← All implementations

Shopify · Platform

Aquifer / River

The Aquifer agent platform (session/harness/sandbox split) powers River, a Slack-native coding agent, plus research, migration, and app-security agents.

1

Supporting infrastructure

This entry describes supporting infrastructure that other work builds on. The catalog classifies it as a platform. The record also reports a workflow.

Approach type
Platform
Work
Coding, Code review, Research, Security
Human involvement
Drafts reviewed
Invocation
Event driven, Interactive
Interfaces
Slack, Github
Deployment stage
Scaled
Evidence strength
Detailed primary
Entry reviewed

How it works

The workflow the sources report for this implementation.

Durable identity, disposable loop, isolated execution; swap any layer independently

1

Slack-native coding agent in public channels only; visibility drives adoption

1

Written-down knowledge mined from successful patterns and public transcripts

1

Where people stay involved

  • River coding request → reviewed pull requestWork product review · Level 3

Level 3 for River coding request → reviewed pull request; human attention boundary: work-product-review.

1

Observation date
2026

Implementation details

Sandbox

An execution environment (filesystem, shell, repo, build/test) separated from the harness; Shopify credits the brain-and-hands framing to Anthropic

1

Harness

Session (durable; Postgres append-only event log) + Harness (cheap agent loop) + Cell (ephemeral Go runtime); cells die, sessions persist

1

Model

The design lets Shopify change the model without changing the sandbox

1

Interfaces

slack, github

1

Tool access

Repo + tests + data warehouse + production traces + PR creation; a gateway credentials proxy

1

Knowledge

Monorepo 'World' (code + skills + conventions + intent docs + runbooks + AGENTS.md); Nix reproducible envs; Slack-transcript corpus mining

1

Credentials

Gateway credentials proxy; per-profile sandbox policies; Shopify SSO

1

Context management

Skills loaded on-demand as files, updatable per session; session survival across cell/sandbox/machine death

1

Reported results and limitations

The catalog records what the sources report, with the scope and the denominator of every figure. A qualification below limits the figure it sits under.

Reported metrics

Headline claim

1 in 8 merged PRs company-wide coauthored by River

1

Reported by
Shopify
Scope
Merged River-coauthored PRs across Shopify
Denominator
All Shopify merged pull requests
Key observation

River: 59,918 sessions / 30 days across 5,170 Slack channels

1

The source does not report the denominator of this figure.

Reported by
Shopify
Scope
River sessions and distinct Slack channels in a recent 30-day period
Method
river_sessions domain table, written by River every session
Key observation

3,536 River-coauthored PRs merged; 1 in 8 merged PRs company-wide

1

Reported by
Shopify
Scope
River-coauthored merged PRs in the recent 30-day period; company-wide PR share
Denominator
All Shopify merged pull requests for the one-in-eight share
Method
river_sessions domain table for reported session-linked counts
Key observation

Median session 19 min; median 50 tool calls/session

1

The source does not report the denominator of this figure.

Reported by
Shopify
Scope
Median River session duration and tool calls per session

Lessons and interpretation

Agent-friendly is human-friendly; monorepo, reproducible envs, written skills, and fast CI help both

1

Local agents have a ceiling; private windows mean only the person at the keyboard learns anything

1

Session survival is critical; cells die, sandboxes die, machines die; the conversation doesn't

1

Treat agents as profiles, not platforms; a new agent is a new bundle on the same substrate

1

Sources and research details

Citations link to the original publisher. Each source also keeps a preserved copy in the repository, so a changed or removed page stays checkable.

