GouvernAI plugin is permissive with your AI agent where risk is low. Conservative where it matters. Invisible everywhere else.
GouvernAI is a Claude Code plugin with two enforcement layers. ~60% of typical actions (reads, drafts, navigation) flow through with zero friction. Guardrails only activate when risk is real.
Skill layer: classifies actions across 4 risk tiers — T1 excluded, T2 notifies, T3 pauses for approval, T4 requires full stop with risk assessment. Escalation rules bump tiers for bulk operations, unfamiliar targets, and scope expansion.
Hook layer: PreToolUse hooks run on every Bash, Write, and Edit call. Hard-blocks obfuscated commands, credential transmission, catastrophic operations, and self-modification. No override.
Includes /guardrails slash command with persistent modes (strict, relaxed, audit-only), audit-only mode for autonomous agents, and append-only audit logging. 85 unit tests. Zero dependencies. MIT license.
Website: https://gouvernai.ai
Features
- Dual enforcement (skill + hooks)
- 4-tier risk classification
- Audit logging
- Credential exfiltration blocking
- Obfuscated command detection
- AI agent
- Claude Code
- automode