Skip to content

Releases: Bhanuj-AI/ai-governance-oss

bhanuj-governance-plugin-api-v1.0.0

Choose a tag to compare

@thisisbhanuj thisisbhanuj released this 23 Sep 12:38
Immutable release. Only release title and notes can be modified.
bdf21ee

bhanuj-governance-plugin-api v1.0.0

Initial stable release of BHANUJ’s provider-neutral runtime plugin contract.

  • Extracts versioned plugin metadata, lifecycle, replay-adapter contribution, replay context, cancellation, and governed intervention-envelope contracts from Core.
  • Lets external runtimes integrate without importing ai-governance or Core models.
  • Adds ReplayExecutionResult, so external adapters return neutral results while Core retains ownership of canonical execution persistence and lineage.
  • Defines canonical plugin registration through bhanuj.governance.plugins.
  • Adds source-free wheel build and clean-environment installation verification, ensuring [tool.uv.sources] remains developer-only.

Causal Audit Framework

Choose a tag to compare

@thisisbhanuj thisisbhanuj released this 11 Sep 00:40
Immutable release. Only release title and notes can be modified.
ab30e50

Summary

Introduces an Agents Runtime governance capability that ingests auditable execution evidence, detects runtime findings, and performs explainable Causal Audits using durable controlled Replay—not inferred metadata. This release adds governed, deterministic counterfactual evidence controls for causal audits, with improved runtime operations visibility.

Causal Audit now proves evidence influence through:
Observed execution → explicit replay capability → controlled Replay → counterfactual execution → outcome comparison → deterministic classification

What changed

  • Added tenant-scoped Agent Execution and ordered event ingestion APIs, persistence, projections, and Studio views.
  • Added runtime findings, detectors, worker processing, governance projections, and SQLite/PostgreSQL/Neo4j repository support.
  • Added Causal Audit domain model, REST API, persistence, settings, worker handling, immutable completed results, and product taxonomy:
    • NO_TOOL_EVIDENCE
    • EVIDENCE_IGNORED
    • OVER_EXTENDED
    • EVIDENCE_ALIGNED
  • Added an explicit AgentRuntimeReplayCapability contract, requiring a runtime-declared adapter, opaque frozen replay reference, and supported interventions.
  • Extended Replay with immutable controlled-evidence interventions: NULLIFY, REPLACE, and PERTURB.
  • Added a safe deterministic reference adapter through the existing Replay adapter registry; historical Replay fails closed when asked to apply controlled evidence.
  • Causal Audit creates durable child Replay records/jobs, waits for counterfactual executions, then records baseline/counterfactual scores, influence, classification reason, and Replay/execution lineage.
  • Replay worker schedules Causal Audit finalization after controlled Replay completion.
  • Added Studio navigation for Executions | Findings | Causal Audit, contextual Help drawer, tabbed runtime settings, demo data, and operator documentation.
  • Refined the Causal Audit detail UI with signed score chains, explicit saturation summaries, and collapsed evidence/lineage details.
  • Introduces versioned, tenant-scoped Evidence Intervention Policies.
  • Adds REST APIs and Studio workflows to create, validate, activate, retire, and apply intervention policies.
  • Supports deterministic structured-evidence interventions during controlled causal replays.
  • Records intervention-policy version, provenance, evidence digests, and counterfactual replay lineage as durable causal-audit evidence.
  • Extends causal-audit eligibility and results with policy and lineage details.
  • Adds SQLite, PostgreSQL, and in-memory persistence support for intervention policies.
  • Updates local Compose configuration so API and replay workers share durable Agent Runtime persistence.
  • Enhances the Agents Runtime experience with execution selection, policy management, causal-audit review, and local demo-data guidance.
  • Expands the Home dashboard with runtime health, operational metrics, attention signals, provider readiness, and richer recent activity.
  • Improves Studio theme consistency and auto-dismisses the local-demo-ready confirmation after five seconds.
  • Adds architecture, interoperability, sequence, and PostgreSQL OpenTelemetry documentation.

