Install

AI writes the code.
Thea proves it.

Every team now lets AI agents write code. Thea shows what they changed, which checks ran, and who let it merge.

exit 0
$python scripts/atlas.py check
    Contract 3.52.0: OK
    $thea gate scripts/verify.py
      Named for this file, run in orderA failed or skipped gate refuses the commit.
      $thea contract · generated on every build
      Counted, never typedEvery number above is generated from the repository on each build.
      Contract 3.52.0
      Runs under the agents your teams already use

      Agents ship faster than anyone can review.

      The missing piece is not a smarter agent. It is an independent record of what each change actually passed.

      1. "Done" becomes evidence

        An agent's summary is self-reported. Thea replaces it with the exit codes of your formatter, type checker and tests.

      2. Process is enforced, not suggested

        Rules run at commit and again in CI. A skipped check counts as a failure.

      3. Every mistake becomes a rule

        A refused change is recorded with the guard that stops it. 105 failure shapes closed so far.

      See every agent at work.

      The Thea dashboard shows which agents ran, what they changed and which checks passed. It reads Thea's records and never makes a judgment of its own.

      • Agents and sessions

        Claude Code, Codex, opencode and Hermes, read from each runtime's own session files.

      • Checks

        PASS, FAIL or NOT RUN for every changed file. It never shows a green it did not read.

      • Mistakes

        The failure ledger: every shape an agent repeated and the guard that now stops it.

      Four guarantees no agent can talk its way around.

      The agent never grades its own homework.

      Your own toolchain decides. The exit code is the verdict, never the agent.

      • PASS, FAIL or NOT RUN for every check
      • A missing tool is named, never passed by default
      • Same answer in the hook, in CI and over MCP
      scripts/verify.pyillustrative
      1. Formatterruffexit 0 · PASS
      2. Type and syntaxpython3exit 0 · PASS
      3. Unit testspytestexit 1 · FAIL
      Refused. The agent reported done; the unit tests disagreed. The verdict names the failing check.
      99%correct routing with Thea, against 59% blind
      119/119agent controls passing, each refusing a planted bypass
      89%fewer tokens than pasting tool lists
      36languages routed by one contract

      Generated from a recorded run of contract 3.52.0. See the benchmarks

      Adopt agents without lowering the bar.

      Every verdict is a record you can audit, every rule is code you can review, and nothing leaves your infrastructure.

      Audit trail
      What ran, what passed, what was refused and why.
      Policy as code
      Versioned and reviewed with the repository.
      No egress
      Runs on your machines and your CI.
      Open core
      MIT licensed. Read every line that judges your code.

      From a check on your machine to a mark anyone can trust.

      1. Available now

        Open core

        CLI, hooks, MCP server and CI check on contract 3.52.0. Free and MIT licensed.

      2. Private beta

        Dashboard

        A local Mac app that shows every agent, check and repeated mistake. Nothing leaves the machine.

      3. Next

        Pull request checks

        A GitHub check and one comment per pull request: which gates ran, passed, were skipped or refused.

      4. Planned

        Team sync and policy

        Opt-in. Ships verdicts, never source code. Rules such as "no agent merges to main without the security gate".

      5. Planned

        Thea Verified

        A signed receipt that a change passed its own toolchain on a runner its author did not control.

      Start free. Scale when your agents do.

      Enforcement is never paywalled. Plans differ only in how many agents connect at once.

      Before you roll it out.

      Stop trusting. Start proving.

      Install in minutes. The next change that skips a check does not land, and you see exactly why.

      AI governance at every team size.

      One engine, from one developer to a whole organization.

      Developers

      Let the agent run. Keep the receipts.

      "All tests pass" is a claim. Thea replaces it with evidence you read in a second.

      • Your agent asks Thea for a file's checks before it edits
      • The git hook refuses a commit that failed or skipped one
      • Runs on your machine: no account, nothing to host

      Compare plans

      Compare plans

      $ thea gate scripts/verify.py 1. formatter: ruff format --check scripts/verify.py 2. compiler_or_typechecker: python3 -c 'import ast,sys; [ast.parse(open(f, encoding="utf-8").read(), f) for f in sys.argv[1:]]' scripts/verify.py 3. unit_tests: pytest
      Teams

      One policy for every agent and repository.

      One versioned contract gives every agent and pipeline the same answer.

      • One contract file per repository, reviewed like code
      • Same gates locally, at the hook, in CI and over MCP
      • Shared dashboard, gate history, approvals and audit export

      Compare plans

      $ python scripts/verify.py # the done set, each gate PASS / FAIL / NOT RUN contract · planted_suite · agent_controls code_shape · examples · context_cost markdown · lint · own_enforcement
      Business

      Controls that refuse, evidence an auditor can read.

