AgentFlow SDLC is an open-source process layer for software projects that use AI coding agents. It keeps requirements, decisions, validation, review, and handoffs in durable source records instead of trapped in one chat session. GitHub is the first source adapter.
It adds delivery governance around your existing repository. It does not generate an application, replace your source system or harness, or dictate your technology stack.
| Question | Answer |
|---|---|
| What is it? | A role-based path from request to pull request, backed by templates, validators, and durable evidence. |
| What problem does it solve? | AI can produce code faster than teams can understand, review, resume, and govern the work around it. |
| What is the value? | Clear scope, reproducible checks, explicit review boundaries, safer handoffs, and less process memory. |
| Who is it for? | Adopters, maintainers, provider authors, and operators who need reviewable AI-assisted delivery. Manual, CLI, and extensible provider bindings keep the core harness-neutral. |
The safest first look is read-only:
# Run directly via npx or global install:
npx -y github:smota/agentflow-sdlc doctor-env --target /path/to/your-project
# Or install globally as an application:
npm install -g github:smota/agentflow-sdlc
agentflow-sdlc doctor-env --target /path/to/your-projectdoctor-env reports on the target project's tooling; it does not change the target project. Ready to continue? Get started is the entry document — it reaches a first governed change, a frozen acceptance contract with a recorded observation, in six commands. Prefer an assistant to drive the same steps conversationally? Use the assisted onboarding guide and assisted configuration guide.
flowchart LR
Request["Request"] --> Scope["Scope & design"]
Scope --> Build["Implement"]
Build --> Verify["Test & review"]
Verify --> PR["Evidence-backed PR"]
PR --> Resume["Ship or resume with context"]
One accountable executor normally carries the work through explicit roles. Focused advisers or routed agents are optional when they improve a decision; sensitive work retains human approval.
flowchart TB
Project["Your existing repository"]
Guardrails["Policy · roles · branch rules"]
Tools["Templates · CLI · validators"]
Evidence["Issues · handovers · commits · PRs"]
Project --> Guardrails
Guardrails --> Tools
Tools --> Evidence
| Capability | What it provides | Where to start |
|---|---|---|
| Preview-first adoption and updates | Content-bound plan, transactional apply, lockfile v2, and external rollback receipt | Adopter path |
| Role-based delivery | Analyst through PR-readiness phases with explicit handoffs | Workflow |
| Durable evidence | Portable artifact references, transition envelopes, lifecycle boundaries, and PR evidence | Evidence contracts |
| Deterministic validation | Issue, config, role-pass, PR, release, skill, agent, evidence, lifecycle, and eval checks | CLI reference |
| Intelligent collaboration | Provider-neutral intent plus bounded advisory, discovery, spike, and human-gated modes | Collaboration |
| Role acceptance and councils | Digest-bound handovers, deterministic checks, accountable acceptance, and bounded rework | Role collaboration |
| Providers and runtime identity | Capability-based manual, CLI, Grok, and optional AFD facets with truthful attribution | Provider matrix |
| Source adapters | Source-neutral core with GitHub as the first read/mutation adapter | Source adapters |
| Skills, plugins, settings, and extensions | Portable skills plus project-selected overlays and harness adapters | Extension packs |
| Lifecycle roles and methods | Productized accountability contracts with configurable analysis and engineering approaches | Lifecycle roles |
| Optional visual operations | Cockpit goal, readiness, release, replay, approval, and follow-up views | Cockpit |
| Executable quality model | Agent eval manifests, multi-agent acceptance checks, and derived outcome metrics | Agent evals |
| Guiding principles and core values | Six core pillars governing autonomous AI coding, regulated assurance, and continuity | Guiding principles |
AgentFlow SDLC is built upon six foundational pillars governing AI coding in modern engineering environments:
- Extensibility & harness neutrality: Agnostic across AI models and execution targets (
claude-cli,agy-cli,codex-cli, API providers). - Regulated assurance & compliance-by-design: Tamper-evident cryptographic span ledgers, Four-Eyes Principle dual-control, and black-box QA separation of duties.
- Risk-aware card taxonomy & adaptive execution: Proportional execution paths (
light,standard,high-assurance) with topological dependency blocking (blocked_by). - Agentic flow with human decision comprehension: Meaningful human gate oversight and transparent waiver accounting without artificial friction.
- Durable continuity & portability: Resilient cross-machine handoffs, POSIX path normalization,
.git/index.lockcleanup, and monotonic lease fencing preventing context loss. - Bounded supervision & zero deadlock: Guaranteed deterministic resolution of external CI gates and supervised process cleanup.
Read Guiding principles for full architectural invariants and standards for contributing agents.
The current release line is 1.3.0 and requires Node.js 20 or newer. Read the v1.3.0 release notes for the latest capabilities and qualification limits. No agentflow-sdlc package is currently published on npm, so install directly from GitHub using npm as shown above; no manual clone is required. The release badge always resolves to the newest published GitHub release.
| I want to… | Read this |
|---|---|
| Evaluate the product quickly | AgentFlow in 5 minutes |
| Adopt it in a repository | Get started |
| Find the right guide for my role | Start here |
| Author or integrate an execution provider | Provider author path |
| Operate and troubleshoot an installation | Operator path |
| Understand every document and tool | Documentation index |
| Configure branches, checks, and routing | Project setup and assisted configuration |
| Run or contribute issue work | Contribution workflow |
| Extend or integrate the framework | Modular architecture |
- Durable evidence over private chat memory.
- One accountable executor by default; more intelligence only when it improves a decision.
- Humans and agents follow the same public contribution contract.
- Human authority for high-assurance work.
- Follow-up issues instead of hidden TODOs or silent scope drift.
- Generated harness adapters are distribution surfaces, not the source of product truth.
| Area | Contents |
|---|---|
| Policy | AGENTS.md and executor adapters such as CODEX.md, CLAUDE.md, and AGY.md |
| Workflow | roles/, skills/, and agents/templates/ |
| Documentation | docs/, organized by audience in the documentation index |
| CLI and validators | bin/, scripts/, lib/, and schemas/ |
| Distribution | adapters/, skills/, extensions/, and manifests/ |
| Optional interface | Cockpit assets and runtime commands |
Start from a GitHub issue or explicit maintainer direction. Read AGENTS.md first, then follow the contribution workflow. Keep changes issue-scoped, run the relevant validators, and use the project PR manifest.
Licensed under the Apache License 2.0.
Candidate-bound observations, guarded run recovery, environment inspection and contained adoption storage are documented in reliable delivery. Use run operations for the CLI and release acceptance for the remaining publication gates. These development interfaces do not imply an npm 2.0 release.
