Brevet: Change Control for What AI Agents Learn
A governed evolution loop that makes agent learning promotable, auditable, and revocable.
AI agents now change their own behaviour while they work. They save memories, write themselves new skills and edit their own instructions. Many of these changes help. Yet none of them passes through the steps an organisation expects when a person changes how work is done. Nobody writes the change down, nobody approves it, and when it turns out to be wrong there is no earlier version to go back to.
Brevet adds those steps. It is a local-first Python runtime that wraps the
agent you already have and runs its learning as a governed evolution loop.
When an expert corrects the agent's draft, Brevet records the correction and its
reason as an override. Offline, in the dream cycle, overrides that keep
recurring become candidate capabilities: proposed rules and other learned
behaviour, with no authority. At the dawn gate, a named human or mission
group (the accountable review board) decides which candidates to promote. The
overrides then replay as evals, and the conservative gate stops a
release that makes either half of them worse. Promoted capabilities ship in a
signed release, listed in capabilities.lock, and a capability that proves
wrong can be recalled, with every release that shipped it flagged. Every
step is recorded on a hash-linked evidence chain.
Agents propose deltas; evidence tests them; humans promote them; the runtime only ever executes signed versions.
Three questions Brevet answers
| Question | How Brevet answers it |
|---|---|
| What has the agent learned? | Every release carries capabilities.lock, the capability bill of materials: each learned capability, where it came from and the hash of its exact content. |
| Who approved it? | Each capability records the human or mission group that promoted it at the dawn gate, with the overrides that justified it. |
| How do we take it back? | Recall it. Brevet flags every release that shipped it and records why it was recalled. |
A concrete example
A quality reviewer at a pharmaceutical plant checks an agent's severity rating
for each equipment problem. The agent rates pump vibration during cleaning as
minor. She overrides it to major every time, because that vibration is an
early sign of seal wear. After four overrides, the dream cycle proposes a
candidate rule. At dawn her mission group promotes it, and release 0.2.0 ships
with the rule in its capabilities.lock. Months later, engineers trace the
vibration to a faulty sensor, so the mission group recalls the rule and Brevet
flags release 0.2.0.
The same story in code
The agent here is a plain Python function; with a real framework you pass your agent object instead.
import brevet
from brevet.runner import EvalRunner
agent = brevet.wrap(triage_agent) # wrap the agent you already have
# Work and override: the agent drafts; the reviewer corrects the draft and says why.
result = agent.run("Pump P-301: vibration high during cleaning",
task_family="equipment_triage")
agent.record_final(result.task_id, "severity: major",
participant="human:qa.reviewer@example.com",
rationale="Vibration during cleaning is an early sign of seal wear.",
tags=["vibration-during-cleaning"])
# Dream: once the same override keeps recurring, it becomes a candidate.
agent.dream()
candidates = agent.dawn() # the dawn queue
rule = next(c for c in candidates if c.kind == "prompt_rule")
# Dawn: a named mission group promotes it. A dream:* approver is rejected.
agent.dawn(decide=(rule.capability_id, "promote"),
approver="mission_group:quality_team")
# Evals: replay the overrides as tests, before and after the change.
before = agent.evaluate()
# ...update your agent so that it follows the promoted rule...
after = agent.evaluate()
# Release: refused unless the conservative gate passes.
check = EvalRunner.compare(before, after)
agent.release(to_version="0.2.0", channel="trial",
approver="mission_group:quality_team",
delta_in=check["delta_held_in"], delta_out=check["delta_held_out"])
# Recall: the rule proves wrong. Then verify the whole evidence chain.
agent.recall(rule.capability_id, reason="The vibration came from a faulty sensor.",
issued_by="mission_group:quality_team")
agent.verify()
The full script is examples/pump_vibration.py, and ABOUT.md shows what it prints.
Quickstart
pip install brevet
brevet demo # the whole loop as one command
brevet playground # step through the loop in your browser
Everything runs on your own machine, with no model or network connection. To
run the example above, clone the repository and run
python examples/pump_vibration.py. For a guided, clickable tour, open
docs/demo.html in a browser.
Works with the agent you already have
brevet.wrap() recognises agents built with LangGraph, the Claude Agent SDK,
DeepAgents, AutoGen, LlamaIndex, Pydantic AI, the Google Agent Development Kit,
CrewAI and the OpenAI Agents SDK, and it accepts any Python function. Brevet
never changes the agent it wraps. uvx brevet mcp offers the whole loop to any
MCP client (ABOUT.md shows the setup), and
examples/claude-cowork uses it to govern what Claude
itself learns.
Project status
Brevet implements the whole loop and keeps every record, and a workspace can require every decision to be signed by its registered approvers. Some protections depend on the system you deploy it in, such as verifying who holds each key and anchoring the evidence chain outside the machine. ABOUT.md lists them, and the paper sets them out in full.
Learn more
- ABOUT.md: the seven stages, the authority ladder, supported frameworks, the MCP server and commands, how Brevet fits with CHAP and Metis, and how the repository is organised.
- GLOSSARY.md: every term, with its plain meaning first.
- SPEC.md: the rules any implementation must follow.
- BENCHMARK.md: the proposed governed-adaptation benchmark.
Citation
If you use Brevet in research, please cite the paper Brevet: Change Control for What Self-Evolving AI Agents Learn (Shahid, Suttie and Black, 2026). CITATION.cff gives the software citation.
License
Apache-2.0. See LICENSE. Brevet is a Brightbeam project.
Metadata
Release files for brevet 0.3.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| brevet-0.3.0.tar.gz | 124.9 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| brevet-0.3.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 211.5 kB
Release files / brevet-0.3.0.tar.gz
| Download URL | brevet-0.3.0.tar.gz |
|---|---|
| Size | 124.9 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
87dcf59ec24b4c19d17e3384f07e40a3e3af8f399a85078a20b1e92259361ca6
|
|
BLAKE2b-256 checksum How to use checksums |
950dfc8f598e6f3c990bb4809380bb8502e9cb4eac3fd1769b0a2b1c8cdb6e9a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.9.6
|
Release files / brevet-0.3.0-py3-none-any.whl
| Download URL | brevet-0.3.0-py3-none-any.whl |
|---|---|
| Size | 86.7 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
8dfa8d6311a06b3b829cc507ee3e2dc9dd4d8c0799c1b0ce714bfa67a7b49ee9
|
|
BLAKE2b-256 checksum How to use checksums |
4ee126bdf08c85af5ac2f2a2fd073b49a1699aa8595a4780b5185fd0b64764d4
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.9.6
|