Tool-neutral core
Roles, transitions, approvals, and security policy stay independent of any vendor.
Governed AI delivery
A dependency-free toolkit that turns AI coding into an auditable software delivery workflow—with explicit scope, approval, review, QA, and publish gates.
The missing control plane
Prompts can explain good behavior. They cannot prove approval, prevent a force push, or preserve a review trail. Governed Agent SDLC turns those expectations into portable policy, structured artifacts, deterministic validation, and safety hooks.
Project policy keeps scope, credentials, merge, and release under human authority. Generated role guidance and hooks constrain supported tool actions; platform permissions remain part of the security boundary.
One accountable path
Each handoff produces readable evidence. Every gate is explicit.
Separate facts, assumptions, scope, and risk.
Build an ordered task graph from approved intent.
Work from an active task with an explicit write boundary.
Assess independently; never repair while reviewing.
Run the declared QA matrix and record evidence.
Open a PR only after a final human decision.
Policy that travels
Roles, transitions, approvals, and security policy stay independent of any vendor.
Readable Markdown and TOML frontmatter make lifecycle state machine-checkable.
Supported hooks deny known credential access, force pushes, protected-branch refspecs, and reviewer or QA source writes.
Initialize, generate, validate, diagnose, and transition artifacts with Python 3.11+.
Start with generic, Python, .NET, and Nuxt defaults without changing governance.
Continuously checked across Windows, Ubuntu, macOS, and three Python versions.
Trust boundaries by design
The workflow kernel owns meaning. Profiles add stack knowledge. Adapters translate policy. Hooks enforce selected high-value boundaries without replacing platform permissions.
Read the architectureThree commands to begin
Install the published package, then initialize an existing project. Nothing project-owned is overwritten.
$ python -m pip install governed-agent-sdlc
$ agentkit init ./my-project --name my-project
$ agentkit doctor ./my-project
Human authority. Agent velocity.