A team, not a lone agent.
Each role gets only the tools its job needs. A Reviewer has no write tool at all, so it cannot be talked into editing.
Open source · Apache-2.0 · v0.2.0-beta.3
docket runs a small team of AI agents on your codebase. One plans, one writes, one reviews. Every file edit, shell command and API call passes one gate first, and the risky ones wait for you.
$ docket policies test pre_tool_call implementer 'git push origin production' Result: require_approval $ docket pod myapp dispatch → Dispatching 1 pending task(s) through: lead → implementer → reviewer ⋯ tool.ask tool=bash policy_id=high-risk-deploy ⋯ approval.deny channel=timeout $ docket audit verify ✓ 6 chained line(s) verified clean.
The usual way
With docket
git push origin production is held by code until a person says yes.Each role gets only the tools its job needs. A Reviewer has no write tool at all, so it cannot be talked into editing.
Built-in tools and MCP tools alike pass the same policy check before they run. There is no setting that turns it off.
Runs, traces, approvals and token counts stay queryable after the turn. docket audit verify tells you if the log was touched.
How it works
docket init sets up a pod: a small team scoped to one project. docket pod <id> dispatch runs a task through it.
Reviewer and Tester are optional. When they are on, their verdict blocks the task: it is not advice a model can argue past. Blueprints shape the same pipeline for research, content, ops or product work.
The gate
Every action takes the same path: policy, risk check, a person if needed, budget, then execution. Here is what that looks like.
git push origin productionDeploys, money and secrets are high-risk. The call pauses until someone approves it from the CLI, HTTP, MCP or Telegram. No answer in 120 seconds means denied.
Proof
Captured from real runs against a local model on 2026-09-18. Every line is what the CLI printed.


Three ways in
docketSet up a pod and dispatch tasks against your own repo. The fastest way to a governed run.
docket harness runOne agent, one turn, driven by another program. It never waits for a person: anything that needs approval ends the run as blocked.
docket-runtimeSend your app’s own tools through the same policy, approval and audit gate. Two dependencies. Built from source.
Get started
Install, point it at a model, and dispatch a task. Local models work.
brew tap yielab/docket-cli https://github.com/yielab/docket brew install docket-cli
docket models provider add local http://127.0.0.1:8081/v1 \ --model local-model --ctx 32768 --max-tokens 4096 docket models preset local cd ~/code/myapp docket init docket pod myapp delegate "Create FIRST_TURN.md containing: governed first turn" docket pod myapp dispatch docket runs list docket trace tail myapp docket audit verify
Needs Python 3.11+, Git, Bash, and an OpenAI-compatible endpoint with tool calling: hosted (OpenRouter, Vercel AI Gateway) or local (llama.cpp, vLLM, LM Studio).
Read the full quick start →Open source under Apache-2.0. Read the code, run it on your own machine, and check every decision it made.