      An instruction file cannot stop an agent. Every Thea control is enforced, tested and recorded.

      • Narrow tools, sandboxed writes, spend and step budgets
      • Named actions wait for a human approval; a hash-chained audit trail
      • SSO, self-hosted control plane, signed provenance

      Compare plans

      # controls, each with a planted bypass that must be refused narrow_tools only the tools the task needs sandbox writes stay in the worktree budget stop at declared spend and steps approval named actions wait for a human effects side effects declared, then checked audit hash chain; an edit is named

      Adopt in stages, enforce when ready.

      Observe, then block, then govern. Each stage is one step; your agents stay as they are.

      1. Day one

        Advise

        Agents ask before they edit. Nothing blocks yet.

      2. First week

        Enforce

        Add the git hook and required CI check. Failed changes cannot merge.

      3. Team and Business

        Govern

        Turn on controls, share the failure ledger across repositories and give leads a dashboard.

      Runs where your code already lives.

      Your machine

      The CLI, hooks and MCP server run locally over standard input and output.

      Your CI

      A check in your own GitHub Actions marks every pull request.

      Your control plane

      A self-hosted control plane for shared policy, history and audit.

      Bring Thea to your team.

      Start free, or join the Business design-partner program.

      The governance layer for AI coding agents.

      Each layer answers what an agent should never guess.

      Institutional memory for agents.

      Once is a bug; twice is a rule. 105 failure shapes and 40 success moves so far.

      Symptom to shape

      Named by shape, not file, so it is caught anywhere.

      Shape to guard

      A second sighting ships a rule and a planted test.

      Guard to move

      Agents see the lesson before they edit.

        thea failures · most-sighted first · × = sightings

        Every repository gets an executable constitution.

        README, AGENTS.md, CI config and tribal knowledge become one contract the build checks.

        One system, every layer.

        Each layer works alone; together they close the loop.

        Wherever your agents run.

        The same contract answers through every surface. Three ship today; three are on the roadmap.

        It remembers every mistake, and guards it.

        Every mistake is kept with its fix, every success with its move.

        Seen twice becomes a rule

        How often it recurred, the guard that refuses it, the move that replaces it.

          thea failures

          Moves that worked, kept

          The move, when it applies and how it was verified.

            thea successes

            No claim without code

            Every declaration must resolve to the file that implements it, or the build fails.

            agreement.lock · atlas.py check

            Small by design

            Agents ask for one file's route instead of reading the tree.

            verify.py context_cost

            Nothing drifts

            No calendar dates in tracked text, no unbounded unpushed work, no hand edits to generated files.

            dated claims · unpushed_bound · generated files

            Every language, one contract

            Every language carries a guide, a card and a manifest.

            languages/ · cards · instruments

            Enforced, never only declared

            Each hard invariant names the function that enforces it. A control with no enforcer is refused.

            thea invariants

            One route for every agent change

            Same five steps for any agent. Each verdict is an exit code.

              thea commands

              A proof contract, not a plugin.

              Review gives an opinion. Thea gives a standard: one file that defines what proves a change.

              The method is public.

              The contract, gates and language packs are open source.

              A badge that links to proof.

              A README badge that opens the latest verdict.

              Signed verdicts.

              Signed verdicts an auditor can check without rerunning.

              From edit to approved merge.

              The agent asks which checks apply. The change cannot merge until they pass.

              Port

              One record per file: route, tier, gates, past lessons and the next command.

              $ thea port scripts/verify.py --frame agent

              Gate

              The numbered commands that prove a change to this exact file.

              Verify

              Exit 0 only if every gate passed. NOT RUN is never a pass.

              $ python scripts/verify.py

              Land

              Push, pull request and merge in one step. Refused on conflict.

              $ python scripts/branchstate.py --land

              Port speaks to whoever asks.

              The same file record, framed for its audience with --frame.

              Plug in where you work.

              Change classes add gates.

              Pass a class with --change; the plan adds the gates that class requires on top of the file's own.

              $ python scripts/atlas.py plan <path> --task implementation --change security_sensitive --json

              The done set, every time.

              scripts/verify.py runs each of these once and exits 0 only if all of them pass.

                A building inspector for AI-written code.

                The agent builds. Thea checks the work and remembers every defect.

                Know what "done" means

                Every change shows which checks ran and passed.

                Catch breakage before it merges

                A failed or skipped check stops the change at commit and at pull request.

                Stop repeat mistakes

                A mistake seen twice becomes a tested rule.

                Keep your agent and your tools

                Claude Code, Codex, opencode, Hermes or a script, with the tools you already have.

                Spend fewer tokens

                Agents ask for one file's checks, not the whole repository: 89% fewer tokens, measured.

                Free, local, yours

                MIT licensed, on your machine. No account, nothing to host.

                Check
                A command your project already trusts, such as its tests or type checker. Thea calls it a gate.
                Contract
                One small file that says which checks prove which kind of change.
                Verdict
                PASS, FAIL or NOT RUN, taken from the check's exit code, never from the agent.
                Ledger
                The record of past mistakes, each paired with the guard that now stops it.

                From prompt to production.

                Agents write the code. Nothing governs it.

                Agents report "done" whether or not anything was checked.

                "All tests pass." Which tests, run where?

                A claim is not evidence. The diff does not say what ran.

                Every gate reports PASS, FAIL or NOT RUN from its exit code.

                Rules in a README are suggestions.

                Docs describe the process. Nothing stops an agent skipping a step.

                One executable contract, enforced at commit and at landing.

                The same mistake, every week.

                Each session starts from zero and repeats last week's failure.

                A ledger of failure shapes, each paired with its replacement move.

                Infrastructure, not another agent.

                Thea holds every agent to the same contract.

                Your agents

                Contract · Port · Gates · Verify · Enforce · Control · Memory

                CLIMCP serverGit hooksCI workflowllms.txt
                FormattersCompilers and typecheckersTest runnersLinters and scannersGit and GitHub
                Your toolchain, unchanged

                One change, four steps.

                Thea adds proof, a verdict and a memory.

                1. 01

                  Your agent changes a file.

                  Any agent, unchanged.

                2. 02

                  Thea names the proof.

                  The exact commands that prove it. Riskier changes get more.

                3. 03

                  The checks run. The exit code decides.

                  PASS, FAIL or NOT RUN. Nothing is taken on the agent's word.

                4. 04

                  Bad work is stopped. The lesson is kept.

                  A failed change cannot land. A repeat mistake becomes a rule.

                Agent

                Instructions advise. Thea enforces.

                Columns are categories, not named products.

                Built inPartly, or only if someone writes itNot covered

                Evidence, not adjectives.

                Recorded runs. Each figure names the instrument behind it, so you can rerun it.

                With TheaBlind

                Context and footprint

                • Tokens before routing1,724
                • Fewer than tool lists89%
                • Pairs answered324/324
                • Random baseline2.8%
                • Install8 KiB · 1 dep

                README generated block · 3.52.0

                Cross-model

                99%

                with Thea against 59% blind, across 11 models from 5 providers

                abtest.py · 11 models · 2,409 questions

                Enforcement

                17/17

                planted broken commits refused at the hook

                enforce.py · v3.52.0

                Self-test

                461

                planted mistake kinds, each refused by a test

                planted suite · 3.52.0

                A real run, failures included.

                One recorded python scripts/verify.py on a working branch. It exited 1, and the record says exactly why.

                  Failure ledger

                  105

                  failure shapes filed, each with a guard; 40 success moves that replace them.

                  $ thea failures

                  Agent controls

                  119/119

                  control tests passing in the same run; each plants a bypass that must be refused.

                  $ python scripts/verify.py

                  Scope: these are evidence for routing, checks and refusals, not for end-to-end task success.

                  The difference is the evidence.

                  Same model, same edit to scripts/verify.py. The left side is illustrative; the right side is a recorded Thea run.

                  Without Theaillustrative
                    Merged on the agent's word. Two failing gates go unnoticed.
                    With Thearecorded
                      Refused before landing. The verdict names the two gates that failed and the one that could not run.

                      Agent autonomy, with enforced limits.

                      Controls refuse rather than warn, and each names the function that enforces it. Audit-ready by default.

                      Generated sandboxes

                      Generated Docker or macOS sandboxes: no network, only the worktree writable.

                      $ python scripts/sandboxgen.py docker <contract>

                      Public by design, secret-free by rule

                      Staged secrets are blocked before a commit exists, and the line is named.

                      Supply chain

                      OpenSSF Scorecard and dependency review run in CI. Toolchain downloads are checked against digests pinned in the contract.

                      Read-only by default

                      The MCP server exposes read-only commands. Each tool's exit code is its verdict.

                      Security model

                      Verify what you install.

                      Releases are deterministic tarballs with build attestations. Dependencies install only against pinned hashes.

                      Check a release

                      gh release download "$TAG" --pattern 'atlas-*' --repo HLIntel/thea-software gh attestation verify atlas-$TAG.tar.gz --repo HLIntel/thea-software shasum -a 256 -c atlas-$TAG.tar.gz.sha256

                      Install with hashes

                      git clone --depth 1 --branch <tag> https://github.com/HLIntel/thea-software python -m pip install --require-hashes -r scripts/requirements.lock.txt python scripts/atlas.py doctor

                      Pin a tag, never main.

                      Free for one agent. Priced by how many you run.

