Observed facts
Facts reproducibly obtained from Git, files, tool outputs, provider APIs, or runtime observations.
Public research preview · Approach
MetaAware turns observable project state and explicit policy into deterministic findings. AI helps people ask questions and understand results, but it does not create the governing fact, silently change the rule, or grant authority.
Operating model
MetaAware separates observation, judgment, explanation, and authority so that every failure can be located and challenged.
Evidence contract
Facts reproducibly obtained from Git, files, tool outputs, provider APIs, or runtime observations.
Project intent that cannot be inferred safely: target release, branch purpose, required reviewers, approved artifact, business invariant, or accepted exception.
Versioned results from CI, scanners, SBOM systems, infrastructure providers, identity services, or payment test environments. Imported evidence remains attributed to its producer and observation time.
Explicit rules defining which evidence is required, how it is evaluated, what severity applies, and which recovery condition closes the finding.
A fluent explanation cannot substitute for any missing input.
Finding contract
This conceptual example shows the minimum reasoning chain a user or another system should be able to inspect.
HEAD is not the commit identified by the recorded review.HEAD.Does not prove: A fresh review does not prove that the code is correct, secure, valuable, or ready for production.
This structure allows a developer, reviewer, CI system, or agent to inspect the same judgment without relying on the wording of one AI response.
Epistemic state
The system reproduced the fact directly.
The project or an authorized person supplied the context.
The result includes an explicit, challengeable interpretation.
Available evidence supports incompatible states.
Required evidence is absent, inaccessible, stale, or insufficient.
Unknown is not automatically pass or fail. A policy may conservatively prevent an action while evidence is missing, but the system must distinguish that policy response from a claim that a defect has been proven.
Natural-language boundary
A developer may ask, “Why is this release unsafe?” or “What should I do next?” The adapter translates the question into a bounded query. The answer must remain traceable to the resulting evidence and rule.
Natural language improves accessibility. It does not become the source of governance authority.
Responsibility separation
They obtain evidence from a defined source and report its identity, version, freshness, and limitations.
It applies versioned rules only to the evidence available. It must return unknown when the required evidence is missing.
It translates findings, retrieves relevant guidance, compares recovery options, and adapts explanation depth to the user.
Humans define policy, approve exceptions, accept consequential risk, and remain accountable for the decision.
External outcomes, independent oracles, blind scenarios, expert review, and prospective use test whether the rule and explanation were actually adequate.
Governance stack
Incidents, user outcomes, independent review, and the environment can contradict the system.
Evidence and governed revision test whether MetaAware's rules, explanations, and boundaries remain adequate.
Versioned policy converts bounded evidence into findings and recovery conditions.
People and agents create changes, reviews, releases, declarations, and observable outcomes.
Domain expansion
Security tools, cloud systems, runtime services, identity providers, and payment sandboxes remain specialist evidence producers.
Versioned rules and project business invariants define what the available evidence supports.
AI explains; humans authorize. Missing evidence produces unknown, and integrated findings do not become certification.
Capability improvement
A new rule, a stronger AI model, or a larger number of warnings does not by itself demonstrate improved governance capability.
An improvement claim must identify the previous failure, the new evidence, the regression scenario, the blind result, changes in false positives, false negatives and unknown, and the remaining limitation.
Present tense
MetaAware does not yet have a released governance CLI.
The approved MVP is limited to six read-only capabilities—status, audit, next, why, explain, and doctor—and three rule families: branch and worktree safety, review freshness, and release provenance.
Assist and enforce modes, security policy packs, provider integrations, runtime observation, identity governance, and payment-integrity governance are accepted directions or design possibilities, not implemented capabilities.
Authoritative sourceGOV-PHILOSOPHY / TECHNICAL-DESIGN / ADR-013 / ADR-014 · Operating model, assurance boundary, and governed capability expansion · 2026-09-13