governance-core
Reusable multi-agent governance infrastructure for Claude Code projects.
Drop-in package providing a complete governance layer (constitution clauses, safety hooks, proposal workflow, wrap-up discipline, cross-clone sync) so you can focus on your project's business logic instead of re-inventing multi-agent coordination from scratch.
What you get
Install this package + run governance-core install in a new project, and
your project immediately has:
- 5 safety hooks (PreToolUse + PostToolUse): scope-guard, edit-write-guard,
session-boundary-guard, command-guard, sensitive-data-guard — all configurable
via
.governance/config.json - Proposal workflow (
/proposalskill): classify gate, draft / submit / approve / complete / archive state machine with audit trail - Wrap-up discipline (
/wrap-upskill): STATE.md + git + knowledge publishing + skill learning in one command - Constitution iteration (
/iterate-constitutionskill): structured constitutional change workflow with red-line audit - Cross-clone coordination (
/sync-infra,/sync-repos): physical-files sync + cross-repo git operations - 17 constitution clauses (
art_00..art_16+ appendix) covering ritual, config management, contracts, scope governance, test/prod unification, git discipline, artifacts, constitutional protection, wrap-up discipline, memory staleness, etc.
Authorization
governance-core is source-available: you may read, audit, and fork the
source freely. Using it to govern a project — running governance-core install / upgrade — requires a valid authorization code issued by the
maintainer. install verifies the code offline (no network) against a public
key bundled in the package; without a valid code the governance layer is not
materialized.
install also requires candidate-uplink consent: improved skills, hooks,
and mechanisms detected in your project may be packaged as candidates and
uploaded to governance-core's public repository for review. In the current
version this consent is mandatory — declining it aborts the install.
governance-core install --project-root . --auth-code GC1.<...> --accept-candidate-uplink
To obtain an authorization code, contact the maintainer. See LICENSE for terms.
Quick start
This package is one half of a 2-piece distribution. The other half is multi-agent-template — a cookiecutter template + bootstrap CLI that generates a new project skeleton.
Typical workflow:
# One-time setup (per machine)
pip install cookiecutter
pip install governance-core
pip install multi-agent-bootstrap
# Per-project: one-line bootstrap
multi-agent-bootstrap new my-project \
--agents core,data \
--ritual-phrase "Acknowledged"
# Verify
cd ~/workshop-claude/my-project
governance-core doctor --project-root .
See docs/architecture.md for the full picture (generic vs business boundary, config injection mechanism, upgrade flow, cross-clone coordination).
Standalone CLI usage
You can also install governance-core directly into an existing multi-agent project (without cookiecutter):
cd /path/to/your/project
pip install governance-core
# Write .governance/config.json with your project config
mkdir -p .governance
cat > .governance/config.json <<EOF
{
"project_name": "my-project",
"ritual_phrase": "OK",
"core_agent_name": "core",
"agents": [
{"name": "core", "branch": "master", "clone_dir": "agent-core"}
]
}
EOF
# Render clauses + install hooks/skills (requires an authorization code)
governance-core install --project-root . --auth-code GC1.<...> --accept-candidate-uplink
# Validate
governance-core doctor --project-root .
Subsequent updates: git pull this repo, pip install -e . --upgrade,
then governance-core upgrade --project-root /path/to/your/project (this
preserves your .governance/config.json but refreshes clauses/hooks/skills).
Example content disclaimer
Some clauses and knowledge docs in this package contain examples drawn from
the upstream project where governance-core was first developed (domain
terminology, pipeline names, broker/API references, agent name conventions).
These are explanatory examples, not requirements. Your project's
.governance/config.json supplies its own agent names, ritual phrase, and
clause keywords; the package's logic is project-agnostic.
A v1.0 release will template-ize all example tables; v0.1.0 ships with disclaimers attached to mixed clauses and methodology docs.
Project status
v0.1.0-alpha (2026-05):
- API may break between minor versions (0.1.x)
- Stable from 1.0.0 onwards
- Bug reports + PRs welcome
License
MIT — see LICENSE.
Related
- multi-agent-template — companion cookiecutter template + bootstrap CLI
- Trade Agent (the project where this package was first developed) — private
Metadata
Release files for governance-core 0.39.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| governance_core-0.39.0.tar.gz | 443.7 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| governance_core-0.39.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 999.7 kB
Release files / governance_core-0.39.0.tar.gz
| Download URL | governance_core-0.39.0.tar.gz |
|---|---|
| Size | 443.7 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
93b23d81eb111d69a80a384bb6cc0fa2c55ab47993a7915439166f68c693d2a5
|
|
BLAKE2b-256 checksum How to use checksums |
0db041e0627e48b4ba46e85d3d72369df5181d323acfd46962b156cb42eb5227
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 8, 2026.
Transparency logRelease files / governance_core-0.39.0-py3-none-any.whl
| Download URL | governance_core-0.39.0-py3-none-any.whl |
|---|---|
| Size | 556.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
7ba16d0ee6fc6a25c7017c2cde9d21cd0c630fecb30144ee16d32970a7d1d66b
|
|
BLAKE2b-256 checksum How to use checksums |
7ac08b12e758c04b3f3bdaec83c0f143b47ab785ca1087beb3264e5c2bf7749f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 8, 2026.
Transparency log