🦔 SmartMoat
Know your moat. Score the tasks AI can't easily take — and widen them.
IAIso §6 · Workforce · SmartTasks.cloud · the Smart* family
Which of your skills can AI still not touch — and for how long?
As AI reshapes how we work, a new gap opens: your tasks are automating and you don't know which skills still defend you. SmartMoat closes it —
score at the exact moment the gap bites, and it works the second you clone it
(a synthetic demo ships in demo/).
Install
SmartMoat is not published on PyPI or any other package registry yet. Until
this section says otherwise, a package called sf-smartmoat on any registry
is not ours, and neither is smartmoat.
Install from a clone (Python 3.10 or later):
git clone https://github.com/SmartTasksOrg/sf-smartmoat
cd sf-smartmoat
python -m venv .venv
. .venv/bin/activate # Windows PowerShell: .\.venv\Scripts\Activate.ps1
python -m pip install .
sf-smartmoat --demo
Status
- Version 3.0.0, experimental. A small deterministic command-line tool with a bundled synthetic demo and two smoke tests.
- Published: nowhere yet; install from a clone (above).
- Tested: the 2 smoke tests in
tests/on Python 3.12, Linux, on every push to master and every pull request (.github/workflows/ci.yml). - Not tested: Windows and macOS; Python versions other than 3.12.
- Security review: none independent. Report vulnerabilities as described in SECURITY.md.
Run it in your stack
| Where you work | How you run it |
|---|---|
| Python | from a clone: python -m pip install . (not on PyPI yet) |
| CI / pre-commit | add the hook from .pre-commit-hooks.yaml |
What's in this repo
- Core engine —
src/sf_smartmoat/: score() -> MoatScore; plan() -> Plan. Deterministic, dependency-free. - CLI —
sf-smartmoat --demo(and--version): a deterministic demo of the core. - Also included — a runnable
demo/,examples/, the IAIso mappingspec/iaiso-map.json, a browsersite/playground.html, plus public smoke tests intests/.
How it works
Rule IDs are namespaced MOAT-* so output looks kin to the rest of the family
(SmartPangolin's SEC-*, etc.). Deterministic, dependency-free, fail-loud.
The data objects (UML)
These are real dataclasses in src/sf_smartmoat/models.py — the
diagram and the code are the same thing:
classDiagram
class Task {
+name: str
+agent_exposure: float
+human_moat: float
}
class MoatScore {
+exposure: float
+moat: float
+percentile: int
}
class Plan {
+moves: list[str]
}
class IAIsoControl {
+section: str
+name: str
}
Plan ..> IAIsoControl : conforms to
Where it sits in the architecture
SmartMoat doesn't stand alone — it stacks with the family, and everything conforms to the IAIso standard — the same standard that governs SmartTasks' own apps, while each tool here stays standalone and drops into your architecture:
graph LR
IAIso([IAIso standard]):::std
Cloud([SmartTasks.cloud]):::cloud
SmartPangolin[SmartPangolin]:::tool
SmartPrompt[SmartPrompt]:::tool
SmartCheck[SmartCheck]:::tool
SmartSeal[SmartSeal]:::tool
SmartStandard[SmartStandard]:::tool
SmartSim[SmartSim]:::tool
SmartMoat[SmartMoat]:::tool
SmartRoute[SmartRoute]:::tool
SmartFeed[SmartFeed]:::tool
SmartPangolin -->|emits clean artifacts to| SmartSeal
SmartPrompt -->|hands secret/PII flags to| SmartPangolin
SmartPrompt -->|enforces prompt rules from| SmartStandard
SmartCheck -->|stamps verified output with| SmartSeal
SmartCheck -->|checks against rules from| SmartStandard
SmartSeal -->|issues receipts consumed by| SmartCheck
SmartSeal -->|issues receipts consumed by| SmartRoute
SmartStandard -->|supplies rule sets to| SmartPrompt
SmartStandard -->|supplies rule sets to| SmartCheck
SmartSim -->|feeds role forecasts to| SmartMoat
SmartSim -->|draws signals from| SmartFeed
SmartMoat -->|consumes forecasts from| SmartSim
SmartRoute -->|verifies receipts from| SmartSeal
SmartRoute -->|enforces the standard from| SmartStandard
SmartFeed -->|feeds signals to| SmartSim
SmartFeed -->|feeds signals to| SmartMoat
SmartPangolin -.conforms.-> IAIso
SmartPangolin -.shares IAIso with.-> Cloud
SmartPrompt -.conforms.-> IAIso
SmartPrompt -.shares IAIso with.-> Cloud
SmartCheck -.conforms.-> IAIso
SmartCheck -.shares IAIso with.-> Cloud
SmartSeal -.conforms.-> IAIso
SmartSeal -.shares IAIso with.-> Cloud
SmartStandard -.conforms.-> IAIso
SmartStandard -.shares IAIso with.-> Cloud
SmartSim -.conforms.-> IAIso
SmartSim -.shares IAIso with.-> Cloud
SmartMoat -.conforms.-> IAIso
SmartMoat -.shares IAIso with.-> Cloud
SmartRoute -.conforms.-> IAIso
SmartRoute -.shares IAIso with.-> Cloud
SmartFeed -.conforms.-> IAIso
SmartFeed -.shares IAIso with.-> Cloud
IAIso -.governs.-> Cloud
classDef tool fill:#1c232d,stroke:#f5b83d,color:#efe9f5;
classDef std fill:#04121f,stroke:#46d6c8,color:#46d6c8;
classDef cloud fill:#1a1327,stroke:#a78bfa,color:#a78bfa;
style SmartMoat stroke-width:3px,stroke:#ff6b6b;
- SmartMoat consumes forecasts from SmartSim →
Open site/playground.html for the interactive version.
