+ − zoom · 0 fit · F fullscreen · ← → tour · Esc close
+ − zoom · 0 fit · F fullscreen · ← → tour · Esc close
· E2E PRODUCT VISION
Governed Composition · Stateless Evaluation Core · Federated Five-Phase SDLC
repo · evolith_arch32 · numbers as of 2026-09-21
ADR-0101 · ADR-0074 · ADR-0102 · ADR-0116 · ADR-0125 · ADR-0128 · ADR-0129
1
WHO ARRIVES ↓
Humans · terminal · IDE
CI · pull request
AI agents · MCP clients · Claude Code plugin
Tracker · external client
Evolith CLI
npx -y @beyondnet/evolith-cli
validate --engine opa
@beyondnet/evolith-cli 1.4.0 · Node ≥ 18
38 command files (generated inventory)
exit 0 pass · 1 tool failed (no verdict)
2 gate blocked · 3 invalid invocation
GitHub Action
uses:
beyondnetcode/evolith_arch32@v1
Marketplace: Evolith Governance Validation
fail-on-violation: true
outputs compliance-status · exit-code
"Not evaluated" in words
MCP server
npx -y @beyondnet/evolith-mcp
(stdio · Streamable HTTP)
@beyondnet/evolith-mcp 1.4.0
55 tools · 12 resources · 8 prompts
stdio JSON-RPC 2.0 · Streamable HTTP
ABAC native AND OPA · approvalToken
REST Core API
POST /api/v1/evaluate
Bearer EVOLITH_API_KEY
12 controllers · 33 endpoints (measured)
ghcr.io/beyondnetcode/evolith-core-api
ADR-0073 envelope
{ success, data | error, meta }
Channels: npm @beyondnet/evolith-cli 1.4.0 · @beyondnet/evolith-mcp 1.4.0 · GitHub Marketplace action v1 · MCP registry io.github.beyondnetcode/evolith
Claude Code plugin evolith / evolith-governance 1.3.1 · GHCR 3 images (core-api · mcp · agent-runtime)
One parity matrix: 74 operations · CLI 43 · MCP 51 · REST 32 · 15 on all three (reviewed 2026-07-11) · guard 24 both ways · exploration suite in a required check · Node SDK @beyondnet/evolith-sdk 2.0.1
The chatbox is an intermediary, not the source of authority — LLMs and agents consume approved context, rulesets, skills and permissions through Evolith contracts.
EvaluationContext ↓ · ↑ EvaluationResult — a verdict, never a decision (ADR-0101)
2
STATELESS EVALUATION ENGINE — @beyondnet/evolith-core-domain 1.4.0
EvaluationContext → EvaluationResult
schema 1.0.0 → 2.0.0 · decisionRecommendation.binding: false
never persists tenant · product · initiative
Native TS · 19 handlers
handler throw → errored
OPA → Wasm · 35 policies
OPA v1.19.0 · 4 entrypoints
missing wasm → every rule failed
Enforcer · 6 sandboxed analysers
dependency-cruiser · NetArchTest
import-linter · checkov · trivy
ISO 5055 SARIF
passed
failed
skipped
errored
A blocking rule that never ran fails the PR exactly as one that failed.
blockingSkippedRuleIds · undeclared rule → skipped (no-policy-in-bundle)
empty corpus → RulesetsNotFoundError · missing evolith.yaml → GOV-000
12 EvaluationKinds · 7 KindEvaluators (CLI · MCP) · evidence kind refused (UnsupportedEvaluationKindError)
Markdown explains · *.rules.json defines · OPA + Native enforce (ADR-0041)
THE CONSTITUTION — read by every door
144
ADRs
newest ADR-0129
184
rule packs
21 categories · 417 rules
50
schemas
phase-gate + contracts
33
artifacts
24 binding (ADR-0125)
8
topologies
5 dimensions ⟂ SDLC axis
3
standards packs
SSDF · ISO 5055 · SLSA
core 105 · nodejs 21 · dotnet 12 · android 1 · ai-augmented 5
NIST SSDF v1.1 · ISO/IEC 5055:2021 · SLSA v1.0 = 16 rules
Knowledge OS (M0) · OKF v0.1 (ADR-0105, Proposed)
RAG on pgvector (ADR-0112) · KO-* (ADR-0115, Proposed)
Security ADR-0119…0124 → generated conformance packs
inventory 2026-09-01 · cli 1.4.0: 177 packs · 412 rules
WHO CAN SAY YES (ADR-0116):
human · custodian · board → accept · promote · ratify · waive · enforce
agent · engine · ci → observe · recommend · attach-evidence · draft-candidate | mutative MCP tools need { apply: true, approvalToken }
3
tracker-web
React 19 + Vite 8 SPA (nginx)
tracker-api · .NET 10 BFF (ASP.NET Core) — sole Core client
UMS-delegated Bearer · TenantScope isolation (T-044)
ACL to view-models · T-038 · T-046
Owns runtime governance state
gate policies (requiresCoreVerdict) · submissions · evidence · exceptions (T-039)
ledger both ways (T-055) · HITL approvals · append-only audit
58 local decisions (index) · UAT on Coolify since 2026-08-22
tracker-gateway · NestJS facade for external consumers (T-052)
UMS · tenant master (ADR-0129) · identity (T-040 · T-053)
SDLC EXECUTION ENGINE · orchestrated by Tracker · evaluated by Core
PHASE 1
f1 · gate-f1
CONCEPTION & DISCOVERY
Gate: Business Sign-Off
PRD
Discovery Canvas
PHASE 2
f2 · gate-f2
DESIGN & ARCHITECTURE
Gate: Design Baseline Approved
ADR Registry
Reference Blueprint Alignment
PHASE 3
f3 · gate-f3
CONSTRUCTION
Gate: Successful Build
CI Pipeline
Definition of Done Checklist
PHASE 4
f4 · gate-f4
VALIDATION & QA
Gate: RC Stamped
Test Summary Report
Acceptance Validation
PHASE 5
f5 · gate-f5
DELIVERY & OPERATIONS
Gate: Production Live
Release Notes
Observability Validation
WEDGE (vision §1.5) · architecture conformance on every PR
⟂ TOPOLOGY AXIS
8 topologies
5 dimensions
guard 30 keeps the
axes disjoint
evolith drift
measures this axis,
not a gate
Granularity = Initiatives — no tasks / backlog / epics / user-stories. Agile work items are ExternalReferenceContext ingested via ACL.
