Skip to content
Open the dashboard
Start here

What is Groundrule?

7 min read

Groundrule turns your team’s engineering standards into two things: instructions that every coding agent reads before it writes code, and checks that run on every change. You keep one rulebook. Groundrule keeps the agent files and the checks in step with it, in every repository.

Every engineering team has rules. Money is stored in cents. Never call Stripe directly; go through the gateway. Never log a session cookie. Today those rules live in three places, and all three leak:

  • People’s heads. New engineers learn them in code review, one comment at a time.
  • A wiki, a handbook, a Notion page. Written once, rarely read, never checked.
  • Agent files. AGENTS.md, CLAUDE.md, .cursor/rules: copied between repositories, each one slightly different, none of them enforced.

Coding agents make the gap wider. An agent writes a lot of code, fast, and it follows only the rules it is given. If the rule isn’t in its instructions, the agent doesn’t know it. If nothing checks the rule, nobody notices until review.

Groundrule works in four steps. The dashboard, the command-line tool (CLI), and coding agents all use the same rulebook.

Step What happens Where
Define Start from maintained packs (security, TypeScript, Docker, GitHub Actions and more), adopt them rule by rule, and write your own standards. Dashboard
Import Scan your repositories for the rules they already have: agent files, lint settings, CODEOWNERS. Read handbooks, PDFs, Notion and Confluence pages, and pull-request reviews. Everything found becomes a proposal. CLI and dashboard
Review Proposals wait in an inbox, routed to the people who own each category. Someone accepts, edits or rejects each one. Nothing changes until a person decides. Dashboard
Teach and enforce groundrule sync writes the rules into every agent’s instructions. groundrule check checks changes locally and in CI. Each rule moves through stages, Observe → Teach → Advise → Enforce, when the evidence from your own code says it is ready. CLI, CI, coding agents

The Groundrule dashboard for a workspace called Acme Payments: a greeting, setup progress, and the rulebook’s standards.

Groundrule has two parts:

  • The open-source kernel (Apache-2.0). It includes the rule format, the groundrule CLI, the checks, the packs, and an MCP server for coding agents. It works fully offline in one repository: write standards as YAML files, run sync and check, and nothing leaves your machine. Source: groundrule-oss.
  • The Groundrule platform at app.groundrule.dev. It adds what an organization needs:
    • one rulebook across every repository, with teams, owners and roles;
    • the catalog, the review inbox, and imports from repositories, documents and pull requests;
    • evidence across repositories, and promotions;
    • AI that drafts rules for people to review.

A repository connects to the platform with one line in .groundrule/config.yaml. From then on, the CLI fetches the organization’s rulebook, and everything else works the same.

These are deliberate choices, and they hold everywhere in the product:

  • AI never changes your rulebook on its own. AI drafts rules, finds rules in documents and suggests checks. Every result is a proposal labelled AI with a confidence, and a person accepts it or not.
  • It doesn’t upload your source code. A scan sends results: counts, which rules pass, and short snippets around findings. You can turn snippets off. Imported documents are deleted once they have been read. See What we store.
  • It doesn’t block anyone by surprise. A rule reaches Enforce only when someone moves it there, and Groundrule suggests that only after the rule has been clean in your repositories for long enough.
  • It doesn’t block pull requests on GitHub yet. Today, checks run where you run the CLI: on a laptop, in a pre-commit hook, or as a CI step that fails the build. A GitHub App that checks pull requests directly is planned. The GitHub App available today reads review comments to find rules.

Groundrule is in private early access. The dashboard, the CLI, the MCP server, and every feature in these docs are working today. Where something isn’t built yet, these pages say not yet.