Skip to content

Governed autonomy for serious repositories

Hard gates for agentic coding.

One repository-owned governance layer for Claude Code, Codex, and Pi. Tests, reviews, security checks, decisions, and project context survive the host you use.

You decide. codeArbiter enforces.

Claude CodeCodexPi preview

Direct hook evidence

A broad stage meets the shipped guard

Shipped H-03 hook
Verified direct hook invocation · Jul 30, 2026Replay source applies to the exact latest published ca artifact: v2.21.15 at 929229354e3ab2cf1a875a6e source digest
Read the exact invocation result

Attempted tool call git add -A

BLOCKED [H-03]: 'git add -A' / 'git add .' / 'git add --all' / 'git add -u' are prohibited. Stage files explicitly (commit-gate skill).

Exit 2 · command not executed · no staged files

Audit side effect The block appended an H-03 event to .codearbiter/gate-events.log.

Capture source plugins/ca/hooks/pre-bash.py at SHA-256 b2cf1a875a6ec0aa4c36e59bfdc2c9f64a81a70dcc901a5bbc46465b087e4873.

Published-artifact applicability Replay digest applies to both the current hook source and the exact latest published ca artifact source. Read the complete release applicability record.

Evidence boundary This directly invoked the shipped hook with the host payload shape. It does not prove a host discovered or registered that hook.

The exact stderr and audit effect from a direct invocation of plugins/ca/hooks/pre-bash.py, rendered as a faithful replay. The denied staging command never ran. This evidence verifies the shipped guard itself, not host discovery or registration; the quickstart’s doctor probe verifies that end-to-end path.

Work you can inspect

From a requirement to a testable plan.

Follow one criterion through a real draft specification and its linked plan. See what needs your review before the work can run.

One goal. Connected records.

Export saved searches

Unapproved fixture

Choose a criterion to follow its connection into the plan. These are real native-rendered drafts, not a live coding session.

Specification Draft

AC-001 · Preserve fields and order

Parsed CSV has name/query headers and one row for each record in input order.

Given
Two saved searches with plain text fields.
When
Export the collection.
Observe
Parsed CSV has name/query headers and one row for each record in input order.
Open the native specification

Implementation plan Pending

T-001 · Preserve fields and order

References AC-001

export_csv.py + test_export_csv.py

python -m unittest -v test_export_csv.TestExport.test_rows

Required check: TestExport.test_rows

Open the native plan

Specification Draft

AC-002 · Round-trip special characters

Every field equals the original text after CSV round-trip.

Given
A record containing commas, quotes, newlines and Unicode.
When
Export and parse using the standard CSV reader.
Observe
Every field equals the original text after CSV round-trip.
Open the native specification

Implementation plan Pending

T-002 · Round-trip special characters

References AC-002

export_csv.py + test_export_csv.py

python -m unittest -v test_export_csv.TestExport.test_round_trip

Required check: TestExport.test_round_trip

Open the native plan

Specification Draft

AC-003 · Keep an empty result explicit

The function returns None, not a header-only export.

Given
The input collection is empty.
When
Request an export.
Observe
The function returns None, not a header-only export.
Open the native specification

Implementation plan Pending

T-003 · Keep an empty result explicit

References AC-003

export_csv.py + test_export_csv.py

python -m unittest -v test_export_csv.TestExport.test_empty

Required check: TestExport.test_empty

Open the native plan

Structural checks passed. Approval checks did not. Task eligibility was refused with DRAFT_BINDING. The local Python tests shown in the tour do not approve or accept these drafts.

Inspect validation resultsSource and capture identities
Inspect the structured criterion
{
  "applicability": {
    "mode": "conditional",
    "rationale": "Two saved searches with plain text fields."
  },
  "constraint_refs": [],
  "guarantees": [
    "Parsed CSV has name/query headers and one row for each record in input order."
  ],
  "id": "AC-001",
  "intent_refs": [
    "SCOPE-01"
  ],
  "kind": "behavior",
  "obligation": "must",
  "preconditions": [
    "Two saved searches with plain text fields."
  ],
  "scenarios": [
    {
      "given": "Two saved searches with plain text fields.",
      "id": "SCN-AC-001",
      "then": "Parsed CSV has name/query headers and one row for each record in input order.",
      "when": "Export the collection."
    }
  ],
  "source_refs": [],
  "statement": "Parsed CSV has name/query headers and one row for each record in input order.",
  "title": "Preserve fields and order",
  "trigger": "Export the collection.",
  "verification": {
    "evidence_state": "planned",
    "id": "VER-AC-001",
    "method": "automated",
    "negative_control": "An implementation returning None for every input fails the export checks.",
    "oracle": "Parsed CSV has name/query headers and one row for each record in input order.",
    "planned_target": "TestExport.test_rows"
  }
}
Open the complete product tour

Measured, not hand-typed

The shipped payload is the source of truth.

From first install to confident operation

A curriculum, not a pile of pages.

Follow one progressive route, perform a small exercise at each stage, and finish with a power-user capstone you can prove from repository state.

Start the complete learning path

What changes when codeArbiter is active

Autonomy with evidence attached.

Every guarantee is backed by a mechanism you can inspect.

Stops at the tool boundary

Host enforcement adapters run before shell and write calls. A blocking verdict prevents the call; it does not depend on the model remembering a prompt.

Inspect enforcement

State belongs to the repository

Specs, plans, decisions, tasks, questions, and audit records live in .codearbiter/. Change hosts without creating parallel memory.

Explore the state store

Bypasses leave a trail

Overrides, autonomous decisions, and checkpoint findings are durable artifacts. Audit a range from source records instead of reconstructing it later.

See the audit model

How work moves

Ask for the outcome. Keep the proof.

codeArbiter routes intent into the lane that owns it, scales the gates to the risk, and leaves a resumable record on disk.

Understand gated lanes
  1. 1

    State the work

    Feature, fix, sprint, dependency, decision, review, or release.

  2. 2

    Clear the lane

    Specs, tests, reviewers, and security checks appear only when the change needs them.

  3. 3

    Ship through a PR

    Commit evidence and review state travel with the branch. The default branch is never a direct write.

Start from the job, not the machinery

A clear entry point for the work in front of you.

Choose your host

One policy core. Native entry points.

The project state is shared; command spelling and host capabilities are documented honestly.

Claude Code

stable
/ca:feature

Marketplace install, native plugin agents, hook trust flow, and optional rich statusline.

Install for Claude Code

Codex

stable
$ca-feature

The same enforcement decisions and state through Codex-native skills and hook verdicts.

Install for Codex

Pi

preview
/ca-feature

Feature Forge preview with an npm convenience channel, pinned Git tags for reproducibility, project trust, a rich footer, and supervised child dispatch.

Install the Pi preview

Need the exact differences? Read the compatibility matrix and the dated Claude Code + Codex verification record.

Fit before friction

Built for work that has to remain explainable.

codeArbiter adds deliberate process. That pays off when the repository outlives the current session, more than one person or host touches it, or a security and delivery claim needs evidence.

Use it when

  • agents implement meaningful product work;
  • decisions and bypasses need attribution;
  • tests and reviews must be real stops;
  • the same project moves between supported hosts.

Skip it when

  • the code is a disposable one-hour experiment;
  • any process friction is unacceptable;
  • the repository cannot carry a checked-in state directory.

Open source · AGPL-3.0-only · local enforcement

Put one repository under governed change.

Install for one host, opt the repository in, then run the live doctor probe.

No telemetry service is required for enforcement. Disable one repository or uninstall completely with the state implications documented.