instruxi-io/enforcer
Enforcer for your agent: the MCP connection, one sign-in, workspace switching and setup, the graph worker and the governor.
How Enforcer is organised — tenants, accounts, roles, scopes — and how to look up anything else from the live API instead of from memory. Use when the user mentions Enforcer, their workspace or tenant, members, invites, roles, API keys, or asks what they can do through the Enforcer MCP server.
Work with files in the user's Enforcer workspace — find, inspect, share with a group, upload and download. Use when the user mentions files, documents, uploads, attachments or storage in Enforcer, or asks to put a local file into their workspace or get one out of it.
The Enforcer governor — decides whether an agent action is allowed before it runs and keeps a tamper-evident record of every decision. Use when the user asks what the governor has seen, its spend limit or settings, or whether the decision record is intact.
Work a plan held in the enforcer graph — claim the next runnable node yourself, do it, keep the lease alive, report it against its acceptance criteria with captured command output as evidence. Use when a project has .claude/graph.json, when asked to "work the plan", "take the next node", "claim from the frontier", when a coordinator hands you a graph node to work as a subagent, when fanning a plan out to subagents, or when the enforcer graph MCP tools (graph_next_work, graph_report, graph_heartbeat, graph_plan_status, graph_remember) are available.