---
title: Roadmap
description: What is planned for Zit, why, and what each item depends on. Plans, not promises; no dates.
---

Each item below is a known gap: it is listed on [Limits](/limits) or came out of the review in `feedback/review-01.md`. Status is as of <ZitVersion />. Nothing here is built until it says so, and the order is the current priority, not a schedule.

## Distribution

| Item | Why | Status |
|---|---|---|
| Publish the crate, so `cargo install zit` works | Install without access to the repository | Done: `zit` 0.1.1 is on [crates.io](https://crates.io/crates/zit); `cargo install zit --locked` installs it |
| Publish the Pi extension (`pi install npm:pi-zit`) | Install without a local checkout | Done: `pi-zit` 0.1.0 is on [npm](https://www.npmjs.com/package/pi-zit). Still to do: a turn with a live model |
| Release Autohand Code with `autohand --zit` | A whole Autohand Code session in a Zit workspace | Built and run end to end; ships in the next Autohand Code release |
| Windows | Claude Code and Cursor run there; Zit is Unix-only (signals, `libc`) | Not started |

## Correctness

| Item | Why | Status |
|---|---|---|
| Resolve references by path and import, not only by name | A mention of `Config` depends on every `Config` in the repository ([Limits](/limits#semantics)) | Not started |
| More languages with symbol granularity (Java, C#, C++, Kotlin, Ruby, PHP, Swift) | Files in those languages are one resource with no inferred reads | Not started |
| Re-measure false refusals | The 21–23% figure predates the interface-only staleness rule (ADR 16) | Not started |
| Signed evidence | Fetched check results are untrusted by default; trusting them (`zit.trustFetchedEvidence`) trusts whoever can push refs | Not started |
| Run `[[derive]]` and `[prepare]` only from trusted states | A change's own `zit.toml` commands run when you accept or materialise it | Not started |
| Keep agents' branches, tags and stashes out of the real repository | A workspace shares the repository's refs | Not started |
| Stop children of interactive agents | Headless runs stop the agent's process group; interactive runs stop only the agent | Not started |

## Scale and teams

| Item | Why | Status |
|---|---|---|
| Claims across machines | Claims and live write sets are local to one machine | Not started |
| Verify non-conflicting changes as one batch | Changes are verified one at a time; merge queues batch ([Compared](/compare)) | Not started |
| An integrator for CI (for example a GitHub Action) | Today you run `zit accept` in a job yourself | Not started |
| Stable-path workspaces for compiled projects | Each workspace is at a new path, so Cargo and similar tools rebuild per workspace (about 1.9 GB after ten Rust agents, Lesson 01) | Not started |
| Usage from Autohand Code and Pi | Only Claude Code (tokens and dollars) and Codex (tokens) report it to `zit run` | Not started |

## Evidence

| Item | Why | Status |
|---|---|---|
| Repeat the experiments on other repositories, languages and machines | Every real-agent result so far is from one or two runs on one Mac ([Lessons](/lessons)) | Not started |
| Human review of what landed | Quality has been scored only by a blind model judge (Lesson 04) | Not started |
| A pnpm baseline for the dependency benchmark | The 327 MB against 1,619 MB comparison is against `npm ci` per worktree | Not started |
| Linux disk benchmark with real dependencies | The Linux runs use a synthetic repository of small files | Not started |

## From the research

Candidates from [Prior art and objections](/prior-art), each answering a weakness found there. Sizes are estimates.

| Item | Why | Size |
|---|---|---|
| Parse-check the composed state before running checks | Text from `git merge-tree` can be syntactically wrong (Mori and Hashimoto, 2026) | Small |
| Report false refusals and false accepts against test oracles | Merge-tool evaluations that ignore incorrect clean merges overstate quality (Schesch et al., 2024) | Medium |
| Replay public agent-conflict data: AgenticFlict, CooperBench, STALE | Measured accuracy on other people's data instead of our own runs | Medium |
| A conflict graph from footprints, to verify independent changes together | Uber's SubmitQueue commits independent changes in parallel; Zit verifies one at a time | Large |
| A structure-aware merge for adjacent insertions | Zit's most common remaining rejection; semistructured merge removes it (Apel et al. 2011; Cavalcanti et al. 2017) | Large |
| Detect renames before deciding staleness | A rename is a delete plus an add, which stales every reader (RefFilter, 2025) | Medium |
| Compose open workspaces against each other in the background | Crystal's speculative merging warns before anyone records | Medium |
| Measure how much parallelism refused claims give up | Pre-write admission serialised 93.3% of clean cases in Claim Plane (2026) | Small |
| A port and namespace per workspace | Agents share ports and machine-wide state today | Small to medium |
| An optional log of the commands an agent ran | Zit keeps the final message and cost, not what was run | Small |
| Select checks from footprints instead of declared `inputs` | Check inputs are trusted, not verified | Medium |

To propose or take on an item, open an issue ([CONTRIBUTING.md](https://github.com/autohandai/getzit/blob/main/CONTRIBUTING.md)).
