Expflow
Expflow is a schema-governed, local-first workflow ownership and observability platform for projects where people, agents, and tools produce changing artifact trees.
Expflow records what changed, which evidence was trusted, which decisions remain durable, and which outputs can be inspected, regenerated, restored, or reused.
Current release candidate:
v1.1.0.
What Expflow Tracks
Expflow separates five concerns that are often blurred in automated work:
- material files before and after workflow activity;
- accepted authority sources for the work;
- attributed claims, decisions, conflicts, and review requests;
- workflow inputs, outputs, projections, regeneration attempts, equivalence evaluations, and reuse evidence;
- local security, migration, package, and proof evidence.
Material output does not imply semantic acceptance, workflow completion, or reuse permission. Expflow keeps those records separate.
Release Scope
Expflow v1.1.0 covers the local core surfaces implemented in this repository:
- four ordinary commands:
expflow init,expflow sync,expflow status, andexpflow restore; - local
.expflow/material storage with immutable object, node-revision, tree-revision, receipt, validation, change, and material-head records; - complete-tree sync, drift status, tree/node restore, scoped path selection, explicit identity directives, and digest-similarity proposals without silent identity preservation;
- project locks, operation-scoped staging, recoverable init/restore intents, stale-lock classification, causal tree/receipt head repair, restore recovery, and restored-tree digest verification;
- library runtimes for authority sources, semantic decisions, workflow boundaries, projections, regeneration/equivalence, structural reuse, security controls, migration evidence, and the native extension host;
- stable, bounded, versioned read models over advanced authority, semantic, workflow, projection, reproduction, and material linkage records;
- attributed evidence intake, quarantine, duplicate detection, source proposals, correspondence, conflict, artifact-candidate, and decision helpers through the TypeScript library;
- deterministic portable workflow package export, offline validation, import planning, collision-safe import, and resume-state reporting through the TypeScript library;
- repository-contract checks for immutable architecture sources, schemas, examples, fixtures, registries, package boundaries, and end-to-end proof.
Quickstart
With the npm package available from the public registry:
npm install -g expflow
expflow init
expflow status
The npm package exposes the expflow CLI and TypeScript library exports. The Python package is a separate hook scaffold with read-only repository architecture discovery; it does not dispatch or execute hooks.
Installation
After verified registry publication, install the primary Expflow CLI and TypeScript package with:
npm install -g expflow
Install the Python hook scaffold separately with:
pip install expflow-hooks
expflow-hooks is not the primary Expflow CLI implementation. It exposes the limited Python hook/scaffold package and expflow_hooks import surface.
Workflow
- Run
expflow initto create local Expflow state. - Change files in the project tree.
- Run
expflow statusorexpflow sync --dry-runto preview pending changes. - Run
expflow syncto record a complete material tree revision. - Run
expflow status --historyorexpflow status --node-history <path>to find restore references. - Run
expflow restore <reference> --dry-runbefore restoring a recorded tree or node revision.
Gate C ownership/reproduction behavior, Phase 4 evidence intake/reconciliation behavior, Phase 5 portable workflow package behavior, and Gate D security/migration behavior are available through library runtimes rather than additional ordinary commands.
Commands
| Command | Purpose |
|---|---|
expflow init |
Initialize local Expflow project state. |
expflow sync |
Preview or commit a complete material tree revision. |
expflow status |
Report drift, current project version, history, and restore references. |
expflow restore |
Preview or restore a recorded material tree or node revision. |
Useful Phase 1 options:
expflow sync --dry-runpreviews path-level changes without committing.expflow status --historylists recent tree restore references.expflow status --node-history <path>lists node restore references for a tracked path.expflow restore <reference> --dry-runpreviews affected paths and conflicting drift.expflow restore <reference> --forceexplicitly overwrites conflicting unrecorded drift.
What Expflow Delegates
Expflow core intentionally does not implement every surrounding integration surface.
- Adapter inspection and reconciliation: belongs in separately versioned adapter packages.
- External revision cursors and idempotency: outside the core repository.
- Guerilla hook dispatch: compatibility reference only, not an Expflow core runtime.
- Network services, databases, and brokers: absent from the local core.
- Archive extraction and generated-code execution: blocked by the Gate D security posture.
- Pilots and empirical evaluation: one repository-owned pilot completed in Phase 7. Broader external pilots, comparative evaluation, multi-user evidence, and adoption evidence remain future work.
Repository Map
docs/architecture/contains immutable architecture sources.docs/internal/contains current Build Week governance, status, prompts, and activation records.docs/external/contains current product overviews and narratives.docs/releases/v1.1.0/contains the frozen v1.1.0 release documentation record.apps/gui/contains the local Expflow GUI client and server.schemas/andexamples/mirror the architecture schemas and examples for tooling.src/contains the TypeScript package, CLI, GUI bridge, read-model runtime, evidence runtime, portable package runtime, material runtime, Gate C library runtimes, Gate D security/migration runtimes, and contract tooling.python/expflow_hooks/contains the Python hook-package scaffold and repository-only schema discovery.tests/contains repository-contract, material-runtime, evidence-intake, authority, Gate C ownership/reproduction, Gate D security/migration, package, and end-to-end proof tests.
For implementation status, see docs/internal/CURRENT_STATUS_MATRIX.md. For contributor setup and validation commands, see README_DEV.md.
Validation
npm ci
npm run validate
python -m pip install -e ".[dev]"
python -m pytest
python -m build --wheel
python tests/contracts/verify_python_wheel.py
Documentation
- v1.1.0 GitHub release note
- v1 compatibility promise
- Release publishing policy
- Current status matrix
- Developer guide
- Security policy
License
Expflow is released under the MIT License.
Release files for expflow-hooks 1.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| expflow_hooks-1.1.0.tar.gz | 6.2 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| expflow_hooks-1.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 12.5 kB
Release files / expflow_hooks-1.1.0.tar.gz
| Download URL | expflow_hooks-1.1.0.tar.gz |
|---|---|
| Size | 6.2 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
289787c4fdb17b0671041682a55b15e89c4ca6dfdb36b055294219c9ed13265e
|
|
BLAKE2b-256 checksum How to use checksums |
d15eb25b6c46a1f5587c881f457444f6f22ec5b845208220ea123f70fa595cf9
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.13
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 23, 2026.
Transparency logRelease files / expflow_hooks-1.1.0-py3-none-any.whl
| Download URL | expflow_hooks-1.1.0-py3-none-any.whl |
|---|---|
| Size | 6.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
0f6283734eb7ef1a42893aab3eb8a6675ad763b0c456aaac5b10ad0a49713900
|
|
BLAKE2b-256 checksum How to use checksums |
ff28e8a9d5d965e0663ebe0e72cadbdac612cbf440d43501e9cfd2c132a5e1e8
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.13
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 23, 2026.
Transparency log