Softsensor product · Open source · Apache-2.0 core

The governed execution layer for agentic software delivery.

Teams now run fleets of coding agents and production-facing MCP tools. Concord gives each task a governed harness — code, deploy, live investigation, bootstrap job, or data product — and records the proof in a single source of truthful intelligence.

✈️ Air-traffic control for code, runtime evidence, data contracts and deploy checks — across Claude · Codex · Gemini
Proven, not theoretical

Concord runs Softsensor's own delivery.

This isn't a framework we hope you'll try — it's the governed execution layer behind our production AI. The case studies on this site shipped through Concord — the “single source of truthful intelligence” we named in 2020, now the system we run on.

PORTFOLIO

15+

Production AI projects governed end-to-end — pharma, clinical, claims, education, hospitality, logistics and data.

THROUGHPUT

1,400+

Governed, evidence-backed changes shipped — each attributed, gated and journaled.

CONCURRENCY

18 in parallel

Peak concurrent agents on a single project — dozens a day — coordinated with no collisions or lost writes.

DOGFOOD

Ships this site

softsensor.ai itself is built, gated and deployed through Concord.

Across these projects Concord has coordinated 500+ agent identities over 1,200+ sessions and 17,000+ governed events — both orchestrated sub-agents and independent terminal agents, governed identically. Figures reflect Softsensor's own governed delivery; client names are withheld for confidentiality.

Lineage: Concord grew out of AI Agent Setup — our open-source, skill-aware tooling for standing up Claude, Codex and Gemini on any repo (2025, Apache-2.0). First we made agents easy to set up; then we made them accountable.

The problem

Fleets of agents are easy to run. Hard to trust.

Running parallel coding agents is now a commodity. The unsolved part is proving what happened before merge, after deploy, and inside production-facing investigations.

Collision

Agents collide

Parallel agents race on shared files, overwrite each other's work, and leave ownership of every change unclear.

Amnesia

Evidence disappears

Prompts, plans, test runs, live reads, bootstrap jobs and rationale scatter across terminals and chat logs — gone by the time anyone asks.

Compliance

Your controls still apply

Review evidence, traceability, runtime proof and change-control history are mandatory however the work was generated.

The critical capability

One control plane for the whole engineering fleet.

The agents are the workforce; Concord is the control plane that coordinates them, gives each a role, and accounts for everything they do — across repos, providers, runtime tools, and proof types.

Coordinate

Parallel, without collisions

Every agent works in its own git worktree behind a per-ticket lock — so a fleet runs in parallel, across many repositories, with clear ownership and zero overwrites.

  • Isolated worktree + branch per ticket
  • One owner, one lock
  • Multi-repo by design
Orchestrate

A team, not a swarm

Governed roles take work from plan → build → review → test → land, in either topology: independent agents, or an orchestrator directing sub-agents.

  • Role skills: planner · coder · reviewer · QA · lander
  • Two governed topologies
  • Provider-agnostic: Claude · Codex · Gemini
Account

Who did what, provably

Every transition is attributed to a specific agent, under a specific reviewer, in an append-only journal — so multi-agent work is replayable and auditable.

  • Per-agent provenance
  • Append-only, tamper-evident journal
  • Source-vs-landed commit lineage
Multi-repoMulti-providerTrack-specific gatesRuntime receiptsApache-2.0 core
The governed lifecycle

Govern → Gate → Record → See.

Every unit of agent work runs the same path — and lands in a tamper-evident journal. The proof changes by track, so a live production read is not verified like a code diff.

01 · GOVERN

Isolated work

Worktree + branch + lock per ticket. Many agents, many repos — no collisions.

02 · GATE

Right proof

Tests for code, content checks for pages, receipts for live-MCP work, data contracts for analytics, deploy evidence for runtime work.

03 · RECORD

Append-only journal

Every transition recorded with actor and provenance — a verifiable history of who did what, under whose review.

04 · SEE

Operator cockpit

A read-only web view renders the board, traceability, gates, live-MCP receipts, bootstrap risk, runtime health and timeline.

To do
CASE-204
Evidence-gated closure
Doing
RISK-077
SLA auto-escalation
2 gates
Review
INTEL-006
Translation svc
4/4
Done
COORD-019
Evidence export
landed ✓
4182 {"event":"gate.passed","ticket":"RISK-077","actor":"agent:claude/s-9c4"}
4184 {"event":"landing.recorded","reviewer":"human:dchen","status":"complete ✓"}

The cockpit shows the evidence, live

  • Board & timeline — kanban plus the full event log
  • Traceability — requirement → implementation closure & feature proof
  • Gates & health — quality, runtime and deploy-gate artifacts
  • Live evidence — scoped MCP receipts, bootstrap-risk checks, waivers and config posture
  • Pipeline — landing & PR provenance (source vs landed commit)
What is new

One lifecycle. Different proof harnesses.

