Briefcase AI SDK
Governance infrastructure for AI decisions: enforce controls, record context, replay later.
Install
pip install briefcase-ai
Quick Example
import briefcase
briefcase.observe("console") # send records to stderr (or "memory" / "runs.jsonl")
@briefcase.capture(decision_type="classify_text")
def classify(text: str) -> str:
return text.upper()
classify("hello world") # a decision record is emitted
capture works immediately — no briefcase.init() required. Call init() only
when you use the native runtime features (storage backends, snapshots). Without a
call to briefcase.observe(...) (or briefcase.setup(exporter=...)), @capture
records decisions but has nowhere to send them.
Exporters. briefcase.observe(...) accepts "console", "memory" (records
collected on exporter.records), a "*.jsonl" path, or any
briefcase.exporters.BaseExporter instance — subclass BaseExporter to ship
records to your own backend.
Evaluations and RL
Two bridges emit decision records from work that is not a single function call. Both use the exporter you already configured.
from briefcase.integrations.evals import EvalRun, from_inspect_log, replay
with EvalRun("gsm8k", model="claude-opus-5") as run: # one eval.case per case,
run.log_case("q1", inputs=q, outputs=a, passed=a == target) # one eval.run
print(run.summary()["pass_rate"])
replay(from_inspect_log("logs/2026-08-12_gsm8k.eval")) # inspect-ai .json/.eval
The parsers are stdlib only and never import the eval framework, so a log can be
replayed on a machine that has neither installed. See
examples/eval_runs/.
from briefcase.integrations.gym import GuardrailGymEnv, capture_episodes
env = GuardrailGymEnv(guardrail, tasks, injections) # a guardrail as a gym.Env
env = capture_episodes(env) # rl.step / rl.episode records
Needs pip install briefcase-ai[gym]. See examples/rl_gym/.
capture_episodes exports on a background thread by default, since step capture
is on the hot path. A script that exits right after close() can lose its
records; pass capture_episodes(env, async_capture=False) in short runs.
EvalRun already defaults to async_capture=False for that reason.
Logging
The library is silent by default (it installs only a NullHandler). Turn on
visible logs explicitly:
import briefcase
briefcase.enable_logging("DEBUG") # or set BRIEFCASE_LOG_LEVEL=DEBUG
Using with AI tools (Cursor, Claude Code, Codex, …)
This repo ships machine-readable usage guidance: llms.txt /
llms-full.txt, an AGENTS.md, and copy-paste
editor rules under docs/llm/. An MCP server is available via
pip install briefcase-ai[mcp] then briefcase-mcp.
Extras
| Extra | Description |
|---|---|
replay |
Deterministic replay engine for recorded decisions |
drift |
Drift scoring and cost calculation for model outputs |
sanitize |
Built-in PII redaction utilities |
otel |
OpenTelemetry helpers |
storage |
Rust-backed SQLite storage engine |
validate |
Prompt validation engine |
guardrails |
Guardrail framework, wrappers, and registries |
rag |
Versioned embedding pipeline and instrumented retrieval |
rag-chroma / rag-pinecone / rag-weaviate |
Vector-store adapters (each adds its client) |
correlation |
Workflow and trace correlation helpers |
external |
External data snapshot tracking |
events |
Structured event type and emitter interface |
kafka / webhook / gcp-logging |
Event transports and the Cloud Logging exporter (webhook is stdlib) |
routing |
Router protocol, agent router, versioned policy registry |
opa |
OPA HTTP router with cached decisions and internal-router fallback (adds httpx) |
lakefs |
lakeFS versioned storage client, branch manager, lineage, staged commits |
vcs |
VCS client base protocol plus DVC, Nessie, Pachyderm, ArtiVC, DuckLake, Iceberg, and git-LFS adapters |
vcs-dvc / vcs-pachyderm / vcs-ducklake / vcs-iceberg |
Per-provider VCS clients (the rest are HTTP/subprocess based) |
gym |
Gymnasium bridge: guardrail env adapter and RL episode capture |
evals |
Eval-harness bridge: EvalRun logger, inspect-ai / lm-eval parsers (adds zstandard for .eval archives on Python < 3.14) |
bitemporal |
Bitemporal evidence store, as-of views, append-only corrections |
bitemporal-iceberg |
pyiceberg-backed bitemporal store (any supported catalog) |
bitemporal-glue |
AWS Glue catalog auth for the Iceberg backend (adds boto3) |
kdb |
kdb+ bitemporal backend (adds KX-licensed pykx; excluded from all) |
compliance |
Examiner bundles joining decision, evidence, and policy version |
compliance-kms |
KMS-signed examiner bundles against your own AWS KMS key (adds boto3) |
controls |
Gateway, quota, throttle classification, and retry (no extra dependencies) |
integrity |
Tamper-evident hash chains, canonical JSON, Ed25519 signing over digests and JSON manifests (signing adds pynacl) |
langchain / crewai / llamaindex / autogen / ag2 / pageindex / openai-agents |
Framework auto-instrumentation via briefcase.auto (each adds its framework) |
mcp |
MCP server (briefcase-mcp) exposing the SDK to AI agents |
dev |
Dev tooling: pytest, mypy, flake8, moto |
all |
Installs every optional extra listed above except kdb |
Most features are native- or pure-Python-backed and ship with the base package —
their extras (replay, drift, sanitize, storage, routing, bitemporal,
compliance, …) are convenience groupings that pull in no additional
dependencies. The extras that install third-party packages are otel,
lakefs, bitemporal-iceberg, bitemporal-glue, kdb, compliance-kms,
gym, evals, mcp, opa, kafka, gcp-logging, integrity, the rag-* and vcs-*
store adapters, and the framework auto-instrumentation extras.
