assurance-cli
Did the job cover everything it was supposed to cover?
One command. One honest ratio. An exit code your pipeline can act on.
pip install assurance-cli
assurance diff --expected corpus.txt --found retrieved.json \
--scope "documents the question spans" --where "the retrieved set" --fail-on-gap
2 of 5 documents the question spans — not in the retrieved set: doc-2, doc-3, doc-5
also present and not expected: doc-9
That second line matters as much as the ratio: the retriever drew on something the scope never allowed. It's reported, and it earns no credit.
No account · no API key · no network call · no model decides any of it
Three commands
diff is the general one. check is the special case for a folder of
dated or numbered tabular files — if your files are .md, or named in a format it can't read, use
diff and declare the set yourself.
assurance diff — any two sets of keys
# code review agent actually read the diff?
git diff --name-only origin/main...HEAD > changed.txt
assurance diff --expected changed.txt --found reviewed.txt --fail-on-gap
# eval suite ran every declared case?
assurance diff --expected cases.json --found ran.json --fail-on-gap
# straight from a pipe
retriever --query "$Q" | jq -r '.chunks[].doc_id' | \
assurance diff --expected corpus.txt --found - --json
Inputs are whatever you already have: one key per line, a JSON array (strings, or objects
with key/id/name/path), - for stdin, or an inline comma list.
assurance check — a folder of dated or numbered files
assurance check ~/reports
22 of 24 months from 2024-01 to 2025-12 in reports — not in this folder: March 2025, July 2025
— Range inferred from filenames: earliest 2024-01, latest 2025-12. Override with --from / --to.
assurance check ~/invoices --expect numbered
7 of 8 runs from inv_0001 to inv_0008 in invoices — not in this folder: INV-0006
— Range inferred from filenames: earliest inv_0001, latest inv_0008. Override with --from / --to.
Monthly, quarterly, weekly, daily, numbered. That last line is the derivation: it prints with every ratio so you can disagree with the denominator, not just the result.
assurance init — did anything change underneath?
assurance init ~/thesis-data
# Baseline written to ~/thesis-data/.assurance.json — 34 tabular files recorded.
# ... weeks pass, several people touch the folder ...
assurance check ~/thesis-data --against-baseline
Exit codes
0 |
it checked, and either found no gap or wasn't asked to fail on one |
1 |
a finding: a gap with --fail-on-gap, a stale baseline, or nothing it could check |
2 |
could not run: bad path, unreadable list, unparseable JSON, a table where keys were expected |
"I couldn't check this" exits 1, not 0. A folder whose filenames it can't parse must not look like a folder it checked and found whole.
Diagnostics go to stderr, results to stdout, so --json stays pipeable.
It expects your files, not tidy ones
- Excel exports work. UTF-8 BOM and CRLF are handled; a BOM used to glue itself to your first key and report it as missing and unexpected in the same sentence
- Spaces, unicode and month words in filenames —
Inventory Report August 2024.csvparses .xlsx, and nested subfolders- A piped CSV is refused, not misread. It names the column-picking command instead of quietly admitting your header row as a key
- When it can't work out a series it says so, rather than reporting an empty check as a pass
Use it for
| expected | found | |
|---|---|---|
| RAG | documents the question spans | chunks retrieved |
| Code review in CI | git diff --name-only |
files reviewed |
| ETL / batch | records or partitions declared | records or partitions loaded |
| Compliance | controls in scope | controls with evidence |
| Research data | the series you expect | what's actually in the folder |
What it won't do
- Invent your expected set.
difftakes your declaration;checkderives one and prints how - Send anything anywhere. No network, no telemetry, no keys
- Guess. A JSON object of id → metadata is refused, not interpreted
Family
assurance-core — the pure arithmetic, zero dependencies · assurance-mcp — the same checks as MCP tools
Upstream is I-Ops; this repo is a publication, never a source. Apache-2.0.
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file assurance_cli-0.2.3.tar.gz.
File metadata
- Download URL: assurance_cli-0.2.3.tar.gz
- Upload date:
- Size: 26.8 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
737eabfe86d07bb46abec90458fd889197b0a3d82f74502ebc17279576fbe4ef
|
|
| MD5 |
32bd0fbdab136125c7283e9d256b5877
|
|
| BLAKE2b-256 |
48a7ce873989f7791e6a1768a2819edd8e89e121268838ee181e6585a401e1a3
|
Provenance
The following attestation bundles were made for assurance_cli-0.2.3.tar.gz:
Publisher:
publish.yml on i-ops-hq/assurance-cli
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
assurance_cli-0.2.3.tar.gz -
Subject digest:
737eabfe86d07bb46abec90458fd889197b0a3d82f74502ebc17279576fbe4ef - Sigstore transparency entry: 2644368344
- Sigstore integration time:
-
Permalink:
i-ops-hq/assurance-cli@db8751ee24c9691ca529171c5b3766aceac5d210 -
Branch / Tag:
refs/tags/v0.2.3 - Owner: https://github.com/i-ops-hq
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish.yml@db8751ee24c9691ca529171c5b3766aceac5d210 -
Trigger Event:
push
-
Statement type:
File details
Details for the file assurance_cli-0.2.3-py3-none-any.whl.
File metadata
- Download URL: assurance_cli-0.2.3-py3-none-any.whl
- Upload date:
- Size: 22.2 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
cc684ac92dba2c4b00ceff517a56c19dfed5894ec826adeaa2b8ba1b05f38cd6
|
|
| MD5 |
7210d84d6f217a431cb4541e93d0d7f4
|
|
| BLAKE2b-256 |
3bc794a8d92d916eec7bb8b653d19029cadf3c0b0215cf2767e24c84936d7bfc
|
Provenance
The following attestation bundles were made for assurance_cli-0.2.3-py3-none-any.whl:
Publisher:
publish.yml on i-ops-hq/assurance-cli
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
assurance_cli-0.2.3-py3-none-any.whl -
Subject digest:
cc684ac92dba2c4b00ceff517a56c19dfed5894ec826adeaa2b8ba1b05f38cd6 - Sigstore transparency entry: 2644368599
- Sigstore integration time:
-
Permalink:
i-ops-hq/assurance-cli@db8751ee24c9691ca529171c5b3766aceac5d210 -
Branch / Tag:
refs/tags/v0.2.3 - Owner: https://github.com/i-ops-hq
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish.yml@db8751ee24c9691ca529171c5b3766aceac5d210 -
Trigger Event:
push
-
Statement type: