OpsGuard AI is a multi-tenant, AI-assisted operational workflow platform for controlled request intake, assessment, approval, integration execution, reconciliation, and audit.
This repository contains the Week 1 foundations through Day 12: Evaluation Runner, plus a submission-focused hackathon demo slice. It includes deterministic request creation, tenant-aware PostgreSQL persistence, provider-neutral structured assessment, an OpenAI adapter, and evaluation coverage. It does not include workflow execution, tools, retrieval, or production authentication.
The single-page React/Vite demo exposes one controlled workflow: create a synthetic tenant-scoped request, ask GPT for a structured proposal, validate it, apply deterministic route policy, persist audit lineage, and display the outcome. No external action is executed.
pnpm infra:up
pnpm db:migrate
pnpm demo:seed
pnpm dev:api
pnpm dev:webConfigure the API and web variables from .env.example, including a server-only OpenAI key and an
explicit CORS origin allowlist. See the demo specification and
demo runbook for the architecture, security boundary, scenarios,
local smoke test, and deployment checklist.
- AI output is an untrusted proposal, never authority.
- The deterministic application owns tenant context, authorization, validation, workflow state, approvals, side effects, retries, reconciliation, budgets, and audit.
- Dependencies point inward through application-owned contracts and ports.
- Later roadmap capabilities must not be implemented before their owning slice.
The accepted baselines are documented in:
- Product problem statement
- V1 scope
- System context
- Domain boundaries
- ADR-0001: Model responsibility boundary
- Authoritative threat-model baseline
- Initial tenant-aware data model
- Database migrations and recovery
apps/
api/
web/
workflow-worker/
evaluation-cli/
packages/
domain/
application/
database/
auth/
contracts/
ai-core/
config/
observability/
testing/
Each workspace is private, uses ECMAScript modules, extends the shared strict TypeScript configuration, and participates in the shared lint, typecheck, test, and build task graph.
- Node.js 22.13 or newer
- pnpm 11
- Docker Engine with Docker Compose v2.20 or newer (for local infrastructure)
The exact pnpm version is pinned through the root packageManager field.
pnpm install
pnpm format:check
pnpm lint
pnpm typecheck
pnpm test
pnpm buildRun pnpm format to apply the shared Prettier configuration to supported foundation files. Day 1 documentation and uploaded source material are intentionally excluded from automated formatting.
The local-only Compose environment provides PostgreSQL with pgvector available, isolated Temporal persistence, Redis, MinIO, Temporal and its UI, an OpenTelemetry Collector, and Jaeger.
cp .env.example .env
pnpm infra:config
pnpm infra:up
pnpm infra:ps
pnpm infra:downSee the local environment guide for endpoints, credentials, health checks, troubleshooting, and the explicitly guarded state-reset command.
The application PostgreSQL schema contains the Day 4 tenant, user, membership, request, request-history, AI-run metadata, prompt-version metadata, model-configuration metadata, and audit tables. Composite foreign keys enforce same-tenant relationships at the database boundary. Day 6 adds active-membership resolution and atomic request, initial-history, and creation-audit persistence. Row-level security, production authentication, broader request operations, workflow execution, and external integrations remain deferred.
pnpm db:generate
pnpm db:check
pnpm db:migrate
pnpm db:testpnpm db:test creates and removes a guarded, randomly named isolated test database; it never resets
the normal application database. See the migration and recovery guide
before changing or applying migrations.