Change control for what AI agents learn: humans promote, releases are signed, rules can be recalled
AI agents now change their own behaviour while they work. They save memories, write themselves new skills and edit their own instructions. Many of these changes help. Yet none of them passes through the steps an organisation expects when a person changes how work is done. Nobody writes the change down, nobody approves it, and when it turns out to be wrong there is no earlier version to go back to.
Brevet adds those steps. It is a local-first Python runtime that wraps the
agent you already have and runs its learning as a governed evolution loop.
When an expert corrects the agent's draft, Brevet records the correction and its
reason as an override. Offline, in the dream cycle, overrides that keep
recurring become candidate capabilities: proposed rules and other learned
behaviour, with no authority. At the dawn gate, a named human or mission
group (the accountable review board) decides which candidates to promote. The
overrides then replay as evals, and the conservative gate stops a
release that makes either half of them worse. Promoted capabilities ship in a
signed release, listed in capabilities.lock, and a capability that proves
wrong can be recalled, with every release that shipped it flagged. Every
step is recorded on a hash-linked evidence chain.
Agents propose deltas; evidence tests them; humans promote them; the runtime only ever executes signed versions.
| Question | How Brevet answers it |
|---|---|
| What has the agent learned? | Every release carries capabilities.lock, its bill of materials: each learned capability, where it came from and the hash of its exact content, plus the harness the release runs with (prompts, skills, tools, settings and libraries). |
| Who approved it? | Each capability records the human or mission group that promoted it at the dawn gate, with the overrides that justified it, signed by their registered key once the workspace requires it. |
| How do we take it back? | Recall it, or roll back to an earlier release. Brevet flags every release that shipped it, withholds it from running agents and records each agent's acknowledgement. |
A quality reviewer at a pharmaceutical plant checks an agent's severity rating
for each equipment problem. The agent rates pump vibration during cleaning as
minor. She overrides it to major every time, because that vibration is an
early sign of seal wear. After four overrides, the dream cycle proposes a
candidate rule. At dawn her mission group promotes it, and release 0.2.0 ships
with the rule in its capabilities.lock. Months later, engineers trace the
vibration to a faulty sensor, so the mission group recalls the rule and Brevet
flags release 0.2.0.
The agent here is a plain Python function; with a real framework you pass your agent object instead.
import brevet
agent = brevet.wrap(triage_agent) # wrap the agent you already have
# Work and override: the agent drafts; the reviewer corrects the draft and says why.
result = agent.run("Pump P-301: vibration high during cleaning",
task_family="equipment_triage")
agent.record_final(result.task_id, "severity: major",
participant="human:qa.reviewer@example.com",
rationale="Vibration during cleaning is an early sign of seal wear.",
tags=["vibration-during-cleaning"])
# Dream: once the same override keeps recurring, it becomes a candidate.
agent.dream()
candidates = agent.dawn() # the dawn queue
rule = next(c for c in candidates if c.kind == "prompt_rule")
# Dawn: a named mission group promotes the rule and the eval cases compiled
# with it. A dream:* approver is rejected.
for cap in candidates:
agent.dawn(decide=(cap.capability_id, "promote"),
approver="mission_group:quality_team")
# Evals: replay the overrides as tests, on the current release and on the next.
before = agent.evaluate(baseline=True)
# ...an agent that takes a context argument now receives the promoted rule...
after = agent.evaluate()
# Release: bound to those two runs, and refused unless the conservative gate passes.
agent.release(to_version="0.2.0", channel="trial",
approver="mission_group:quality_team", evals=(before, after))
# Recall: the rule proves wrong. Then verify the whole evidence chain.
agent.recall(rule.capability_id, reason="The vibration came from a faulty sensor.",
issued_by="mission_group:quality_team")
agent.verify()
The full script is examples/pump_vibration.py, and ABOUT.md shows what it prints.
pip install brevet
brevet demo # the whole loop as one command
brevet playground # step through the loop in your browser
Everything runs on your own machine, with no model or network connection. To
run the example above, clone the repository and run
python examples/pump_vibration.py. For a guided, clickable tour, open
docs/demo.html in a browser.
brevet.wrap() recognises agents built with LangGraph, the Claude Agent SDK,
DeepAgents, AutoGen, LlamaIndex, Pydantic AI, the Google Agent Development Kit,
CrewAI and the OpenAI Agents SDK, and it accepts any Python function. Your
framework keeps running the agent; Brevet serves it its governed rules and
checks each declared tool call. uvx brevet mcp offers the whole loop to any
MCP client (ABOUT.md shows the setup), and
examples/claude-cowork uses it to govern what Claude
itself learns.
Every decision can require the signatures of approvers whose keys are checked against your allowed-signers file or GitHub. Releases are bound to the eval runs behind their numbers, and any release can be rolled back. A recalled rule is withheld from running agents, which confirm it on the record. A tool broker checks the agent's tool calls against the tiers the manifest grants, and the evidence chain is anchored outside the workspace, so even a rewritten chain is caught. ABOUT.md shows how to switch each one on.
brevet benchmark scores a workspace on its four axes.If you use Brevet in research, please cite the paper Brevet: Change Control for What Self-Evolving AI Agents Learn (Shahid, Suttie and Black, 2026). CITATION.cff gives the software citation.
Apache-2.0. See LICENSE. Brevet is a Brightbeam project.
Source-derived launch command. Check the maintainer’s required arguments and credentials before running:
uvx brevetMerge this template into ~/Library/Application Support/Claude/claude_desktop_config.json. Keep existing servers. Add any arguments, credentials, and permissions required by the maintainer; this template has not been install-tested.
{
"mcpServers": {
"io-github-brightbeamai-brevet": {
"command": "uvx",
"args": [
"brevet"
]
}
}
}Restart Claude Desktop completely for changes to take effect. Confirm the server appears connected in the client’s tool list, then try a read-only example from its documentation.
Claude Desktop setup referenceBrevet works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.
~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.~/.cursor/mcp.jsonRestart Cursor for changes to take effect..vscode/mcp.jsonReload VS Code window for changes to take effect.~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect..mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.