  1. Under the Riverhttps://shopify.engineering/under-the-riverEngineering blog · First party · Last source verification: 2026-08-31
Research details for every claim on this page
  1. Summary
    Statement type
    Fact
    Provenance
    Reported
    Confidence
    High
    Confidence reason
    A linked first-party source states the claim.
  2. Headline claim
    Statement type
    Metric
    Provenance
    Reported
    Confidence
    High
    Confidence reason
    A linked first-party source states the claim.
    Reported by
    Shopify
    Scope
    Merged River-coauthored PRs across Shopify
    Denominator
    All Shopify merged pull requests
    Method
    Not reported
    Observation date
    Not reported
  3. Sandbox
    Statement type
    Fact
    Provenance
    Reported
    Confidence
    High
    Confidence reason
    A linked first-party source states the claim.
  4. Harness
    Statement type
    Fact
    Provenance
    Reported
    Confidence
    High
    Confidence reason
    A linked first-party source states the claim.
  5. Model
    Statement type
    Fact
    Provenance
    Reported
    Confidence
    High
    Confidence reason
    A linked first-party source states the claim.
  6. Interfaces
    Statement type
    Fact
    Provenance
    Reported
    Confidence
    High
    Confidence reason
    A linked first-party source states the claim.
  7. Tool access
    Statement type
    Fact
    Provenance
    Reported
    Confidence
    High
    Confidence reason
    A linked first-party source states the claim.
  8. Knowledge
    Statement type
    Fact
    Provenance
    Reported
    Confidence
    High
    Confidence reason
    A linked first-party source states the claim.
  9. Credentials
    Statement type
    Fact
    Provenance
    Reported
    Confidence
    High
    Confidence reason
    A linked first-party source states the claim.
  10. Context management
    Statement type
    Fact
    Provenance
    Reported
    Confidence
    High
    Confidence reason
    A linked first-party source states the claim.
  11. Supporting component
    Statement type
    Fact
    Provenance
    Reported
    Confidence
    High
    Confidence reason
    A linked first-party source states the claim.
  12. Supporting component
    Statement type
    Fact
    Provenance
    Reported
    Confidence
    High
    Confidence reason
    A linked first-party source states the claim.
  13. Supporting component
    Statement type
    Fact
    Provenance
    Reported
    Confidence
    High
    Confidence reason
    A linked first-party source states the claim.
  14. Key observation
    Statement type
    Metric
    Provenance
    Reported
    Confidence
    High
    Confidence reason
    A linked first-party source states the claim.
    Reported by
    Shopify
    Scope
    River sessions and distinct Slack channels in a recent 30-day period
    Denominator
    Not reported
    Method
    river_sessions domain table, written by River every session
    Observation date
    Not reported
  15. Key observation
    Statement type
    Metric
    Provenance
    Reported
    Confidence
    High
    Confidence reason
    A linked first-party source states the claim.
    Reported by
    Shopify
    Scope
    River-coauthored merged PRs in the recent 30-day period; company-wide PR share
    Denominator
    All Shopify merged pull requests for the one-in-eight share
    Method
    river_sessions domain table for reported session-linked counts
    Observation date
    Not reported
  16. Key observation
    Statement type
    Metric
    Provenance
    Reported
    Confidence
    High
    Confidence reason
    A linked first-party source states the claim.
    Reported by
    Shopify
    Scope
    Median River session duration and tool calls per session
    Denominator
    Not reported
    Method
    Not reported
    Observation date
    Not reported
  17. Lesson
    Statement type
    Inference
    Provenance
    Catalog judgment
    Confidence
    Medium
    Confidence reason
    The catalog derives this observation from the linked sources.
  18. Lesson
    Statement type
    Inference
    Provenance
    Catalog judgment
    Confidence
    Medium
    Confidence reason
    The catalog derives this observation from the linked sources.
  19. Lesson
    Statement type
    Inference
    Provenance
    Catalog judgment
    Confidence
    Medium
    Confidence reason
    The catalog derives this observation from the linked sources.
  20. Lesson
    Statement type
    Inference
    Provenance
    Catalog judgment
    Confidence
    Medium
    Confidence reason
    The catalog derives this observation from the linked sources.
  21. Operating model assessment
    Statement type
    Inference
    Provenance
    Catalog judgment
    Confidence
    Medium
    Confidence reason
    The source documents pull-request creation but does not establish outcome-only supervision.
    Observation date
    2026