Managed platform
Every library feature runs against infrastructure you own: storage
backends (in-memory, SQLite, pyiceberg, Glue-authenticated Iceberg, kdb+),
KMS-signed examiner bundles, guardrails, RBAC/ABAC/OPA policy evaluation,
routing, replay, framework auto-instrumentation (briefcase.auto), lakeFS
branching and lineage, vector-store and VCS adapters, event transports, and
the controls layer, in both Python and TypeScript
(@briefcase-ai/controls).
The commercial offering is the hosted platform, not gated code: a managed control plane, catalog provisioning and credential brokering, operational runbooks (DR failover, catalog migration, key rotation), certified retention and regulator attestations, licensed market-data ingest (Bloomberg BPIPE, Refinitiv, ICE), and SOC 2 / FedRAMP posture with SLA support.
Contact sales@briefcasebrain.com for the managed platform.
Telemetry
The SDK can report anonymous usage metrics (SDK version, OS, architecture, backend
type) to help prioritize development. No personal data or decision content is ever
collected. Telemetry is only transmitted when a collection endpoint is configured
via BRIEFCASE_API_URL (it defaults to localhost, i.e. a no-op), and you can
disable it entirely at any time:
export BRIEFCASE_TELEMETRY=0 # also accepts: false, no, off (case-insensitive)
Links
- Docs: briefcaseai.io
- GitHub: github.com/briefcasebrain/briefcase-ai-sdk
- Contributing: CONTRIBUTING.md
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distributions
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file briefcase_ai-4.4.0.tar.gz.
File metadata
- Download URL: briefcase_ai-4.4.0.tar.gz
- Upload date:
- Size: 336.9 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
ed4765e1a77f508167f170deae1928c7c8a3be55a5c67137c8a7c34cbeda850d
|
|
| MD5 |
cd7587dd3578ed5689ad7866edcc8d8a
|
|
| BLAKE2b-256 |
2c760870089391bfd279d2607ba0db0950d3cb8d2a1b14e3c2e2174d0e9ed736
|
Provenance
The following attestation bundles were made for briefcase_ai-4.4.0.tar.gz:
Publisher:
publish.yml on briefcasebrain/briefcase-ai-sdk
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
briefcase_ai-4.4.0.tar.gz -
Subject digest:
ed4765e1a77f508167f170deae1928c7c8a3be55a5c67137c8a7c34cbeda850d - Sigstore transparency entry: 2494596514
- Sigstore integration time:
-
Permalink:
briefcasebrain/briefcase-ai-sdk@5ae160efaf544f4b875f8ab1caa21b9b4fd06e96 -
Branch / Tag:
refs/tags/v4.4.0 - Owner: https://github.com/briefcasebrain
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish.yml@5ae160efaf544f4b875f8ab1caa21b9b4fd06e96 -
Trigger Event:
push
-
Statement type:
File details
Details for the file briefcase_ai-4.4.0-cp39-abi3-win_amd64.whl.
File metadata
- Download URL: briefcase_ai-4.4.0-cp39-abi3-win_amd64.whl
- Upload date:
- Size: 7.6 MB
- Tags: CPython 3.9+, Windows x86-64
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
fe8cb2b3f9b0d6c9fe6378d463ea25e6e9293ceadd6fe959549a86fe3a3edafc
|
|
| MD5 |
591e21edfd8eb989a757b185bcd9cbe8
|
|
| BLAKE2b-256 |
de99341f619fc0eb46b8574a27908588df38f1250f01eec9141a88c0ae928192
|
Provenance
The following attestation bundles were made for briefcase_ai-4.4.0-cp39-abi3-win_amd64.whl:
Publisher:
publish.yml on briefcasebrain/briefcase-ai-sdk
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
briefcase_ai-4.4.0-cp39-abi3-win_amd64.whl -
Subject digest:
fe8cb2b3f9b0d6c9fe6378d463ea25e6e9293ceadd6fe959549a86fe3a3edafc - Sigstore transparency entry: 2494596538
- Sigstore integration time:
-
Permalink:
briefcasebrain/briefcase-ai-sdk@5ae160efaf544f4b875f8ab1caa21b9b4fd06e96 -
Branch / Tag:
refs/tags/v4.4.0 - Owner: https://github.com/briefcasebrain
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish.yml@5ae160efaf544f4b875f8ab1caa21b9b4fd06e96 -
Trigger Event:
push
-
Statement type:
File details
Details for the file briefcase_ai-4.4.0-cp39-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl.
