Skip to main content

governance-drift

Deterministic AI-agent governance drift detection — evidence-backed findings, stated coverage gaps, and SARIF output for CI.

Your organization has an approved baseline of AI agents (which agents, which models, which connectors) and a reality that drifts from it: vendors retire models that production agents still pin; agents appear that nobody approved. governance-drift detects that drift and reports it under rules that make the report trustworthy — every finding carries a source URI, JSON field path, and content hash; findings that can't be re-verified are dropped; and coverage gaps are stated rather than hidden.

This is the Python reference implementation. The same pipeline also runs as a Weft graph on WeaveMind Cloud (clonable, ~$0.03/run) with a human approval gate.

Install

pip install governance-drift          # the govdrift CLI (pyyaml only)
pip install "governance-drift[http]"  # + httpx, for wiring live sources in Python

Scope: govdrift scan reads local files. The [http] extra adds httpx and the http_fetcher building block for consumers who construct sources in Python against live Foundry/tenant endpoints — http_fetcher(url, client) takes a caller-owned client, so its lifecycle stays with you rather than with the CLI. A URL branch for govdrift scan is not shipped yet.

Scan

govdrift scan \
  --inventory approved.yaml \
  --foundry   foundry_models.json \
  --tenant    tenant_observed.json \
  --out       out/

Writes out/<date>-drift.md (human report), out/findings.sarif (SARIF 2.1.0), and out/hashes.json (cross-run source-change tracking). Exit code is 1 if any finding survived verification, else 0 — so it doubles as a CI gate.

Governance drift as a GitHub code-scanning check

govdrift emits SARIF, which GitHub ingests natively. Drop this in a workflow to turn unapproved-agent and retired-model findings into code-scanning alerts:

- run: govdrift scan --inventory approved.yaml --foundry foundry.json --out out/
  continue-on-error: true          # let SARIF upload run even when drift is found
- uses: github/codeql-action/upload-sarif@v3
  with:
    sarif_file: out/findings.sarif

What it checks

  • Model retirement — a vendor-retiring/deprecated model that an approved agent still pins. Severity scales with days remaining (≤30 critical, ≤90 high, ≤180 medium).
  • Unapproved agents — anything observed in the tenant that isn't in the approved baseline. HIGH by definition.

Every finding's evidence is re-resolved against the payload it came from before the report is written; a finding citing an unresolvable path is dropped and counted. Adapters are small classes implementing ChangeSource / InventorySource — Azure AI Foundry model lifecycle and inventory/tenant JSON-YAML ship today; add your own in ~40 lines.

License

MIT © Jeremy Gracey

Metadata

Release files for governance-drift 0.1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for governance-drift 0.1.1
File Size Uploaded
governance_drift-0.1.1.tar.gz 35.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for governance-drift 0.1.1
File Interpreter ABI Platform
governance_drift-0.1.1-py3-none-any.whl Python 3 none any Details

Total release size: 60.1 kB

Release files / governance_drift-0.1.1.tar.gz

Download URL governance_drift-0.1.1.tar.gz
Size 35.8 kB
Tags Source
SHA-256 checksum
How to use checksums
e0907daeedbc149aba1be77156ce7bd97437c434bafeba990e9c5eff7e2d4111
BLAKE2b-256 checksum
How to use checksums
14d8ff5f71a01b5443a0da19edd94aaac3b2cab0df958884af91e5017453d7e1
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 19, 2026.

Transparency log

Release files / governance_drift-0.1.1-py3-none-any.whl

Download URL governance_drift-0.1.1-py3-none-any.whl
Size 24.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
cbf05ef1f74a294fd014187e85e6d1f089c694b57d63080c2e5eaa505fcf38ea
BLAKE2b-256 checksum
How to use checksums
38cdea9ce0b6393837d3d0766cc73a1597048a51ab16bdbb8f2dda171bcd5ad2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 19, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.1 This release

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page