Governance infrastructure / Public alpha 03

Operational evidence for autonomous software work.

AgentGuard records available evidence from an autonomous coding session and produces an early, deterministic signal for human scope review.

A local Windows amd64 experiment for Claude Code—not a complete security product, semantic task understanding, or a production team dashboard.

Pre-release software. Verify the published SHA-256 checksum before running. Download checksum

AG / SESSION 0184 REVIEW REQUIRED
Declared task Update session review documentation
Evidence events
14
Components
03
Exceptions
01
Observed componentClassification
docs/scopeIn scope
internal/sessionSupported expansion
scriptsUnexplained expansion
Illustration of deterministic path-and-order rules—not a live product result.
01Local-first captureEvidence stays on the workstation
02Content-free recordsNo commands, diffs, or file contents stored
03Human decisionThe signal informs a human scope review
04Explicit publicationNothing is sent without a CLI action

Operating model

A narrow evidence chain you can inspect.

AgentGuard separates local evidence capture from team review. Each transition is explicit; unsupported activity stays visible as a limitation, not hidden behind a confidence score.

  1. 01 / Declare

    Define the task boundary

    Record a plain-language task and the project-relative component roots expected to change.

  2. 02 / Observe

    Capture supported events

    Store a redacted timeline from documented Claude Code hook surfaces without file content.

  3. 03 / Classify

    Apply deterministic rules

    Compare paths and event order with the declared scope. No semantic necessity claim is made.

  4. 04 / Review

    Escalate the exception

    Put unexplained expansion in a human queue and export the same stable, redacted evidence.

System boundary

Local enforcement. Deliberate team visibility.

A / WORKSTATION

Local CLI

Records supported hook evidence, evaluates deterministic scope rules, and produces the review artifact. It keeps working without the hosted service.

  • No telemetry
  • No background agent
  • No billing dependency
Explicit publishRedacted summary only
B / TEAM STAGING

Review queue

Receives only the summary a user chooses to publish. Invited reviewers can acknowledge and resolve exceptions in the staging dashboard.

  • Invite-only accounts
  • Authenticated access
  • Operator-controlled

Trust model

The limits are part of the product.

AgentGuard is useful only when the evidence it has—and the evidence it does not have—remain equally visible.

What the alpha does

  • Runs locally as a standalone Windows amd64 binary
  • Records a redacted timeline of supported hook evidence
  • Flags path-and-order scope expansion for human review
  • Exports the same redacted evidence as stable JSON

What it cannot prove

  • That the observed timeline is a complete account
  • That a change is semantically necessary or correct
  • That unsupported shell, MCP, or network actions are safe
  • That every destructive-command variant is detected

Invalid hook input fails open to Claude Code's native permission flow. An allow decision bypasses the native prompt only for a strict routine rule. Event authenticity and process integrity are not verified in this alpha. The local CLI has no telemetry, automatic updater, billing dependency, or background process.

Evaluation material

Inspect the implementation path before you evaluate.

Invite-only alpha

Evaluate it with the operator, not a checkout flow.

Email the operator with the organization or project you want to evaluate. There is no public account creation, automated approval, trial checkout, or billing flow.