Concord now governs more than code diffs. It gives each work type the evidence standard it actually needs, while keeping one board, one journal and one recovery model.

Development

Code work proves tests and review

Per-ticket worktrees, locks, review cycles, feature proof, contract checks, quality dimensions and source-to-landed commit lineage.

  • Architecture, coverage, mutation and SAST policy checks
  • Fail-closed review before landing
  • Recovery when an agent stalls or dies
Runtime

Live work proves receipts

Production-MCP investigations, deploy checks and bootstrap/backfill jobs record scoped, redacted, source-cited evidence instead of relying on "readyz returned 200".

  • Operation classes and approval posture
  • Deploy identity and verify/falsify records
  • Cleanup proof for temporary access
Data & memory

Data products prove contracts

Analytical products certify data contracts, row-count reconciliation, lineage and quality gates. The same journal feeds governed memory: cited decisions, summaries and recall.

  • Certified-only-feeds-certified lineage
  • Before/after row-count proof
  • Decision memory and execution insights
Why Concord

Rulesets tell you a check ran. Auditors need more.

Branch protection governs the pull request. Concord governs the agent work before the PR — and turns it into a record an auditor can use.

GitHub / GitLab rulesets + CIThe pull request is governed

Required checks, protected branches, CODEOWNERS, approvals. Strong process enforcement — but no record of which agent did what before the PR, no runtime proof after deploy, and no governed memory of the decision trail.

ConcordThe work is governed — and provable

Task locks, worktree isolation, requirement closure, agent provenance, track-specific proof, runtime receipts, fail-closed review and governed memory — across providers, repositories and live engineering workflows.

Built for the audits you already have

Evidence your existing controls can use.

AI coding agents and MCP-powered runtime work don't remove SDLC, CSV or change-control expectations. Concord is built for the regimes you already answer to — producing review evidence, traceability, runtime receipts and change history as a by-product of the workflow.

Change control

SOC 2 · SOX ITGC · ISO 42001

Per-change closure, review cycles and an attributable audit trail — the records these regimes ask for.

Regulated SDLC

GxP · FDA CSA (building toward)

Traceability and fail-closed, control-mapped export — aligned to the direction of the FDA's Computer Software Assurance guidance (records over screenshots).

AI governance

EU AI Act · NIST AI RMF

Indicative control maps included; the evidence export fails closed if anything required is missing.

We describe Concord as designed for / building toward these regimes — it produces evidence and indicative maps, not a certification, validation, or claim of conformity.

Cost of control

Governed fleets can cost less than ungoverned ones.

Governance adds structure — but it removes waste, because Concord holds the context, decisions and evidence agents otherwise re-pay to rediscover.

Avoid

No redundant runs

Cheap pre-checks classify already-satisfied work before an agent is ever dispatched.

Reuse

Shared memory

Decision records, summary tiers, recall and graph context let agents retrieve the relevant slice instead of replaying the whole history.

Right-size

Proof to risk

Evidence depth follows the track — lighter for mechanical edits, stricter for production reads, data products, deploys and bootstrap jobs.

A cost-ledger records spend per change in the same journal that proves the controls — so savings are measured, not estimated. Blended figures will be published from design-partner pilots.

Editions

Open core for teams. Enterprise layer for your trust boundary.

The repo-local governed workflow is open source. Enterprise packaging adds org-wide collection, policy and deployment patterns for customers who need central command-center evidence.

Community

Free · Apache-2.0 · self-hosted
  • Governed lifecycle engine + CLI
  • Multi-agent coordination & isolated worktrees
  • Track-specific gates for code, content, infra, live-MCP and data work
  • Runtime receipts, deploy checks and data-contract certification
  • Read-only local cockpit + governed memory scripts
View GitHub repo
ENTERPRISE

Command Center

Customer-cloud package · design-partner deployment
  • Org collector, warehouse and rollups across many coord instances
  • Central re-hash verification and signed conformance bundles
  • RBAC and broker enforcement contracts for customer SSO/KMS integration
  • Development-landscape adapters for Jira, GitHub, CI and service signals
  • Reference deploy scaffold, audit export and support path
Talk enterprise

Make agentic delivery accountable.

Run coding agents, production-MCP investigations, bootstrap jobs and data products through one governed execution record.