Bernstein: Open-Source Governance and Orchestration for AI Agents
This repository profile is provided by osrepos.com, an open source repository discovery platform.

Summary
Bernstein is an open-source framework designed for the governance and orchestration of AI agents, allowing users to define rules declaratively. It enforces these policies and generates verifiable, replayable records of all agent activities. This Python-based solution provides a robust layer for managing complex AI agent workflows with transparency and accountability.
Repository Information
Topics
Click on any tag to explore related repositories
Use at your own risk
OSRepos shares public repositories for knowledge and discovery only. Any installation, execution, configuration, or use of code from these repositories is the user's own responsibility. Always review the repository, source code, dependencies, licenses, and security implications before running or installing anything. OSRepos is not responsible for issues, damages, or losses resulting from third-party repositories.
Introduction
Bernstein is an innovative open-source framework that serves as the governance and orchestration layer for AI agents. It empowers users to define rules declaratively, specifying who can perform what actions, what requires approval, and what must be recorded. Bernstein then enforces these policies, generating a verifiable and replayable record of every operation. This project is free and distributed under the Apache-2.0 license, emphasizing transparency and control in AI agent deployments.
Why Use Bernstein and Key Advantages
Bernstein stands out with several core differentiators that address critical challenges in AI agent management:
- No LLM in the Coordination Loop: Unlike many other frameworks, Bernstein's scheduler is implemented in plain Python, ensuring that agent runs are reproducible end-to-end. This deterministic approach means replaying a plan yields the exact same task graph, eliminating non-determinism in coordination.
- Checkable After the Fact: Every run is meticulously recorded in a replay journal, and a continuous lineage spine tracks all lineage-bearing steps. An opt-in HMAC-chained audit log (
BERNSTEIN_AUDIT=1) adds verifiable receipts that can be checked offline. This design allows for post-facto verification, identifying any non-determinism as a hash mismatch at the precise step. - Isolated by Construction: Each coding task operates within its own isolated Git worktree, protected by merge gates. Artifact-mode tasks receive a dedicated working directory. By default, agents do not share mutable workspaces, with shared state limited to an atomically claimed task backlog. Stricter filesystem enforcement is available through sandbox backends.
- Broad and Local: Bernstein offers extensive compatibility with 52 selectable CLI agent adapters, alongside a generic
--promptwrapper. It operates with file-based state, avoiding SaaS dependencies or third-party data planes, making it suitable for air-gapped environments.
Installation
Getting started with Bernstein is straightforward. You can install it using uv or pipx:
uv tool install bernstein # or: pipx install bernstein
bernstein init
bernstein doctor # checks a CLI agent is installed and authenticated
bernstein -g "fix the failing test in tests/test_foo.py"
For more detailed installation instructions, including options for pip, brew, dnf, npm, Docker, and air-gapped deployments, refer to the official install guide.
Examples
Bernstein allows you to define complex agent workflows using declarative YAML files. Here is an example of a workflow designed to produce an audit evidence pack:
name: audit-evidence-pack
version: "1.0.0"
phases:
- name: scope
allowed_roles: [manager, architect]
- name: collect
- name: validate
allowed_roles: [qa, security]
- name: deliver
allowed_roles: [security, manager]
nodes:
define-control-inventory:
phase: scope
role: architect
collect-audit-logs:
phase: collect
role: security
depends_on: [define-control-inventory]
# three more evidence streams collect in parallel:
# collect-sboms-and-attestations, collect-runbooks-and-policies,
# collect-eval-results
assemble-pack:
phase: validate
role: docs
depends_on:
- collect-audit-logs
- collect-sboms-and-attestations
- collect-runbooks-and-policies
- collect-eval-results
mock-auditor-pass:
phase: validate
role: qa
depends_on: [assemble-pack]
remediate-findings:
phase: collect
role: docs
depends_on:
- source: mock-auditor-pass
condition: "status == 'failed'"
retry:
max_attempts: 3
until: "status == 'done'"
sign-and-deliver:
phase: deliver
role: security
depends_on:
- source: mock-auditor-pass
condition: "status == 'done'"
You can also verify the integrity of a run offline using a signed receipt:
bernstein verify receipt docs/assets/demo-run/run-receipt.json \
--public-key docs/assets/demo-run/run-receipt.pub.pem
This command re-verifies the committed receipt, ensuring that the published evidence remains untampered.
Links
- GitHub Repository: https://github.com/sipyourdrink-ltd/bernstein
- Official Website: https://bernstein.run
- Documentation: https://docs.bernstein.run/
Related repositories
Similar repositories that may be relevant next.

lat.md: A Knowledge Graph for Your Codebase, Written in Markdown
September 26, 2026
lat.md is an innovative tool that transforms your codebase knowledge into an interconnected graph of markdown files. It helps both AI agents and human developers quickly understand project architecture, business logic, and design decisions. By integrating directly into your project, lat.md ensures documentation remains consistent and up-to-date.

KDA: Kernel Design Agents for High-Performance CUDA Kernel Development
September 26, 2026
Kernel Design Agents (KDA) offers an agent-centric workflow designed to streamline the research, implementation, verification, and iteration of performance-sensitive CUDA kernel tasks. This innovative approach leverages coding agents to accelerate the development of high-performance kernels. It is an early research prototype from NVlabs, welcoming community feedback and contributions.

browser-rs-mcp: Lightweight Stealth Browser Server for AI Agents in Rust
September 25, 2026
browser-rs-mcp is a lightweight, stealth-oriented Model Context Protocol (MCP) browser server written in Rust. It enables multiple AI agents to share a single, persistent Chrome instance, offering over 64 Playwright-style tools without requiring a Node.js runtime. This project is ideal for parallel web scraping, automation, and QA, providing efficient and isolated tab control for each agent.
HarnessRouter: Unified Interface for AI Agent Harnesses
September 22, 2026
HarnessRouter Community Edition provides a self-hosted, Apache-2.0 licensed unified interface for various AI agent harnesses like Codex, Claude Code, and Hermes. It allows users to run multiple agents through a single API, offering features such as sessions, streaming, file handling, and cancellation. The project implements the open-standard Unified Harness Protocol (UHP), ensuring users maintain control over their keys and infrastructure.
Source repository
Open the original repository on GitHub.