Skip to content
Open the dashboard
Build your rulebook

The catalog

Standard ownersEngineering leads6 min read

The catalog lists every standard Groundrule maintains: 171 standards across 13 packs. This page explains what the catalog shows, how to filter it, how to read a rule before you adopt it, and how to get a rule into your rulebook.

The catalog is read-only. It shows the rules as Groundrule ships them, not your settings. Your settings live on each rule’s page in Standards; see Adopting and tuning rules.

Choose Catalog in the sidebar. The page starts with four numbers:

Number What it counts
Standards Every standard in the catalog
Checked Standards with at least one automated check
Packs Packs in the catalog, and how many are turned on in your workspace
Compliance Standards mapped to at least one compliance control

The Catalog page: the four counts, the Kind switch, the search box, four filters, and a table of standards with severity, starting stage, how each is checked, and its pack.

Each row is one standard. The table is sorted by severity (blockers first), then by ID.

Column What it shows
Standard The ID, the title, and one line on why the rule exists
Severity Blocker, warning, advisory, or info
Starts at The stage Groundrule recommends you start the rule at. A noise label appears next to it when noise is medium or high.
Checked by How the rule is checked: Deterministic, Static analysis, or Agent guidance when it has no check
Pack The pack the standard belongs to. A dot means the pack is turned on in your workspace.

On narrow screens, some columns are hidden. The count under the table reads, for example, “12 of 171”.

You can combine every filter.

Control Options What it matches
Kind All, Checked, Guidance Checked: standards with an automated check. Guidance: standards that are agent guidance only.
Search Free text (“Search by ID, title, or why”) The ID, title, why, category, and pack name
Pack All packs, or one pack The pack a standard belongs to
Stack Any stack, or a language or framework The languages and frameworks a standard applies to, such as typescript or spring-boot
Category All categories, or one category The standard’s category, such as API design, CI, Code quality, or Security
Compliance Any compliance, or one framework Standards mapped to SOC 2, ISO 27001, OWASP ASVS, PCI DSS, HIPAA, or NIST SSDF

If nothing matches, the table says “Nothing matches those filters”. Choose Clear filters to reset every filter and the search.

Select a row to open the rule. The window’s title is the ID and title, with the pack’s name underneath.

A catalog rule, AGENT-010 “No merge conflict markers or merge leftovers”: it is a blocker, starts at Enforce, has low noise and a deterministic check, and the AI coding agent hygiene pack is on, with an Open in your rulebook button.

The labels across the top tell you what adopting the rule would mean:

Label Meaning
Severity How serious a violation is: Blocker, Warning, Advisory, or Info. At Enforce, groundrule check fails on blockers by default.
Starts at stage The stage the rule takes when you turn its pack on: Teach, Advise, or Enforce. No catalog rule starts at Observe. See Rollout stages.
Low noise, Medium noise, High noise How often the check is likely to flag code that is actually fine. Low-noise rules can start at Enforce. Noisier rules start earlier, so you see their findings before they can block anyone.
Deterministic The rule has a check that gives the same result every time, with no AI: a regular expression, a file check, a dependency check, or a change-set check.
Static analysis The rule has a Semgrep check.
Agent guidance The rule has no check. It reaches coding agents as instructions, and reviewers apply it.

The sections below the labels:

Section What it holds
Requirement The rule itself, as agents and reviewers read it
Why Why the rule exists
Known false positives Cases where the check flags code that is correct, and what to do about them. Shown only when the pack lists some.
Supports compliance The controls the rule maps to, such as SOC 2 CC6.1 or OWASP ASVS V2.10.4. Shown only when the rule has mappings.
References Links such as a CWE entry or the tool’s own documentation. Shown only when the rule has references.

Code examples (what to do and what not to do) aren’t in this window. They are on the rule’s page in your rulebook, once its pack is on. You can also read any rule, examples included, with npx @groundrule/cli explain <ID>.

You don’t adopt catalog rules one by one. You turn on the pack that contains them, and every rule in it joins your rulebook at its recommended stage. Then you tune each rule.

The footer of the rule window shows whether its pack is on, for example “AI coding agent hygiene is on”, and offers one action:

What you see When What it does
Open in your rulebook The pack is on Opens the rule’s page in Standards, with its rollout panel and evidence
Turn on pack The pack is off, and you are an admin or platform admin Turns the whole pack on for the workspace
“Ask an admin to turn this pack on.” The pack is off, and you have another role Nothing; ask an admin
  1. Open Catalog and find the rule, for example by searching its ID.

  2. Select the rule to open it, and read its requirement, noise, and known false positives.

  3. Turn on its pack. Choose Turn on pack in the footer. Or go to Packs and turn the pack on there; see Packs.

  4. Choose Open in your rulebook to see how the rule is rolled out in your workspace.

You should see a message such as “Docker turned on”, and the footer changes to Open in your rulebook. Every standard in that pack is now in Standards, each at its recommended stage.

If one of the pack’s IDs is already used by one of your own standards, the pack can’t be turned on, and you see “ID is defined both by your organization and by pack.” Your own standards’ IDs can’t change, and standards can’t be deleted yet, so avoid pack prefixes such as SEC- or TS- for your own IDs. The editor suggests IDs with a prefix taken from your workspace’s URL name, such as ACME-005 for acme-payments. Those IDs skip any ID already in your rulebook, but they can still clash with a pack you turn on later if the prefix matches one, such as GO- for a URL name that starts with go-.