Skip to main content

governance-core

PyPI License

Reusable multi-agent governance infrastructure for Claude Code projects.

Drop-in package providing a complete governance layer (constitution clauses, safety hooks, proposal workflow, wrap-up discipline, cross-clone sync) so you can focus on your project's business logic instead of re-inventing multi-agent coordination from scratch.

What you get

Install this package + run governance-core install in a new project, and your project immediately has:

  • 5 safety hooks (PreToolUse + PostToolUse): scope-guard, edit-write-guard, session-boundary-guard, command-guard, sensitive-data-guard — all configurable via .governance/config.json
  • Proposal workflow (/proposal skill): classify gate, draft / submit / approve / complete / archive state machine with audit trail
  • Wrap-up discipline (/wrap-up skill): STATE.md + git + knowledge publishing + skill learning in one command
  • Constitution iteration (/iterate-constitution skill): structured constitutional change workflow with red-line audit
  • Cross-clone coordination (/sync-infra, /sync-repos): physical-files sync + cross-repo git operations
  • 17 constitution clauses (art_00..art_16 + appendix) covering ritual, config management, contracts, scope governance, test/prod unification, git discipline, artifacts, constitutional protection, wrap-up discipline, memory staleness, etc.

Authorization

governance-core is source-available: you may read, audit, and fork the source freely. Using it to govern a project — running governance-core install / upgrade — requires a valid authorization code issued by the maintainer. install verifies the code offline (no network) against a public key bundled in the package; without a valid code the governance layer is not materialized.

install also requires candidate-uplink consent: improved skills, hooks, and mechanisms detected in your project may be packaged as candidates and uploaded to governance-core's public repository for review. In the current version this consent is mandatory — declining it aborts the install.

governance-core install --project-root . --auth-code GC1.<...> --accept-candidate-uplink

To obtain an authorization code, contact the maintainer. See LICENSE for terms.

Quick start

This package is one half of a 2-piece distribution. The other half is multi-agent-template — a cookiecutter template + bootstrap CLI that generates a new project skeleton.

Typical workflow:

# One-time setup (per machine)
pip install cookiecutter
pip install governance-core
pip install multi-agent-bootstrap

# Per-project: one-line bootstrap
multi-agent-bootstrap new my-project \
    --agents core,data \
    --ritual-phrase "Acknowledged"

# Verify
cd ~/workshop-claude/my-project
governance-core doctor --project-root .

See docs/architecture.md for the full picture (generic vs business boundary, config injection mechanism, upgrade flow, cross-clone coordination).

Standalone CLI usage

You can also install governance-core directly into an existing multi-agent project (without cookiecutter):

cd /path/to/your/project
pip install governance-core

# Write .governance/config.json with your project config
mkdir -p .governance
cat > .governance/config.json <<EOF
{
  "project_name": "my-project",
  "ritual_phrase": "OK",
  "core_agent_name": "core",
  "agents": [
    {"name": "core", "branch": "master", "clone_dir": "agent-core"}
  ]
}
EOF

# Render clauses + install hooks/skills (requires an authorization code)
governance-core install --project-root . --auth-code GC1.<...> --accept-candidate-uplink

# Validate
governance-core doctor --project-root .

Subsequent updates: git pull this repo, pip install -e . --upgrade, then governance-core upgrade --project-root /path/to/your/project (this preserves your .governance/config.json but refreshes clauses/hooks/skills).

Example content disclaimer

Some clauses and knowledge docs in this package contain examples drawn from the upstream project where governance-core was first developed (domain terminology, pipeline names, broker/API references, agent name conventions). These are explanatory examples, not requirements. Your project's .governance/config.json supplies its own agent names, ritual phrase, and clause keywords; the package's logic is project-agnostic.

A v1.0 release will template-ize all example tables; v0.1.0 ships with disclaimers attached to mixed clauses and methodology docs.

Project status

v0.1.0-alpha (2026-05):

  • API may break between minor versions (0.1.x)
  • Stable from 1.0.0 onwards
  • Bug reports + PRs welcome

License

MIT — see LICENSE.

  • multi-agent-template — companion cookiecutter template + bootstrap CLI
  • Trade Agent (the project where this package was first developed) — private

Metadata

Release files for governance-core 0.42.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for governance-core 0.42.0
File Size Uploaded
governance_core-0.42.0.tar.gz 465.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for governance-core 0.42.0
File Interpreter ABI Platform
governance_core-0.42.0-py3-none-any.whl Python 3 none any Details

Total release size: 1.0 MB

Release files / governance_core-0.42.0.tar.gz

Download URL governance_core-0.42.0.tar.gz
Size 465.6 kB
Tags Source
SHA-256 checksum
How to use checksums
36ea3a9c50dd085002996a8c44f48036f3ef61c940e609cfc978784937477b23
BLAKE2b-256 checksum
How to use checksums
131faeb656db5ff82252100ff8803ddfe2f121ba1cd38647906e24c90f54d978
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 15, 2026.

Transparency log

Release files / governance_core-0.42.0-py3-none-any.whl

Download URL governance_core-0.42.0-py3-none-any.whl
Size 579.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
29a7023bbe249547d28511e12b86b6421234ac5c9848c6ddc06e435101e08059
BLAKE2b-256 checksum
How to use checksums
d3137171248c615ae349e36075857b68dadcaa6c410934e59ec778f0d57130c9
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 15, 2026.

Transparency log

Release history Release notifications | RSS feed

0.42.1

2 release files

This release

0.42.0 This release

2 release files

0.41.1

2 release files

0.41.0

2 release files

0.40.3

2 release files

0.38.4

2 release files

0.38.3

2 release files

0.38.2

2 release files

0.38.1

2 release files

0.38.0

2 release files

0.37.0

2 release files

0.36.0

2 release files

0.35.0

2 release files

0.33.0

2 release files

0.32.0

2 release files

0.31.0

2 release files

0.30.0

2 release files

0.29.0

2 release files

0.28.0

2 release files

0.27.0

2 release files

0.26.0

2 release files

0.20.0

2 release files

0.17.0

2 release files

0.9.0

2 release files

0.8.0

2 release files

0.7.0

2 release files

0.6.0

2 release files

0.5.0

2 release files

0.4.0

2 release files

0.3.0

2 release files

0.2.1

2 release files

0.2.0

2 release files

0.1.6

2 release files

0.1.5

2 release files

0.1.4

2 release files

0.1.3

2 release files

0.1.2

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page