One coordinator keeps parallel agent work visible
Herdr Projects separates conversation from execution. You tell a coordinator what the project needs, approve its proposed threads, and each thread starts a separate agent on its own Git worktree and branch. The coordinator remains available while workers run. Herdr's sidebar groups the threads by project and shows which ones need an answer, which are working, and which have reached review.
That is more useful than simply opening five terminals. Every brief can carry the same goal, standing instructions, and project memory. A worker can report a lesson under ## Remember, and later threads receive it. The project folder also keeps task assignments, reports, uploads, and files produced by agents. You still decide what to review and merge; the plugin organizes the queue around that decision.
The plugin requires Herdr 0.9.1 and an agent CLI
Herdr Projects is not a standalone runner. It needs Herdr 0.9.1 or newer, Git, macOS or Linux, and an agent CLI that Herdr knows how to start. The repository names Claude Code, Codex, and OpenCode among the choices. Installation uses herdr plugin install, then one configuration pass adds the project sidebar rows, popup key, progress hooks, and coordinator skill.
A prebuilt binary covers the normal path. Rust 1.89 is required when a matching binary is unavailable or when you are developing the project. Remote threads run on SSH machines you already control, while project files stay under ~/.herdr-projects by default. There is no hosted Herdr Projects service. Your agent CLI still talks to its own provider and charges each worker as a full session.
What happened when we ran it
In our unprivileged Rust sandbox with 3 CPUs and 12 GB of RAM, commit 4e4548c installed in 11 seconds and fetched 75 packages. The build succeeded in 44 seconds. The test run ended after 126 seconds with 648 passed and 2 failed out of 650. The repository contained 82 files, about 24,903 source lines, and 1 CI workflow.
The log tail identifies one failing test, thread::tests::copies_report_and_library_and_skips_symlinks. It expected a completed copy and instead received could not run rsync: No such file or directory. A fresh Debian container did not include that executable. The supplied summary says 2 tests failed overall, but the tail does not identify the other failure, so attributing both failures to rsync would go beyond the evidence.
Our run found no Dockerfile and did find a tests directory. We did not launch Herdr, create live agent panes, open pull requests, or connect an SSH worker. The 648 passing tests show wide local coverage, while the failed complete suite means a contributor following the source path still needs to discover at least one undeclared system dependency or test assumption.
Worktrees isolate edits, while merges stay human decisions
A Git-backed thread gets its own worktree and branch. When a pull request merges, the ticker can resolve the thread, copy its report and library home, and remove the worktree after the agent finishes. Cleanup refuses to force-remove a worktree with uncommitted changes. The plugin itself does not push or merge; a thread performs a merge only after it receives that instruction.
The pull-request follow-up is strongest on GitHub. Checks and review comments can be returned to the responsible thread, and a merged pull request closes the work. Open issue 86 asks for Gitea and Forgejo support, while issue 103 says GitHub Enterprise pull-request URLs are ignored. Teams on those forges should treat the coordination loop as incomplete rather than assuming a generic Git remote is enough.
Soft safety settings cannot contain an agent with a shell
The coordinator normally proposes threads and waits for approval. Agent permission prompts remain in place, and routines cannot run shell commands until you enable them and approve each command. The README still calls these controls soft. An agent launched with permission-skipping flags can edit project files, a worker can send hostile text back toward shared memory, and an approved routine command may invoke scripts whose contents were not separately approved.
The documentation recommends allow-listing individual read and steering subcommands, never the bare herdr-projects binary. Destructive or widening operations such as resolving threads, sweeping, deleting, renaming, approving routines, and configuring should keep their normal prompt. This is good advice, but it is policy enforced through agent behavior and file placement, not an operating-system sandbox.
Two open issues expose coordination and audit gaps
GitHub showed 25 open issues and pull requests on October 6, 2026: 13 issues and 12 pull requests. Issue 80 reports that when two projects share one remote machine, only the first project may get polled, leaving the other's threads unstarted or stale. Pull request 102 proposes a fix, but v0.2.34 predates it. Issue 106 says keystrokes sent by one coordinator into a stopped thread leave no durable record of who answered or what was sent.
The activity level is healthy for such a young project. The repository was pushed and v0.2.34 released on September 28, and issue work continued through October 5. Speed also means the operating surface is moving quickly. Our 648 passing tests support a trial, especially for a solo maintainer already inside Herdr. A team should first test one disposable repository, keep permissions narrow, and verify that every remote thread and coordinator action remains attributable.

