assurance-core
Did your agent read everything it was supposed to read?
Every tool call can return 200 and the answer still be built on two thirds of the data.
Groundedness checks the output against the input. This checks the input against the question.
pip install assurance-core
from assurance_core.coverage import Coverage
Coverage.of(
expected=["msa.md", "amendment-1.md", "amendment-2.md"], # what the question spans
found=["msa.md"], # what your retriever returned
where="the retrieved set",
).summary()
# '1 of 3 items — not in the retrieved set: amendment-1.md, amendment-2.md'
Zero dependencies · Python 3.10+ · no model decides any of it
Use it for
Keys are anything you can name, so the same three lines cover:
| expected | found | |
|---|---|---|
| RAG | documents the question spans | chunks the retriever returned |
| Code review agents | git diff --name-only |
files the agent opened |
| Compliance | controls in scope | controls with evidence |
| Data pipelines | partitions declared | partitions loaded |
| Eval harnesses | cases declared | cases actually run |
| Batch jobs | records enumerated | records processed |
Six runnable examples in examples/,
held green by CI.
A gap is six different facts, not one
Most tools give you one missing bucket. It throws away the only thing you need — what to do next.
| means | so | |
|---|---|---|
missing |
nothing matched it | chase the owner |
gone |
a tombstone says it was here | that's an incident |
ambiguous |
two candidates | a human picks; we won't |
unreadable |
present, nothing legible | untested, not absent |
unauthorized |
present, you may not see it | escalate the task, not the answer |
truncated |
the listing hit a cap | the denominator is wrong |
A capped "24 of 24 — complete" is worse than no number at all, so truncated makes complete
false on its own. We don't know what we didn't see is not nothing.
The wording is deliberate too: "not in this folder", never "missing". The first is a fact about a directory listing. The second is a guess about the world.
No model, and it's gated not claimed
Every module is walked by an AST test that fails on a model or service import. CI runs it on 3.10 –
3.13, then imports all sixteen modules from an installed copy and asserts nothing leaked into
sys.modules.
Swap the model and the prose changes. The arithmetic doesn't.
Modules
coverage |
Did the worker read everything the task required? |
staleness |
Do recorded figures still match the source? |
admission |
Should this source inform the answer, given provenance? |
verification · task_contract · run_outcome |
What was done meant to be, and what happened? |
policy · principal · worker · effects |
Who may have which worker produce which effect? |
rule_of_two · run_budget |
Too many risk properties at once? Limits enforced by code? |
report_period · sequence · semantic_checks |
Which month, which series, which figure |
Honest limits
- It will not derive your expected set. That's your declaration on purpose — a denominator a tool invents is one nobody can argue with
- Some modules carry I-Ops' own data as their worked example.
worker.VINCIis aWorkerDefinitionfor our product,policy_config.default_allow_vinci()builds a rule set around it, andeffects.CAPABILITY_EFFECTSis our capability table (draft,render, and what may stage a Gmail draft). They are there because this is a publication of a working system, not a clean-room SDK — but they are examples, not the interface.coverage,staleness,admission,sequenceandreport_periodcarry nothing product-specific - Many conditions still have no verifier, so the honest answer stays complete but unverified
- Source admission is provenance-only — inert on a corpus with no tombstones or supersessions
- Staleness needs a prior artifact record, which this library does not provide
- Not a runtime, an agent framework, or anything that does something on its own
In 0.3.0
Coverage(expected=..., found=...) without missing used to report complete is True on 11 of 12.
The library that exists to stop successful-looking wrong answers had an API that made one.
Coverage.of() now derives the gap, unaccounted blocks completion, and read counts the
intersection. If you build Coverage(...) directly, move to Coverage.of(...).
Family
assurance-cli — same checks as a command, for CI · assurance-mcp — same checks as MCP tools
Upstream is I-Ops; this repo is a publication, never a source. Apache-2.0 · Contributing · Security
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file assurance_core-0.3.3.tar.gz.
File metadata
- Download URL: assurance_core-0.3.3.tar.gz
- Upload date:
- Size: 103.2 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
63be40c84f1dafd0a05a5087d8a0c6d1d88907ab040b5fccb77e3f0091a4426b
|
|
| MD5 |
b3a2fd238384d4a6391e9f5aa37ef3c7
|
|
| BLAKE2b-256 |
23b076c94f60748ca39e1b1357aa2d64bfe2a910352be2f168c03c17ba81cfe2
|
Provenance
The following attestation bundles were made for assurance_core-0.3.3.tar.gz:
Publisher:
publish.yml on i-ops-hq/assurance-core
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
assurance_core-0.3.3.tar.gz -
Subject digest:
63be40c84f1dafd0a05a5087d8a0c6d1d88907ab040b5fccb77e3f0091a4426b - Sigstore transparency entry: 2644347124
- Sigstore integration time:
-
Permalink:
i-ops-hq/assurance-core@f2dfb9941d5314d6c5b5dad3ebca56f05b5c9c76 -
Branch / Tag:
refs/tags/v0.3.3 - Owner: https://github.com/i-ops-hq
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish.yml@f2dfb9941d5314d6c5b5dad3ebca56f05b5c9c76 -
Trigger Event:
push
-
Statement type:
File details
Details for the file assurance_core-0.3.3-py3-none-any.whl.
File metadata
- Download URL: assurance_core-0.3.3-py3-none-any.whl
- Upload date:
- Size: 80.7 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
9d390bf4e3e31dbea1c7a884e813a7aa961b7d92c19f598801ac7a48792be94d
|
|
| MD5 |
3945f6347b04a90731b124b966c974f2
|
|
| BLAKE2b-256 |
a7629d54862aadc0df5700c6d37d5f8d556fa7143318671723b296d3fd0e5d23
|
Provenance
The following attestation bundles were made for assurance_core-0.3.3-py3-none-any.whl:
Publisher:
publish.yml on i-ops-hq/assurance-core
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
assurance_core-0.3.3-py3-none-any.whl -
Subject digest:
9d390bf4e3e31dbea1c7a884e813a7aa961b7d92c19f598801ac7a48792be94d - Sigstore transparency entry: 2644347681
- Sigstore integration time:
-
Permalink:
i-ops-hq/assurance-core@f2dfb9941d5314d6c5b5dad3ebca56f05b5c9c76 -
Branch / Tag:
refs/tags/v0.3.3 - Owner: https://github.com/i-ops-hq
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish.yml@f2dfb9941d5314d6c5b5dad3ebca56f05b5c9c76 -
Trigger Event:
push
-
Statement type: