Skip to documentation
AgentDirectiveDocs
Methodology v0.1.0Back to main site

Learn

Methodology

How AgentDirective turns an ordinary project description into clear requirements without making your decisions for you.

How matching works

AgentDirective checks your description for known traits, such as sensitive data or actions that change production. You can correct the list before continuing. Your choices determine which Control Packs apply.

If nothing matches, you can send the description once to Cloudflare AI for suggestions. This is off by default. We do not store the description or response. AI can suggest only a trait from the existing list; it cannot choose a pack, answer a project question, or change your choices.

Repeatable matchingThe same confirmed traits, matching rules, and pack versions produce the same matches.
Open decisions stay open“Not decided” is recorded as unresolved, not a confirmed default.
Versioned resultsEach directive records the methodology, pack, and schema versions used to create it.

1. Identify what the system does

Traits describe capabilities and boundaries, not just technologies. Examples include sensitive data, outside input, tool access, money movement, multiple customers, production changes, and irreversible actions.

Every suggestion shows where it came from

AgentDirective records whether a trait came from you, a published rule, or the optional AI check. A suggestion is never presented as something you explicitly said.

  • user_stated — selected or written by the user
  • rule_inferred — matched by versioned rules
  • model_suggested — suggested by the optional AI check
  • user_corrected — changed by the user
architecture-model.json
{
  "id": "FINANCIAL_ACTION",
  "value": true,
  "confidence": 0.90,
  "provenance": "rule_inferred",
  "reason": "The proposal includes a payment action."
}

2. Match the safeguards

Each pack has a published applies_when rule. AgentDirective checks it against your confirmed traits and shows why it matched. If nothing matches, it creates a no-match assessment instead of an empty directive.

AI does not choose the safeguards

Only the published pack rules decide what applies. An AI model cannot invent a pack, skip its rule, or hide one that matches.

If you change a project trait, AgentDirective checks the rules again and records what changed.

AUT-001 matching rule
"applies_when": {
  "any": [
    { "characteristic": "FINANCIAL_ACTION", "equals": true },
    { "characteristic": "CONSEQUENTIAL_ACTION", "equals": true }
  ]
}

3. Ask the important questions

Applicable packs surface important questions. Quick Review shows the few most likely to change the build; Full Review shows them all.

StatusMeaningMay provide a binding value?
confirmedAn authorized person supplied the answer.Yes
recommendedA pack recommendation has not been accepted.No
unresolvedThe material question remains open.No
not_applicableThe user says the question does not apply and gives a rationale.No
explicitly_rejectedThe user consciously rejects the safeguard and gives a rationale.No

4. Create, track, and review

  1. Create
    Keep one source of truth

    agent-directive.json holds the requirements. The readable instructions and agent files come from it.

  2. Track
    Keep progress with the project

    The coding agent updates one status entry per requirement and records important changes.

  3. Review
    Compare claims with evidence

    The reviewer checks whether the report is complete and internally consistent. It does not inspect the code itself.

  4. Reassess
    Keep history when scope changes

    A new directive shows what was added, changed, kept, or retired. Earlier decisions stay visible.

5. Versioning and governance

Schemas, the methodology, the pack library, and individual packs use semantic versions. Applicability or requirement changes require a pack version change. Breaking data-contract changes require a schema major version.

Each pack is expected to carry a distinct failure mode and control objective, technical review, evidence review, applicability fixtures, limitations, and changelog history before it can move from review to released. Packs are not added merely to increase match rates; wording gaps belong in versioned signals or context rules, while genuine control gaps require evidence. At present, every published pack remains in review.

Type a word or phrase to search the documentation.