Governed AI delivery

Ship with agents.
Keep humans in control.

A dependency-free toolkit that turns AI coding into an auditable software delivery workflow—with explicit scope, approval, review, QA, and publish gates.

delivery.policy enforced
add-search
  1. 01Specificationhuman approved
  2. 02Implementation planscope locked
  3. 03Implementationtests passed
  4. 04Independent reviewin progress
  5. 05QA + publishgated
0runtime dependencies
6separated roles
9CI environments
MITopen source

The missing control plane

Fast agents need
a deliberate system.

Prompts can explain good behavior. They cannot prove approval, prevent a force push, or preserve a review trail. Governed Agent SDLC turns those expectations into portable policy, structured artifacts, deterministic validation, and safety hooks.

Project policy keeps scope, credentials, merge, and release under human authority. Generated role guidance and hooks constrain supported tool actions; platform permissions remain part of the security boundary.

One accountable path

From intent to pull request

Each handoff produces readable evidence. Every gate is explicit.

  1. 01

    Specify

    Separate facts, assumptions, scope, and risk.

  2. 02

    Plan

    Build an ordered task graph from approved intent.

  3. 03

    Implement

    Work from an active task with an explicit write boundary.

  4. 04

    Review

    Assess independently; never repair while reviewing.

  5. 05

    Verify

    Run the declared QA matrix and record evidence.

  6. 06

    Publish

    Open a PR only after a final human decision.

Policy that travels

One kernel. Multiple tools and stacks.

◇

Tool-neutral core

Roles, transitions, approvals, and security policy stay independent of any vendor.

⌁

Structured evidence

Readable Markdown and TOML frontmatter make lifecycle state machine-checkable.

⊘

Deterministic guards

Supported hooks deny known credential access, force pushes, protected-branch refspecs, and reviewer or QA source writes.

⌘

Portable CLI

Initialize, generate, validate, diagnose, and transition artifacts with Python 3.11+.

▦

Stack profiles

Start with generic, Python, .NET, and Nuxt defaults without changing governance.

✓

Cross-platform QA

Continuously checked across Windows, Ubuntu, macOS, and three Python versions.

Trust boundaries by design

Authority stays visible.

The workflow kernel owns meaning. Profiles add stack knowledge. Adapters translate policy. Hooks enforce selected high-value boundaries without replacing platform permissions.

Read the architecture
01Project manifest + artifactsscope · state · evidence
02Tool-neutral coreroles · policy · gates
03Profiles + adaptersstack · vendor translation
04CLI + deterministic hooksvalidate · enforce · report

Three commands to begin

Bring governance into your repository.

Clone the toolkit, install it locally, then initialize an existing project. Nothing project-owned is overwritten.

terminal
$ git clone https://github.com/vannt-dev/governed-agent-sdlc.git
$ python -m pip install -e governed-agent-sdlc
$ agentkit init ./my-project --name my-project
$ agentkit doctor ./my-project

Human authority. Agent velocity.

Make every handoff accountable.