourteen items, fourteen merges, zero items left needing a human:

ShippedPRModel spend
Spend schema, CSV import, recurrence detection, landing & config#3–#6$7.85
Price-hike, renewal & zombie-trial alerts; Stripe billing; LiveGraph scanner#7–#9$2.26
Spend dashboard, vendor watchlist, cancel recommendations#10–#12$7.98
Status page + analytics, email digests, admin console#2, #14, #15$4.88
The loop's own queue-refill proposal, then export & account deletion#16, #17$0.88

Steady-state items run $0.40–$1.20 each on a deliberately cheap fleet — the three outliers each had a mid-flight incident, which is the next section. When the backlog emptied, the loop didn't stop: its Planner node drafted the next milestone itself (manual entry, alert preferences, categories, a price-history chart) as a QUEUE.md diff that waited on a human merge. A person clicked merge; the loop shipped the first item within the hour.

What broke, and what it produced

The product was the demo; the incidents were the roadmap. Each of these is a real production failure from the build — and the fix it shipped or queued:

  • A rejected review went invisible. The reviewer flagged q-0008 for revision, but the rejection detector required the verdict at position 0 while the edge router accepts the first standalone verdict line anywhere — the loop read queue_in_flight forever. Fixed by making the detector call the router's own parser; detection can never diverge from routing again. The revision lane then fired, the engineer added the missing page, and the PR merged.
  • GitHub ran out of Actions minutes. A CI job queued 15 minutes, never got a runner, and cancelled. Detection existed; recovery didn't. Now a self-hosted runner is provisioned per-app at bootstrap, and a “no runner assigned” delivery flips the repo to it automatically — the loop healed itself on the new runner and its fix round found a real bug.
  • The health check read a redirect as downtime. The Provisioner's own apex→www rule 301s the apex, and Deploy Verify read the bare 301 as “still issuing” — reporting APP_PENDING on a healthy app. Queued: verify must follow same-domain redirects.
  • Stale IDs baked into instructions. A node's saved instructions carried a Railway project ID from an earlier deployment; the owner handoff looked the project up, found nothing, and stopped — legibly, not silently. Queued: input markers are authoritative, instructions never bake drifting IDs.
  • A human edited the spec mid-flight — and wedged the branch. Rewriting an open queue item on main made the in-flight branch's untouched-but-stale copy read as a forbidden reword to the queue-diff verifier — a wedge only a human could clear. The fix is queued: compare against merge-base, not live HEAD. (The rewrite itself was right — the engineer had discovered GoDaddy's OAuth is partner-gated, so the item became PAT Bearer auth.)
  • A secrets gate almost auto-approved empty. The gate that collects the owner's credentials would have been released by the generic auto-approve window. Now secrets-declaring gates can never auto-approve — silence must not release a gate that exists to gather input.

The last gate hands over the keys

The build's final step is an Owner Handoff gate. It renders a fillable secrets form — owner email and password — encrypts the values into the credential vault at approve-time, and writes only {{vault:…}} references to Railway. The model saw references, never values; the run ended with “SUCCESS: build complete — log in at findefend.com/login.” The app now belongs to its owner, and the loop that built it is still running — on a $50/day budget, behind the same gates, proposing its own backlog.

The Findefend Engineering graph on the live canvas mid-run with three nodes running: Lead on a cheap flash model, Engineer thinking, reviewer and dispatch lanes below
Still running: the same graph on its ten-minute tick, working the next milestone it proposed for itself.

The product is real, too

findefend.com's live landing page: 'Find the recurring charges you forgot you're paying for' — CSV import, recurring-charge flags, price-hike and zombie-trial alerts
findefend.com is live right now — upload a statement and it finds the charges you forgot. Yes, the loop built the signup flow too.

The pitch isn't that a loop can write a CRUD SaaS — it's that the failures were legible. Every incident above surfaced as an observable state — a parked gate, a skip reason, a needs-you row — and most produced a platform fix that makes the next app's run smoother. Pick App Bootstrap in Templates, fill in six fields, and watch a domain become a self-improving product. (Or go find the subscriptions you forgot about — the product works either way.)

See it running

The live demo needs no account and no API key — a scripted model drives the real engine while you reroute a run in flight. When you want your own graphs, sign up and the included model runs them; bring a key when you want a different provider.

Keep reading

  • We gave LiveGraph a paragraph. It built citepath.ai — and it hasn't stopped. — citepath.ai is a live GEO SaaS built entirely by a LiveGraph bootstrap run and its improvement loop: provisioning, self-hosted CI, thirty-three merged PRs, every failure — and what each failure became.
  • Our engineering team is a LiveGraph graph. Here is what broke. — LiveGraph's own repo is improved by a LiveGraph loop: a tick fires the Lead, an engineer works through the GitHub MCP, CI routes its own verdict, and a human gate decides every merge. Including the three ways it failed.
  • Share a run people can watch, not a log they can't — POST /runs/:id/share mints a stateless token that renders a read-only, live-updating canvas — topology and hop status, never hop content. Embed it in docs, status pages, or a client deliverable.
  • LangGraph edits a run's state. LiveGraph edits a run's route. — LangGraph compiles your topology into code; LiveGraph keeps it in data you can mutate between hops. Two different primitives — an honest map of where each one fits.
  • We pointed LiveGraph at an empty domain. It shipped a product. — modelright.dev went from a domain name to a live, self-improving app through one bootstrap run and a 10-minute improvement loop — approvals, conflicts, and all.
  • Steer a running agent workflow — LiveGraph re-reads the graph after every hop, so dragging an edge changes where this run goes next.
  • Why you can't reroute a running n8n workflow (and why you can in LiveGraph) — Most engines compile a run before executing it, so mid-run edits only affect the next run. A per-hop engine makes rerouting free — here's the architecture.
  • Giving agents write access to real code without losing sleep — Worktree isolation, operator allowlists, encrypted secrets, and pushes only a human's literal keystrokes can trigger — the safety model, decision by decision.

LiveGraph

Model-agnostic agent orchestration on a live canvas. Hosted at livegraph.ai.

Product

  • Live demo
  • Pricing
  • Security
  • Automations
  • Compare
  • Migrate from Flowise
  • Migrate from Agent Builder
  • Sign up

Resources

  • Blog
  • Docs
  • Changelog
  • Model Radar
  • Status
  • RSS

Agents

  • Agent guide
  • llms.txt
  • llms-full.txt
  • MCP integration

Support

  • [email protected]

Legal

  • Privacy
  • Terms
© 2026 LiveGraphSite by Canweb Ltd.