Tracker decides every phase transition · Core recommendations are non-binding (ADR-0100 · ADR-0101 · ADR-0127). CLI-only deployments block locally: evolith gate evaluate --phase · evolith phase advance.
Two planes: process governance always on (no repo needed) · architecture conformance opt-in via requiresCoreVerdict (default false).
Tracker BFF consumes the Core API as an external client — ADR-0074 explicitly rejected placing the BFF inside Core.
EvaluationResult (ADR-0073 envelope) · non-binding → ACL → GateDecision
POST /api/v1/evaluate · evaluationInput.files (inline) · Bearer
4
AGENT RUNTIME · @beyondnet/evolith-agent-runtime 1.3.0 (ADR-0102) · Experimental
AgentRuntimeService — 20 port files · 21 declared port interfaces · 11 on the hot path (7 required + 4 optional)
47 adapter classes — a port count is not a capability count
InteractionAdapters:
ExternalTrigger
HermesChatBox
Mcp *
OpenCode *
SmartCliChat
SmartCliCommand
* declared, not constructed by any surface (vision, verified 2026-07-28)
Engines behind IAgentEnginePort: Stub (default) · Hermes · Swarms · Cowork · Routing — "Hermes is the engine, not the authority"
Governed orchestration: ABAC native AND OPA (ADR-0087) · HITL POST /runtime-approvals · run-journal replay (GT-593)
Port files in code (20) · 21 declared interfaces · vision taxonomy 18 (§3.4) — the 20 *.port.ts files:
agent-engine
agent-runtime
approval
assistant-invocation
c4-binding-map
communication-gateway
core-evaluation
harness
interaction-adapter
knowledge
lexical-index
memory
policy-validation
quality-signal-provider
run-journal
scheduler
skill-registry
structural-reviewer
tracker-trace
workspace-context
LLM providers · ADR-0128 — claude · gemini · none → deterministic stub
off by default (EVOLITH_LLM_EGRESS) · HITL per call · 30 s Gemini / 60 s Claude · 60,000 bytes fail-closed · 8 redaction classes
The published CLI calls no LLM.
tenant chooses and pays
GOVERNED COMPOSITION
Build the irreducible governance kernel;
compose commodities behind replaceable
ports, adapters and ACLs.
Anti-Corruption Layers (ACLs)
preserve lineage · map to canonical
reject non-compliant
External Tools Cluster
Jira
GitHub / GitLab
CI/CD runners
Test runners
Security scanners
Observability
Deployment
Doc engines
Disposition per capability
Adopt
Embed
Integrate
Extend
Build
Reject
Quality signals · IQualitySignalProvider
ADR-0111 Proposed · Lighthouse ADR-0113
(Proposed)
Data ownership stays with the source
of record; Tracker judges evidence.
commands · events · evidence
5
Evolith Core — Level 0 (Authority)
the Constitution · a satellite of itself
evolith.yaml coreRef 1.0.0
Satellite Repository — Level 1 (Inheritor)
Evolith Tracker (.NET 10) · UMS (ADR-0129)
tenant master · any evolith.yaml
Architecture Board
approves upstream promotion
UP-001 · UP-002 · UP-003 (PROPOSED)
→ inherit · pinned coreRef.version (INH-01 · INH-02 · INH-03) · Upstream Proposal UP-NNN → Architecture Board (INH-05)
approved promotion → Core evolves → every satellite re-inherits · INH-04 local ADRs tagged EvolithSatellite
INH-06 DECISIONS.md · Adopt · Extend · Override · Not Applicable — silence is not an option
evolith init --name <x> --yes → evolith.yaml · missing manifest → GOV-000 · evolith upgrade (INH-03) · satellite:create | satellite:adopt
waiver → Verdict.WAIVE · rulesets.overrides: waivable, never removable (GT-678)
6
Gap board 688 / 715 · 27 not done
P0 GT-435 · NO-GO
generated 2026-09-21
10 required checks · 18 workflows
74 guards + 32 self-tests
enforce_admins
Security tab 0 · 0 · 0 · 0
on c5547114 (2026-09-19)
37 fixed · 58 dismissed with reason
OpenSSF Scorecard 5.1
with committed floors
(2026-08-04)
Tests 107 suites · 1,492 tests
87.33% statements · 87.68% lines
(2026-09-21)
Engines on this repo: opa 133/159
native 41/159
(2026-08-21, cli 1.4.0)
1,109 npm downloads · Linux-only CI install
2026-07-21 → 2026-08-19
no confirmed external adoption
Evidence window 30 days · observed 2026-09-19
stale from 2026-10-20
7/8 packages attested (2026-07-30)
Source of truth: product/suite/vision/evolith-product-vision-master.md · counts from generated inventories (inventory-summary.md 2026-09-01 · product-inventory.md · maturity-reconciliation.json 2026-09-21)
and tree measurements · rendered 2026-09-21