                      The CLI, MCP server, skills, plugin, hooks and every language pack are MIT licensed, with no agent limit. Plans price the dashboard and team features by agents running at once.

                      What each plan includes.

                      Common questions.

                      Install Thea your way.

                      Free and open source. Download, run three commands, and every agent on the machine is governed.

                      Thea Dashboard for Mac

                      See every agent, check and guard in one window (tour). Installing it puts thea and thea-mcp on PATH too, and Connect wires them into each agent.

                      Join the waitlist

                      Every agent on one screen.

                      A local app that renders what Thea already recorded: which agents ran, what they changed and which checks passed. Private beta for Mac.

                      Thea Dashboard · Checks
                      Changed filesthea verify --changed
                      src/billing/invoice.pypython · format, types, testsPASS
                      web/app/routes.tstypescript · lint, typesFAIL
                      db/migrations/0042.sqlsql · migration checkNOT RUN
                      README.mdmarkdown · lintPASS
                      Illustration with example data.

                      Eight pages, each with one source.

                      Every page reads one Thea command or file. If its source fails, the page says NOT RUN and shows the error.

                      Agents and sessionsEach runtime's own session files
                      Changesgit log and git status
                      Checksthea verify --changed, run when edits pause
                      Healththea resume
                      Mistakesthea failures: the failure ledger
                      GitHubLocal repositories, and GitHub through device sign-in
                      ConnectEach agent's MCP config and its own sign-in command
                      Modelthea model: the decision layer's judgments

                      Local by design.

                      The dashboard is a reader. Verdicts come from your toolchain through Thea, and they stay on your machine.

                      Loopback only
                      Binds 127.0.0.1 and refuses any other host.
                      Per-run token
                      Each launch gets a fresh token, compared in constant time.
                      Strict headers
                      Same-origin CSP, no caching and no request log.
                      No key needed
                      No account, no webhook and no API key to run it.

                      One record, every reader.

                      The CLI, hooks, CI and the dashboard all read the same verdict. Team sync is next: opt-in, verdicts only, never source code.

                      Your code stays on your machine. Not by promise. By test.

                      Thea runs locally and writes only to your machine, your repository or storage you choose. No account, no telemetry, no Thea server, and a failing test keeps it that way.

                      What Thea stores, and where

                      Verdicts, ledgers and contracts live in your repository, under your own git history. The live agent count lives in ~/.thea/sessions on your machine: one small file per session holding the agent's name, its session id, its working directory and when it was last seen.

                      Never a prompt, a command, a diff or a file's content. Records unseen for a week are removed.

                      Nothing phones home

                      No telemetry, licence server or sign-in. Enforcement works offline, and the agent count never decides whether a check runs.

                      Enforced by a failing test

                      The test suite scans every shipped Python file for network imports. Only the modules below may make one; anywhere else, the suite fails before the change lands.

                      Your storage, your cloud

                      Everything Thea keeps is plain files in your repository and home directory. Team sharing, when it ships, will use storage you control.

                      The only code that can reach the network.

                      Each runs only when you start it, with your own keys or remote, and talks only to the service you point it at.

                      • Model benchmark: asks the models you configure the same questions with and without Theaabtest.py
                      • Model providers: the endpoints and key names you set for that benchmarkproviders.py
                      • Repository audit: compares your live GitHub settings with your declared ones, using your tokenghaudit.py
                      • Retry wrapper the three above share; opens no connection of its own choosingresilience.py

                      What the scan does not cover

                      It reads Python imports. Git commands go only to the remotes you configured. Your agents, editor and model providers keep their own policies.

                      This website

                      No analytics, cookies, tracking or forms, and no web fonts. Live figures are read from the public README on GitHub, with jsDelivr as a fallback. Nothing you type or click is sent.

                      Policy for contract 3.52.0. Check it yourself: the scan is the case only the declared modules can open a network connection in the planted suite, and its source is on GitHub.

                      Put a contract on your agent. Then let it refuse.

                      Pick where you work. Each path ends with a contract in your repository and checks that refuse unproven changes. Pinned to 3.52.0.

                        Four places a change can be refused.

                        Turn on the ones you need. Each runs the same contract, so a gate skipped at the edit still stops the change later.

                        Paste once. Every chat starts routed.

                        A chat that cannot run code still names a file's gates, reviews a pasted diff and labels its claims. Put this in custom or project instructions.

                        Go deeper when you need to.

                        Detailed docs, from first gate to fleet.

                        Install, commands, MCP server, enforcement and controls. Every example comes from the repository.

                        Browse all docs

                        Add Thea to your home screen

                        1. Tap Share in the browser toolbar.
                        2. Choose Add to Home Screen, then Add.

                        Thea opens full screen from the icon, like an app. iPhone and iPad ask you to confirm this step yourself; no site can add it for you.