Skip to main content

Governed Agent SDLC

Ship with agents. Keep humans in control.

Validate PyPI Python 3.11+ MIT License

Project website · Architecture · Workflow · CLI reference · Adoption guide

Governed Agent SDLC is a cross-platform toolkit for AI coding agents. It separates a tool-neutral workflow kernel from project profiles and vendor adapters, so the same approval, security, artifact, review, and QA rules can be applied to different technology stacks.

The project is intentionally human-in-the-loop. It helps agents work predictably; it does not grant an AI permission to approve, merge, release, or retrieve credentials.

Alpha status: the core workflow, Claude Code and Codex adapters, deterministic safety hooks, cross-platform validation, and PyPI Trusted Publishing are available. Interfaces may still evolve before 1.0.

What is included

  • Six tool-neutral roles: architect, planner, developer, reviewer, QA, and publisher.
  • A structured artifact lifecycle with explicit approval evidence and supersession.
  • A TOML project manifest for repository layout, profiles, commands, and protected areas.
  • A dependency-free Python CLI: init, generate, validate, doctor, and artifact commands.
  • Claude Code agent generation and safety hooks.
  • Native Codex project configuration and governed role generation.
  • Stack profiles for generic repositories, Python, .NET, and Nuxt.
  • Cross-platform tests and reusable GitHub Actions.

Quick start

Requires Python 3.11 or newer. Install the published package:

python -m pip install governed-agent-sdlc
agentkit --version
agentkit doctor

Upgrade an existing installation to this release:

python -m pip install --upgrade governed-agent-sdlc==0.3.0
agentkit --version
agentkit doctor

Version 0.3.0 makes review evaluate apply the project's [[policies]] and treats findings with a missing or unknown severity as medium. Give file findings canonical severities before upgrading if you relied on unknown values passing as info. Initialization remains additive; upgrading the Python package does not overwrite project configuration. See release notes for the full changes.

For local development:

python -m pip install -e .
agentkit doctor
agentkit validate
python -m unittest discover -s tests -v

Initialize another project:

agentkit init ../my-project --name my-project --adapter claude-code
cd ../my-project
agentkit doctor

Use --format json with validate, doctor, generation, migration, and artifact inspection commands for automation. Preview additive initialization or adapter generation with --dry-run.

Initialization is additive: existing AGENTS.md, manifest, core policy, hook, and adapter files are not overwritten. A fresh project receives the generic stack profiles and a minimal AGENTS.md so generated roles always have the instructions they reference.

Create and move a governed artifact:

agentkit artifact new spec add-search
agentkit artifact transition docs/agent/specs/<file>.md awaiting_approval
agentkit artifact transition docs/agent/specs/<file>.md approved \
  --approved-by "github:maintainer" \
  --evidence "https://github.com/org/repo/issues/123#issuecomment-..."

An agent must never supply approval metadata for itself. The human supplies the actor and durable evidence, and CI validates that the fields exist.

Project manifest

agentkit.toml or .agent/project.toml is the source of truth:

version = 1
protected_areas = ["authentication", "database-schema", "billing"]

[project]
name = "commerce"
topology = "monorepo"

[[repositories]]
id = "backend"
path = "services/api"
profiles = ["dotnet"]

[[repositories]]
id = "frontend"
path = "apps/web"
profiles = ["nuxt"]

[workflow]
require_spec = true
require_plan = true
require_review = true
require_qa = true

Repository paths are resolved from the manifest and must remain inside the project root. No machine or user-specific absolute path belongs in committed configuration.

Validation is strict and dependency-free. It rejects unsupported manifest versions and topology, missing workflow flags, invalid field types, duplicate repository identities or paths, escaping repository paths, and profile capabilities that are not provided by profiles/, adapters/, or the repository's GitHub integration.

Artifact validation also checks kind-specific parent gates, approval history for approved/active/ completed/superseded states, repository and protected-area references, timestamps, supersession, and metadata types. Artifact creation refuses filename collisions. Transitions made through the CLI are restricted to Markdown files below the active project's docs/agent/ directory.

Design boundaries

  • core/ is vendor-neutral and is the only source of workflow meaning.
  • profiles/ contain stack-specific commands and exclusions.
  • adapters/ and generated tool files translate the core; they do not redefine it.
  • hooks/ enforce deterministic safety rules. Prompts explain behavior but are not security controls.
  • Hook input is fail-closed: malformed input is denied, as are credential paths/environment dumps, force pushes, and direct protected-branch refspecs.
  • docs/agent/ holds project artifacts, not hidden agent memory.

See Architecture, Workflow, and Adopting Governed Agent SDLC.

Maturity

Version 0.1.1 is an alpha. Claude Code and Codex consume the same core contracts rather than introducing parallel policy files.

See CHANGELOG.md for release history and upgrade notes.

License

MIT. See LICENSE.

Release files for governed-agent-sdlc 0.3.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for governed-agent-sdlc 0.3.0
File Size Uploaded
governed_agent_sdlc-0.3.0.tar.gz 155.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for governed-agent-sdlc 0.3.0
File Interpreter ABI Platform
governed_agent_sdlc-0.3.0-py3-none-any.whl Python 3 none any Details

Total release size: 228.0 kB

Release files / governed_agent_sdlc-0.3.0.tar.gz

Download URL governed_agent_sdlc-0.3.0.tar.gz
Size 155.7 kB
Tags Source
SHA-256 checksum
How to use checksums
fbf3700ca703f14f749ad074399f19ec1e6eaede59d69674df9c6eeaa2bcc041
BLAKE2b-256 checksum
How to use checksums
e152e6530143911b87680d8d0e1b4611908c6917077a59ee4792c2bc49ff1486
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 24, 2026.

Transparency log

Release files / governed_agent_sdlc-0.3.0-py3-none-any.whl

Download URL governed_agent_sdlc-0.3.0-py3-none-any.whl
Size 72.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
548bcf7efcbaca2f7be08f085b24043795ae1b7cc8a7259b5003d9da3686a22c
BLAKE2b-256 checksum
How to use checksums
49516086cdc31a6b9452d096908c46b1c97844a23bd2da48dae03e6eb1aa965e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 24, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.3.0 This release

2 release files

0.2.0

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page