DevGuard

Agent speed.
Team control.

DevGuard is the operating layer for autonomous engineering on GitHub. Define how agents work, keep a durable record of every decision, and enable isolation only when each runtime capability has passed its production gate.

Policy · sandbox · approval · evidence

Live run model Event stream
  1. Intent

    01

    PR #142 · review remediation

  2. Policy gate

    02

    supervised · write risk

  3. TrueForge sandbox

    03

    composed provider only · otherwise unavailable

  4. Human approval

    04

    exact fingerprint · when policy requires it

  5. Verified outcome

    05

    evidence attached · recorded

Transitions are server-confirmed when their capability gates are ready; otherwise the control plane fails closed.

The control plane for work that can change code.

One governed path from intent to verified outcome, regardless of whether work starts in the web app, CLI, or GitHub.

Policy before execution

A repository policy snapshot travels with every run. Unknown or ambiguous actions fail closed.

Sandbox as a boundary

Sandbox execution stays capability-gated: when a verified TrueForge command provider is composed for a workspace, agent code runs in isolated workspaces—never on the DevGuard host. Until that provider is ready, sandbox workflows remain unavailable.

Evidence as the output

Events, artifacts, findings, and validation make every result inspectable after the work is done.

Humans authorize effects

When approval gates are composed for a policy decision, sensitive writes pause on an exact fingerprint until the right maintainer approves. Unavailable approval or provider paths stay disabled rather than silently skipping.

Make the rules once.
See them in every run.

  1. Connect

    Link GitHub and choose the repositories your team governs.

  2. Set the work style

    Choose autonomy, actions, approval gates, and required validation.

  3. Review the proof

    Follow agent events, sandbox evidence, and the exact outcome.

Ready to govern your first repository?

Connect GitHub, set a policy, and inspect the first run from one calm workspace.

Get started