From specification to evidence: how AEGIS keeps a person in charge
AEGIS is my open-source toolkit for delivery with AI agents. It writes the specification first, blocks code until the specification is complete, and records the person who approves the release.
AI makes code cheap to produce, and that moves the constraint to review. Most teams answer with rules: finish the specification before coding, keep a named person accountable, and separate the author of a change from its approver. The rules are easy to write down and hard to keep under a deadline.
AEGIS (Agentic Enterprise Guided Intelligent System) is an open-source toolkit I maintain that makes those rules the default. It runs as agents, prompts, and a command-line validator inside GitHub Copilot and Claude Code. It implements the delivery model of the Enterprise AI Framework, which I also maintain.
Ideation: purpose and requirements
The ideation orchestrator asks a few questions at a time and waits for answers. It writes six business documents: product requirements, functional and non-functional requirements, a user journey map, a system blueprint, and an executive briefing. After each change, a validator checks every id and cross-reference.
Before it asks anything, AEGIS searches the organization’s standards library and uses only standards marked approved. The user is asked only about what the standards leave open.
Architecture: constraints and decisions
Specialist agents propose the interface, data, security, deployment, and observability architecture. Each material choice becomes an architecture decision record, so the reasoning survives the project.
Implementation: bounded work and independent review
A read-only readiness gate runs first. It stops if any document is still a draft, a blocking decision is open, or a contract is missing. A planner then splits the work into packages, and each package declares its paths, tests, and acceptance criteria.
A code agent works on one package at a time, and a hook blocks it from writing anywhere else. An independent reviewer reruns the checks and returns a pass or a list of changes.
Release: a named human decides
The release command records the approver by name. AEGIS never deploys by itself.
What AEGIS leaves to you
| Expectation | What to add |
|---|---|
| A second human approves each AI-made change | The per-package reviewer is an agent. Require human pull request review |
| Operate and monitor | Your operations tooling and an AI incident response process |
| Change or retire | Your change process, with the AEGIS documents as the record |
AEGIS 0.2.0 installs with pip install aegis-sdlc. The
getting started guide covers GitHub
Copilot and Claude Code setups, and the framework’s
walkthrough post
follows one example from a one-line idea to a named release approval.