Nishant Tamilselvan

From specification to evidence: how AEGIS keeps a person in charge

AEGIS is my open-source toolkit for delivery with AI agents. It writes the specification first, blocks code until the specification is complete, and records the person who approves the release.

AI makes code cheap to produce, and that moves the constraint to review. Most teams answer with rules: finish the specification before coding, keep a named person accountable, and separate the author of a change from its approver. The rules are easy to write down and hard to keep under a deadline.

AEGIS (Agentic Enterprise Guided Intelligent System) is an open-source toolkit I maintain that makes those rules the default. It runs as agents, prompts, and a command-line validator inside GitHub Copilot and Claude Code. It implements the delivery model of the Enterprise AI Framework, which I also maintain.

The four AEGIS phases Four phases from left to right. Ideation writes six business documents. Architecture writes five technical documents and decision records. Implementation runs one approved work package at a time with an independent reviewer. Release records a named human approver. A validator runs after every change, and a readiness gate blocks code until the specification is complete. IdeationSix businessdocuments ArchitectureFive technicaldocuments anddecision records ImplementationOne work packageat a time, with aseparate reviewer ReleaseA named personapproves. Noautomatic deploy A validator runs after every change.A readiness gate blocks code until the specification is complete.
The AEGIS phases map to the framework's lifecycle gates.

Ideation: purpose and requirements

The ideation orchestrator asks a few questions at a time and waits for answers. It writes six business documents: product requirements, functional and non-functional requirements, a user journey map, a system blueprint, and an executive briefing. After each change, a validator checks every id and cross-reference.

Before it asks anything, AEGIS searches the organization’s standards library and uses only standards marked approved. The user is asked only about what the standards leave open.

Architecture: constraints and decisions

Specialist agents propose the interface, data, security, deployment, and observability architecture. Each material choice becomes an architecture decision record, so the reasoning survives the project.

Implementation: bounded work and independent review

A read-only readiness gate runs first. It stops if any document is still a draft, a blocking decision is open, or a contract is missing. A planner then splits the work into packages, and each package declares its paths, tests, and acceptance criteria.

A code agent works on one package at a time, and a hook blocks it from writing anywhere else. An independent reviewer reruns the checks and returns a pass or a list of changes.

Release: a named human decides

The release command records the approver by name. AEGIS never deploys by itself.

What AEGIS leaves to you

Expectation What to add
A second human approves each AI-made change The per-package reviewer is an agent. Require human pull request review
Operate and monitor Your operations tooling and an AI incident response process
Change or retire Your change process, with the AEGIS documents as the record

AEGIS 0.2.0 installs with pip install aegis-sdlc. The getting started guide covers GitHub Copilot and Claude Code setups, and the framework’s walkthrough post follows one example from a one-line idea to a named release approval.