Skip to content
Open the dashboard
Reference

FAQ

Short answers, each with a link to the page that covers it in full.

Not in full. groundrule sync and groundrule check download your rulebook and run on your machine or in your CI; your code stays there. groundrule scan --upload sends results: counts, which rules pass, short snippets around findings, and the instructions found in agent files, with secrets redacted. --no-snippets leaves the snippets out, --no-import leaves out the agent-file instructions, tool settings, and owners, and --json shows exactly what would be sent. See What we store.

Groundrule reads the text, sends passages to the AI model with secrets removed, and creates proposals that cite where each rule came from. The uploaded file isn’t kept, and the document’s text is deleted once reading finishes. See Import documents.

No. AI is off in a new workspace, and everything except AI drafting and document reading works without it: packs, your own standards, scans, the inbox, sync, and check. See AI settings and usage.

What AI model does Groundrule use, and is my data used for training?

Section titled “What AI model does Groundrule use, and is my data used for training?”

Claude Opus 5.5, by Anthropic. How requests are handled, what’s removed first, and what the provider may keep is explained in AI and your data.

No. AI writes drafts and proposals, labelled AI with a confidence. A person accepts, edits, or rejects each one. Nothing in your rulebook changes until someone decides.

You have several options, from narrowest to broadest:

  • Record an exception for the files it shouldn’t apply to, with a reason and an expiry date.
  • Move it back to an earlier stage, such as Advise, so it stops failing checks.
  • Lower its severity.
  • Turn it off for the organization, with a reason.
  • If it’s a pack rule, change its wording or scope; you keep receiving the pack’s updates.

Developers who disagree with a rule can say so with npx @groundrule/cli propose, and the proposal waits in the inbox for a reviewer. See Proposals from developers.

No. A team or repository can only be stricter than the organization: a later stage, a higher severity, or extra guidance. To loosen a rule in one place, change the organization’s setting, or record an exception in the repository. See Adopting rules.

Pack updates reach your rulebook, and your own changes stay on top of them. Each rule you changed shows yours next to upstream. A new pack version can be marked as reviewed from the pack’s page. See Adopting rules.

Can I write rules as code instead of in the dashboard?

Section titled “Can I write rules as code instead of in the dashboard?”

Yes. Standards are YAML files in an open format. In a repository, put them in .groundrule/standards/. The dashboard edits the same format and has a YAML view. See The rule format.

Only where you run groundrule check, such as a CI step you add. A rule fails the check only when it’s at Enforce and its severity is at or above the failOn setting, which is blocker by default. Rules start at earlier stages, and Groundrule suggests moving to Enforce only after a rule has been clean in your repositories for long enough. See Rollout stages and Run Groundrule in CI.

Does Groundrule check pull requests on GitHub directly?

Section titled “Does Groundrule check pull requests on GitHub directly?”

Not yet. Today, checks run where you run the CLI: on a laptop, in a pre-commit hook, or in CI. The GitHub App available today reads review comments to find rules. See Rules from pull-request reviews.

No. By default groundrule check looks at changed lines only, and existing violations are reported without failing (legacy: report). Use --all to audit the whole repository. See Check your changes.

Does it work with GitLab, Bitbucket, or other CI systems?

Section titled “Does it work with GitLab, Bitbucket, or other CI systems?”

The CLI runs in any CI that can run Node.js 22 or later; it needs the GROUNDRULE_TOKEN secret and git history to compare against. The GitHub App, which reads review comments, works with GitHub only. See Run Groundrule in CI.

groundrule sync writes four formats: AGENTS.md, CLAUDE.md for Claude Code, Cursor rules, and GitHub Copilot instructions. Agents that read AGENTS.md get the rules from it. Agents that support MCP can also list your rules and propose new ones through npx @groundrule/cli mcp. See Agent instruction files and The MCP server.

Guidance works for any language, because it’s text for your coding agents. Checks work on any text file: regular expressions and file checks apply to every language, dependency checks read package.json, Maven, Gradle, Python, Go, and Cargo manifests, and Semgrep checks run if Semgrep is installed. The catalog has packs for TypeScript and Node.js, React, Python, Java and Spring, Go, Docker, Kubernetes, Terraform, and GitHub Actions, plus language-neutral packs for security, HTTP APIs, testing, and coding-agent hygiene. See Packs.

No. The open-source CLI works fully offline in one repository: run npx @groundrule/cli init --packs security-baseline,typescript-node, then sync and check. Nothing leaves your machine. The platform adds one rulebook across repositories, teams and roles, the inbox, imports, evidence, promotions, and AI. See Use Groundrule without the platform.

Yes, without the platform, as above. A repository connected to the platform needs to reach it to fetch the rulebook when you run sync or check.

Typical costs are about $0.01 to draft a standard from one instruction, $0.05 to write one from a description, and $0.06 to read a 300-word handbook. Each workspace has a monthly budget, $25 by default, set by an admin. AI stops for the month when it’s reached. See AI settings and usage.

Groundrule is in private early access. Sign up at app.groundrule.dev, or use the invitation a teammate sent you. See Create your account.

The kernel is: the rule format, the CLI, the checks, the packs, and the MCP server, under Apache-2.0 at groundrule-oss. The hosted platform at app.groundrule.dev is not.

Not yet.

No. It’s used in every connected repository’s configuration. You can rename the workspace’s display name in Settings → Workspace.

Not yet. Admins can remove every other member, and each person can leave.

What happens to someone’s API tokens when they leave?

Section titled “What happens to someone’s API tokens when they leave?”

They stop working immediately. If a CI job used one of their tokens, create a new token before they leave. See API tokens.