Evidence
Someone is going to ask what your agents did.
Agents now write whole changes, not suggestions. When a reviewer, a customer, or an auditor asks what they touched last quarter, most teams can offer commits and a recollection. Kaplira keeps a structured record for the runs it governs.
- agent
- claude-code · session a4f9e2
- contract
- blocks: auth/session, api/middlewarescope: 4 files declaredrisk: high — touches the session path
- files
- src/auth/session.ts+62 −14 · sha256:9c1f…src/api/middleware/guard.ts+31 −0 · sha256:2ab7…
- tests
- 128 passed · 0 failed · full suite
- review
- no scope drift · no new risk raised
- integrity
- sha256:d840… · matching
Example record
The record
A governed closeout produces a structured run record.
It records which agent worked under which contract, which files changed, which validations ran, and what the review concluded. Completed records can be exported as portable receipts.
Default receipt exports contain structured evidence, paths, and digests — not source code or diffs. Kaplira analyzes the repository locally and does not upload or take custody of it.
Why it is shaped this way
Reviewers often need three things.
A run receipt supports the evidence for each governed item. Reconciliation against merge history is what establishes the complete population and makes defensible sampling possible. The people who need that report are rarely the people writing the code — they are the ones who have to present it.
The population
The complete set of in-scope agent-assisted changes for the period.
Not yetNeeds reconciliation against merge history
A sample
A subset the reviewer picks, drawn from that population.
Not yetNeeds a complete population first
Evidence per item
For each sampled change, evidence that the control operated as described.
TodayOne run receipt per governed item
What Kaplira does today
- A gate that runs before the agent writes, not after
- A contract per architecture block: files, constraints, risks, tests
- Changed-file review against the contract that authorized the run
- Structured run records and exportable receipts with integrity checks
- Works with Claude Code, OpenAI Codex, and Cursor through MCP
What it does not do yet
- Reconciliation against merge historySo the report also declares what changed without a receipt. A declared gap is evidence; a silent one is not.
- Independent counter-signatureSo the record holds for the party being audited, not only for the machine that produced it.
Until both land, Kaplira produces a useful record of the runs it governed — not a complete account of everything that reached the repository. That distinction matters more than any claim we could make, so it is stated here rather than discovered later.
If this is the report you have been asked for, say so.
The desktop app is free and run evidence is stored locally by default. What is worth a conversation is what your reviewers actually require — that is what decides what gets built next.
Talk to the founder