Skip to main content

Developer-first model inventory and governance framework for SR 11-7, EU AI Act, and NIST AI RMF compliance

Project description

model-ledger

git for models — know what models you have deployed, where they run, what they depend on, and what changed.

CI License Python PyPI Downloads Docs

📖 Documentation · Quickstart · Concepts · Governance


model-ledger is a model inventory for any organization with deployed models. It discovers models, heuristic rules, and ETL across your platforms, maps the dependency graph automatically, and records every change as an immutable event. Unlike registries tied to a single platform (MLflow, SageMaker, W&B), it spans all of them — as one connected graph — and it's built to be driven by AI agents through a native MCP server.

Benchmarked at production scale: full inventory reconstruction over a ledger of 28.8k models and 212k events runs in under a second (CHANGELOG, v0.7.4).

Install

pip install model-ledger

The graph builds itself

Every model is a DataNode with typed input and output ports. When an output port name matches an input port name, connect() creates the dependency edge — no hand-wiring.

from model_ledger import Ledger, DataNode

ledger = Ledger()

ledger.add([
    DataNode("segmentation", platform="etl",      outputs=["customer_segments"]),
    DataNode("fraud_scorer", platform="ml",       inputs=["customer_segments"], outputs=["risk_scores"]),
    DataNode("fraud_alerts", platform="alerting", inputs=["risk_scores"]),
])
ledger.connect()

ledger.trace("fraud_alerts")
# ['segmentation', 'fraud_scorer', 'fraud_alerts']

Every mutation is recorded as an immutable Snapshot — an append-only event log that gives you full history and point-in-time reconstruction, because nothing is overwritten.

Talk to your inventory

The MCP server is a first-class surface — point Claude (or any MCP agent) at it:

pip install "model-ledger[mcp]"
claude mcp add model-ledger -- model-ledger mcp --demo

You: if we deprecate customer_features, what breaks?

Claude: 3 models consume it directly, 2 more transitively.

Documentation

Everything lives at block.github.io/model-ledger — and it can't drift, because the API reference is generated from source and every example runs in CI:

  • Quickstart — install to your first dependency trace in 60 seconds
  • Concepts — DataNode, Snapshot, and Composite, in three ideas
  • Agents (MCP) — the eight-tool agent surface, with a worked transcript
  • Connectors — discover from SQL, REST, GitHub, or your own platform
  • Backends — in-memory, SQLite, JSON, Snowflake, or remote HTTP
  • Governance — how the primitives map to SR 11‑7/SR 26‑2, the EU AI Act, and NIST AI RMF
  • API reference — generated from the source

Architecture

flowchart LR
    subgraph Sources
        C1[SQL / REST / GitHub / Prefect<br/>connectors]
    end
    subgraph Core
        L[Ledger<br/>append-only event log,<br/>point-in-time reconstruction]
        G[Dependency graph]
        V[Compliance profiles<br/>SR 11-7/SR 26-2 · EU AI Act · NIST AI RMF]
    end
    subgraph Surfaces
        S1[Python SDK]
        S2[CLI]
        S3[REST API]
        S4[MCP server · 8 tools]
    end
    B1[(in-memory · SQLite · JSON ·<br/>Snowflake · remote HTTP)]
    C1 --> L
    L --> G
    L --> V
    L --- B1
    S1 --> L
    S2 --> L
    S3 --> L
    S4 --> L

For organizations

The OSS core handles discovery, graph building, change tracking, storage, the agent protocol, and compliance validation — the SR 11‑7/SR 26‑2, EU AI Act Annex IV, and NIST AI RMF profiles ship in model_ledger.validate. Your internal package provides only the thin layer on top: connector configs, custom connectors for internal platforms, and credentials. Thin config, not reimplemented logic.

Contributing

See CONTRIBUTING.md. All commits require DCO sign-off.

Security

See SECURITY.md for how to report vulnerabilities privately.

License

Apache-2.0. See LICENSE.

Created and maintained by Vignesh Narayanaswamy at Block.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

model_ledger-0.7.10.tar.gz (267.3 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

model_ledger-0.7.10-py3-none-any.whl (119.8 kB view details)

Uploaded Python 3

File details

Details for the file model_ledger-0.7.10.tar.gz.

File metadata

  • Download URL: model_ledger-0.7.10.tar.gz
  • Upload date:
  • Size: 267.3 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.7

File hashes

Hashes for model_ledger-0.7.10.tar.gz
Algorithm Hash digest
SHA256 9c48b3514c06a1d11d3b28ad53653a6c41556b74cc27d48f62f74c1acbba1207
MD5 e5af636338312e5b3fef41662a7055a4
BLAKE2b-256 79c1f01c0c862b7d96be42ff7d3e99a8e42053caa0719b5fff8c879c9fa0a35c

See more details on using hashes here.

Provenance

The following attestation bundles were made for model_ledger-0.7.10.tar.gz:

Publisher: release.yml on block/model-ledger

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file model_ledger-0.7.10-py3-none-any.whl.

File metadata

  • Download URL: model_ledger-0.7.10-py3-none-any.whl
  • Upload date:
  • Size: 119.8 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.7

File hashes

Hashes for model_ledger-0.7.10-py3-none-any.whl
Algorithm Hash digest
SHA256 189a651f09b3e548d4f44c706f713d871a1b32869a43a773ce6b5fb8149a51b0
MD5 67a15512c8d2d68046f8da4820f8e5f2
BLAKE2b-256 a01961767e1f890b1e9a331fdd2976b72022c6f6c62c8030f0aaa0bc701aafeb

See more details on using hashes here.

Provenance

The following attestation bundles were made for model_ledger-0.7.10-py3-none-any.whl:

Publisher: release.yml on block/model-ledger

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page