Stops at the tool boundary
Host enforcement adapters run before shell and write calls. A blocking verdict prevents the call; it does not depend on the model remembering a prompt.
Inspect enforcementGoverned autonomy for serious repositories
One repository-owned governance layer for Claude Code, Codex, and Pi. Tests, reviews, security checks, decisions, and project context survive the host you use.
You decide. codeArbiter enforces.
Direct hook evidence
A broad stage meets the shipped guard
b2cf1a875a6e source digestAttempted tool call git add -A
BLOCKED [H-03]: 'git add -A' / 'git add .' / 'git add --all' / 'git add -u' are prohibited. Stage files explicitly (commit-gate skill).
Exit 2 · command not executed · no staged files
Audit side effect The block appended an H-03 event to .codearbiter/gate-events.log.
Capture source plugins/ca/hooks/pre-bash.py at SHA-256 b2cf1a875a6ec0aa4c36e59bfdc2c9f64a81a70dcc901a5bbc46465b087e4873.
Evidence boundary This directly invoked the shipped hook with the host payload shape. It does not prove a host discovered or registered that hook.
The exact stderr and audit effect from a direct invocation of plugins/ca/hooks/pre-bash.py, rendered as a faithful replay. The denied staging command never ran. This evidence verifies the shipped guard itself, not host discovery or registration; the quickstart’s doctor probe verifies that end-to-end path.
Measured, not hand-typed
From first install to confident operation
Follow one progressive route, perform a small exercise at each stage, and finish with a power-user capstone you can prove from repository state.
Choose a host, install it, opt in, and verify a real block.
02Pick the right lane for features, fixes, dependencies, and decisions.
03Approve the target, inspect SMARTS calls, and keep the audit trail.
04Trace hooks, tune scope, diagnose drift, and cut releases.
What changes when codeArbiter is active
Every guarantee is backed by a mechanism you can inspect.
Host enforcement adapters run before shell and write calls. A blocking verdict prevents the call; it does not depend on the model remembering a prompt.
Inspect enforcementSpecs, plans, decisions, tasks, questions, and audit records live in .codearbiter/. Change hosts without creating parallel memory.
Overrides, autonomous decisions, and checkpoint findings are durable artifacts. Audit a range from source records instead of reconstructing it later.
See the audit modelHow work moves
codeArbiter routes intent into the lane that owns it, scales the gates to the risk, and leaves a resumable record on disk.
Understand gated lanesFeature, fix, sprint, dependency, decision, review, or release.
Specs, tests, reviewers, and security checks appear only when the change needs them.
Commit evidence and review state travel with the branch. The default branch is never a direct write.
Start from the job, not the machinery
/ca:featureTurn an idea into an approved spec, test-first implementation, and reviewed PR.
/ca:fixStart from a reproduction, prove the regression, and make the smallest verified fix.
/ca:sprintApprove the target once, then let SMARTS-scored decisions drive the plan to a PR.
/ca:add-depReview license, provenance, and known vulnerabilities before installation.
/ca:adrCapture a numbered, user-attributed decision with its governed paths and supersession chain.
40 commandsSearch the source-backed command, skill, agent, and hook-gate reference.
Choose your host
The project state is shared; command spelling and host capabilities are documented honestly.
/ca:featureMarketplace install, native plugin agents, hook trust flow, and optional rich statusline.
Install for Claude Code$ca-featureThe same enforcement decisions and state through Codex-native skills and hook verdicts.
Install for Codex/ca-featureGit-installed Feature Forge preview with project trust, a rich footer, and supervised child dispatch.
Install the Pi previewNeed the exact differences? Read the compatibility matrix and the dated Claude Code + Codex verification record.
Fit before friction
codeArbiter adds deliberate process. That pays off when the repository outlives the current session, more than one person or host touches it, or a security and delivery claim needs evidence.
Open source · AGPL-3.0-only · local enforcement
Install for one host, opt the repository in, then run the live doctor probe.
No telemetry service is required for enforcement. Disable one repository or uninstall completely with the state implications documented.