Safety and governance guarantees

  • Cross-tenant execution IDs fail closed.
  • Missing replay capability, evidence references, unsupported interventions, unsafe adapters, or failed counterfactual samples fail closed.
  • Controlled Replay carries reference-only evidence; no raw prompts, responses, credentials, reasoning traces, or raw tool payloads are persisted.
  • Completed Causal Audits are immutable.
  • Every influence result carries durable controlled Replay and produced-execution lineage.

Compatibility and rollout

For deployments using causal-audit workers, ensure the API and worker processes share the configured durable Agent Runtime store. The local Docker Compose setup now configures this automatically.

v1.0.4

Choose a tag to compare

@thisisbhanuj thisisbhanuj released this 15 Aug 08:26
Immutable release. Only release title and notes can be modified.
b9996ee

Summary

  • Modernizes the native MCP endpoint (:8002/mcp) to support the stateless MCP 2026-07-28 specification while preserving compatible legacy handshake/session clients.
  • Both protocol eras normalize into the same canonical tool registry and continue to use the existing authorization, tenant context, audit, idempotency, and REST control-plane paths.

Full Changelog: v1.0.3...v1.0.4

v1.0.3

Choose a tag to compare

@thisisbhanuj thisisbhanuj released this 14 Aug 03:54
Immutable release. Only release title and notes can be modified.
78a2d09

Summary

  • Moves Runtime Connections directly below General and defines a stable, priority-based Settings order.
  • Returns Sync Events newest-first with bounded offset pagination.
  • Adds 25-event Studio pages with Previous/Next controls while preserving tenant-scoped filtering.

What's Changed

  • feat(studio): prioritize settings navigation and paginate sync events by @thisisbhanuj in #9

Full Changelog: v1.0.2...v1.0.3

v1.0.2

Choose a tag to compare

@thisisbhanuj thisisbhanuj released this 13 Aug 12:42
Immutable release. Only release title and notes can be modified.
fe3aa77

Summary

Adds opt-in, provider-neutral telemetry for anonymous OSS adoption and aggregate workload insights.

  • Introduces versioned telemetry contracts, anonymous installation identity, bounded local aggregation, and strict privacy allow-listing.
  • Supports ESSENTIAL, PRODUCT_ANALYTICS, and PERFORMANCE_RESEARCH categories with live system settings.
  • Adds PostHog and no-op exporters; PostHog is isolated behind the telemetry exporter SPI.
  • Adds asynchronous, bounded-retry delivery that cannot affect governance, evaluation, replay, or job execution.
  • Adds telemetry status and payload-preview APIs for operator visibility.
  • Adds evaluation and lifecycle-derived aggregate instrumentation plus internal export-health metrics.
  • Adds PostHog configuration through HTTPS endpoint validation and env:// secret references.
  • Refactors Settings Control registry into composable, category-owned definition modules.
  • Fixes standalone replay-worker telemetry composition so FastAPI dependencies cannot leak into worker execution.

Use a PostHog project token (phc_...), not a personal API key, for telemetry ingestion.

v1.0.1 - OSS

Choose a tag to compare

@thisisbhanuj thisisbhanuj released this 12 Aug 00:38
Immutable release. Only release title and notes can be modified.
a90bb69

Summary

Introduce the initial public release of BHANUJ - AI Governance Control Plane.

AI governance control plane providing deterministic governance, versioned AI asset management, workflow replay, evaluation,
auditability, ontology-based lineage and framework-independent integrations.

Highlights

  • Governance Decision Engine and Policy Engine
  • Governance Ontology and Knowledge Graph
  • Prompt, Model, and Dataset Registries
  • Evaluation Framework and Experiment Management
  • Workflow Replay and Execution Audit
  • Drift Analysis and Candidate Comparison
  • Job Execution Control Plane
  • Versioned REST APIs and MCP Server
  • Kavach Studio
  • Plugin Extension Framework
  • SQLite and PostgreSQL persistence
  • Neo4j ontology integration
  • SeaweedFS and Amazon S3 object storage
  • Documentation, tutorials, walkthroughs, and example data

This commit establishes the public OSS baseline from which future releases will evolve.