Skip to main content

govern — the missing layer, installable

Every AI coding agent ships code and asks you to trust it. govern makes the trust measurable instead: receipts with re-runnable evidence, a measured-only calibration ledger, graduated per-class autonomy gates, and a kill switch — in any repo, with any agent (Claude Code, Cursor, Codex, humans). Stdlib-only Python, no model, no cloud, nothing to phone home to.

Extracted from the production loop that governs the Titan repository, where the same arithmetic earned three change classes automerge eligibility on measured track record. The extraction is pinned byte-identical to the source by a parity contract run in CI against the live 130+-row ledger.

Install

pip install ./packages/govern     # or pipx install govern-kit
govern init                       # idempotent; never overwrites existing files

init drops: .govern.toml (conventions), a receipt template (the evidence contract), an empty measured ledger, a CI workflow (gate as a PR check, score-on-merge), and the GOVERN_STOP kill-switch doc.

The loop

  1. A change ships with a receipt: what changed, the claimed verdict, a confidence, and a ### How measured block of hermetic commands.
  2. After the receipt is human-merged (govern check-merged refuses working-tree or doctored copies), govern score re-runs the evidence verbatim against merged main and appends a scored_by="measured" row. Self-reported verdicts can never move the measured ledger.
  3. govern gate computes TRUST/GATE overall and per change class: a class earns auto-merge ELIGIBLE only at ≥95% high-confidence hit-rate over a ≥10-claim recency window — judged per class, so one class's burst cannot evict another's track record.
  4. touch GOVERN_STOP halts every gated automation instantly. The gate refusing while that file exists is the contract.

Anti-gaming invariants (all inherited from production incidents)

  • Merged-only scoring — no credit for work that never survived review.
  • Content-hash guard — the scored receipt must be byte-identical to the merged one.
  • Invariant-pin exclusion — a receipt measured only by tests its own PR introduced is a tautology: recorded, flagged, never counted toward TRUST.
  • In-place rescores — rewriting a row preserves ledger order so the recency window cannot be gamed by remove-and-append.
  • Sticky pins — automated rescores can never un-pin an adjudicated row.
  • Goodhart markers — excluded receipts are dropped before windowing.

Signature layers, honestly described

  • HMAC (sig) — proves the ledger wasn't edited by anyone without the key. The key-holder is still you: this convinces your own CI, not an auditor at arm's length.
  • SSH (ssh_sig) — anyone verifies rows against the public key you publish in .govern/allowed_signers, using stock ssh-keygen. Backdating detection relies on the ledger living in public git history; the signature alone proves authorship and integrity, not time.

What this package is — and is not

This package is the trust layer: it scores receipts, keeps the measured ledger, and computes graduated-autonomy gates. It contains no agent, no model, and no execution engine. SignalBrain Forge runs governed change control as a product; the Titan runtime that earned this kit's reference track record is private. Installing govern-kit gives you the referee — what you build on top of it is yours.

Commands

govern score docs/improvements/0001-fix.md   # or --all, or --rescore
govern gate                                  # exit 0 = TRUST
govern gate --class bugfix                   # exit 0 = that class is ELIGIBLE
govern status                                # one-screen scoreboard
govern check-merged <receipt>                # Track-1 guard, exit 0 = scoreable
govern init                                  # install into this repo

Metadata

Release files for govern-kit 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for govern-kit 0.1.0
File Size Uploaded
govern_kit-0.1.0.tar.gz 20.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for govern-kit 0.1.0
File Interpreter ABI Platform
govern_kit-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 44.4 kB

Release files / govern_kit-0.1.0.tar.gz

Download URL govern_kit-0.1.0.tar.gz
Size 20.7 kB
Tags Source
SHA-256 checksum
How to use checksums
f7ec1b05f64157230b40a16f8a21520525536ae69f12f607ad9e9c03263a97a9
BLAKE2b-256 checksum
How to use checksums
d5d475b4b0e5d9f55b11d1e638eccb2c4097768b76cd1da803666467336e98d3
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.12.3

Release files / govern_kit-0.1.0-py3-none-any.whl

Download URL govern_kit-0.1.0-py3-none-any.whl
Size 23.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
b4fd8e943e0573e7c06a27c2a85e18099d60df96b3ba9e2ed77d979108785c15
BLAKE2b-256 checksum
How to use checksums
b0529d0bfb27da782db26c2c6db7b3e5a71946eae7e17fe871876702145caa5a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.12.3

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page