Review runs only once the whole plan is reported complete, with final-tree verification, field-test evidence and a trace from every in-scope requirement to its implementation. It never fires on a draft, a single commit or a corrective patch; the unit under review is the finished plan and its final diff. A small task gets one reviewer carrying three lenses in one brief: spec compliance, correctness, and structure. A large task gets that same single reviewer by default, and a second structure reviewer joins only on explicit request or when an objective trigger fires, protected paths, cited numeric or safety constants, at least six production files, or at least five hundred changed production lines.
The frame is that review is proportional, and it confirms rather than rescues. The gate scales to the blast radius instead of running the same ceremony over a typo and a schema change. Every finding is classified as a blocker, a deferred note or a scope change, and every review returns two explicit verdicts: a simplicity verdict on whether fewer files or lines would do, and a spec-compliance verdict tracing each requirement to its evidence. A run has a fixed ceiling of review waves, and when they are exhausted with a blocker still open the unit is marked blocked and handed back, not patched forever.