Part of the Smart* family
One system, not nine projects — same mascot, same manifesto voice, same rule-ID style, all aligned to the IAIso standard. Each is an independent, open-source, single-purpose tool you can integrate into your own architecture:
| Tool | IAIso | What it does |
|---|---|---|
| SmartPangolin | §1 · Secure Sharing | Scan before you share. Stop leaking secrets into AI models, agents, and tools. |
| SmartPrompt | §4 · Context | Lint before you send. Bad prompt in, bad work out — and it's your name on it. |
| SmartCheck | §2 · Verification | Check before you sign off. Catch the AI when it's confidently wrong. |
| SmartSeal | §3 · Provenance | Seal what you ship. A signed receipt so anyone can verify what they received. |
| SmartStandard | §7 · Standards | Standardize before you scale. One shared, auditable convention for AI-assisted work. |
| SmartSim | §8 · Foresight | Simulate before it hits you. See your role's task-by-task collapse sequence. |
| SmartRoute | §5 · Orchestration | Route only what you trust. Gate agents and tools with trust scores and guardrails. |
| SmartFeed | §9 · Awareness | Distill the firehose. A tight brief of only what moves your work. |
Backed by the standard: SmartMoat implements IAIso §6 · Workforce. Open-source edition: this repo is the simplified, single-purpose version, built for any org to integrate into its own architecture. SmartTasks' desktop app and SmartTasks.cloud run a more advanced, deeply-integrated implementation of the same IAIso governance — a separate product, not this code bundled.
Who's behind this
- Roen Branham — CEO & AI Strategy Architect · CISSP-certified AI, security & governance architect; author of IAIso and sole inventor of the Z4 Semantic Fabric patent application. LinkedIn
- Le Vu Tanh — CTO & Core Engineering Lead · Chief architect of the Cortex engine; large-scale system reliability and low-latency infrastructure — the engineer who ships what gets architected. LinkedIn
The team behind IAIso & SmartTasks: a CISSP-certified security & governance architect and a large-scale systems engineer — 20+ years shipping secure, AI-driven platforms for regulated, blue-chip environments (Allianz, BMW, Rolls-Royce, Heidenhain).
Runs on governed local models
Capability tiers (L1 Layman → L5 Agentic) help place the right model at the right task.
This tool is local-first, so pair it with models you can actually vet. SmartTasks publishes 21+ governance-validated GGUF builds on Hugging Face — each with a machine-readable scorecard (capability tiers L1 Layman → L5 Agentic, IAIso conformance invariants (pass/warn/fail), OWASP-mapped garak red-team, transparency probes (viewpoint-alignment / over-refusal), and per-file SHA-256). Gate model selection on evidence, not vibes — and every finding, including warnings, is published in full.
→ SmartTasks on Hugging Face · Qwen3.6-27B (L5 agentic) · react-agent-coder-llama-3.1-8b (agentic coder) · gpt-oss-20b (open reasoning)
Get in touch
- Companies & enterprises: enterprise@smarttasks.cloud — we help teams integrate SmartMoat + IAIso into their architecture so governance and audit-readiness become a byproduct of how they already work.
- The standard: IAIso · iaiso.org
- The product: SmartTasks.cloud
Built by SmartTasks Lab. Apache-2.0. Contributions welcome.
Metadata
Release files for sf-smartmoat 3.0.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| sf_smartmoat-3.0.0.tar.gz | 12.6 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| sf_smartmoat-3.0.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 21.9 kB
Release files / sf_smartmoat-3.0.0.tar.gz
| Download URL | sf_smartmoat-3.0.0.tar.gz |
|---|---|
| Size | 12.6 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
6f8b96d38d1a693c37114ca49c82365ecac71ab714dd91f24c90e57b598016a7
|
|
BLAKE2b-256 checksum How to use checksums |
119c7231b0613f7b5a478d33452671331a4a634aafb654c46c703b22ffc61e20
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 9, 2026.
Transparency logRelease files / sf_smartmoat-3.0.0-py3-none-any.whl
| Download URL | sf_smartmoat-3.0.0-py3-none-any.whl |
|---|---|
| Size | 9.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
e032d45c99b3db57765bcfde43722d147d74b7e084ebd23a595e4ed5eab8459c
|
|
BLAKE2b-256 checksum How to use checksums |
312b4562fd34496d8a42762e27e37bec73ac5ab327f2e192e6fbc45f24fb835a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 9, 2026.
Transparency log