File metadata
- Download URL: briefcase_ai-4.4.0-cp39-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
- Upload date:
- Size: 8.3 MB
- Tags: CPython 3.9+, manylinux: glibc 2.17+ x86-64
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
525ab3515c483a19a2da71d35beea8a1f2dda3cb4dca78fa58ccfae904330d22
|
|
| MD5 |
cdf47d835fe6611ec408962f97ac77bb
|
|
| BLAKE2b-256 |
e9286beafab02100f2c9ae58602e4d29270e53302068b20a1cb8eda4159a81e0
|
Provenance
The following attestation bundles were made for briefcase_ai-4.4.0-cp39-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl:
Publisher:
publish.yml on briefcasebrain/briefcase-ai-sdk
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
briefcase_ai-4.4.0-cp39-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl -
Subject digest:
525ab3515c483a19a2da71d35beea8a1f2dda3cb4dca78fa58ccfae904330d22 - Sigstore transparency entry: 2494596523
- Sigstore integration time:
-
Permalink:
briefcasebrain/briefcase-ai-sdk@5ae160efaf544f4b875f8ab1caa21b9b4fd06e96 -
Branch / Tag:
refs/tags/v4.4.0 - Owner: https://github.com/briefcasebrain
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish.yml@5ae160efaf544f4b875f8ab1caa21b9b4fd06e96 -
Trigger Event:
push
-
Statement type:
File details
Details for the file briefcase_ai-4.4.0-cp39-abi3-macosx_11_0_arm64.whl.
File metadata
- Download URL: briefcase_ai-4.4.0-cp39-abi3-macosx_11_0_arm64.whl
- Upload date:
- Size: 7.9 MB
- Tags: CPython 3.9+, macOS 11.0+ ARM64
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
0f642b6c696f5201fbbbd9c6b98d1a87fe723ad291a08ee7a2c28a4d72b77361
|
|
| MD5 |
56a1e3d7a409032af61a648b644821e9
|
|
| BLAKE2b-256 |
cfb359f1443d442d278f690a1cd776d6b533f7a09db05e088c611c27a04d6794
|
Provenance
The following attestation bundles were made for briefcase_ai-4.4.0-cp39-abi3-macosx_11_0_arm64.whl:
Publisher:
publish.yml on briefcasebrain/briefcase-ai-sdk
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
briefcase_ai-4.4.0-cp39-abi3-macosx_11_0_arm64.whl -
Subject digest:
0f642b6c696f5201fbbbd9c6b98d1a87fe723ad291a08ee7a2c28a4d72b77361 - Sigstore transparency entry: 2494596544
- Sigstore integration time:
-
Permalink:
briefcasebrain/briefcase-ai-sdk@5ae160efaf544f4b875f8ab1caa21b9b4fd06e96 -
Branch / Tag:
refs/tags/v4.4.0 - Owner: https://github.com/briefcasebrain
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish.yml@5ae160efaf544f4b875f8ab1caa21b9b4fd06e96 -
Trigger Event:
push
-
Statement type:
File details
Details for the file briefcase_ai-4.4.0-cp39-abi3-macosx_10_12_x86_64.whl.
File metadata
- Download URL: briefcase_ai-4.4.0-cp39-abi3-macosx_10_12_x86_64.whl
- Upload date:
- Size: 8.0 MB
- Tags: CPython 3.9+, macOS 10.12+ x86-64
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
a338006797c21d464e250b57478f43f8c8125a7fe298eaadd34d49fc95cf5b50
|
|
| MD5 |
c5f0895f3126df7716733832631731d0
|
|
| BLAKE2b-256 |
5d4560e8569772971ccc06dfde943435c66850b352dcb597e2f5dd29b0218e3b
|
Provenance
The following attestation bundles were made for briefcase_ai-4.4.0-cp39-abi3-macosx_10_12_x86_64.whl:
Publisher:
publish.yml on briefcasebrain/briefcase-ai-sdk
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
briefcase_ai-4.4.0-cp39-abi3-macosx_10_12_x86_64.whl -
Subject digest:
a338006797c21d464e250b57478f43f8c8125a7fe298eaadd34d49fc95cf5b50 - Sigstore transparency entry: 2494596521
- Sigstore integration time:
-
Permalink:
briefcasebrain/briefcase-ai-sdk@5ae160efaf544f4b875f8ab1caa21b9b4fd06e96 -
Branch / Tag:
refs/tags/v4.4.0 - Owner: https://github.com/briefcasebrain
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish.yml@5ae160efaf544f4b875f8ab1caa21b9b4fd06e96 -
Trigger Event:
push
-
Statement type: