# Checks

> Checks are sentences about what must stay true. Agents turn each one into a test, and every change is tested against them before it can ship.

Source: https://gaitro.com/docs/checks

A check is a sentence about something that must stay true, like "Refunds never exceed what the customer paid." The agent that adds it writes a test for it and links the two:

```sh
gaitro check add "Refunds never exceed what the customer paid"
gaitro check compile <handle> --run "npm test -- refunds"
```

`gaitro status` lists checks still waiting for a test. A draft can't ship while one is waiting, while one fails, or before the full suite has run.

## Where checks run

On hosted Gaitro, checks run in a fresh sandbox for every run, destroyed when the run ends. `gaitro check env` says what's in it: the operating system, Node, tools, network and environment variables. Put installs and builds in the setup step so they run once per run, not once per check:

```sh
gaitro check setup "npm ci && npm run build"
```

`gaitro check run <handle>` runs one check on your machine, the way the server does.

## Safety checks

Every change is also checked, on every plan, for passwords or keys in the code, unknown or misspelled new packages, personal data in logs, endpoints that don't check who's asking, database changes that throw data away, and hidden instructions in agent instruction files. Letting one through takes a written reason: `gaitro safety ok <id> --reason "…"`.

## Check minutes

Check minutes are the time checks spend running in the sandbox, setup included. Each plan comes with minutes every month ([Pricing](/pricing)). On Pro and Pro Plus you can buy extra minutes, which are used only after the month's plan minutes run out. When none are left, new check runs wait until there are more.
