Policy before execution
A repository policy snapshot travels with every run. Unknown or ambiguous actions fail closed.
DevGuard is the operating layer for autonomous engineering on GitHub. Define how agents work, keep a durable record of every decision, and enable isolation only when each runtime capability has passed its production gate.
Policy · sandbox · approval · evidence
Intent
01PR #142 · review remediation
Policy gate
02supervised · write risk
TrueForge sandbox
03composed provider only · otherwise unavailable
Human approval
04exact fingerprint · when policy requires it
Verified outcome
05evidence attached · recorded
One governed path from intent to verified outcome, regardless of whether work starts in the web app, CLI, or GitHub.
A repository policy snapshot travels with every run. Unknown or ambiguous actions fail closed.
Sandbox execution stays capability-gated: when a verified TrueForge command provider is composed for a workspace, agent code runs in isolated workspaces—never on the DevGuard host. Until that provider is ready, sandbox workflows remain unavailable.
Events, artifacts, findings, and validation make every result inspectable after the work is done.
When approval gates are composed for a policy decision, sensitive writes pause on an exact fingerprint until the right maintainer approves. Unavailable approval or provider paths stay disabled rather than silently skipping.
Link GitHub and choose the repositories your team governs.
Choose autonomy, actions, approval gates, and required validation.
Follow agent events, sandbox evidence, and the exact outcome.
Connect GitHub, set a policy, and inspect the first run from one calm workspace.