Skip to content

YggdrasilSay it once.

Write a rule and it holds in every session after that, without you repeating yourself. The agent gets only the rules that touch the file it is editing, and has to satisfy them before it moves on.

Yggdrasil

The same rule, two sessions apart

Monday. You ask for a charge endpoint. Before writing anything, the agent pulls the rules that touch that file: audit events, input validation, no direct database access. It writes to them, and the check still catches a missing audit call. It fixes that and moves on.

The following week, new session. You ask for a refund endpoint. You say nothing about audit events. The same three rules are still in force, the agent writes to them, and the check passes first time.

That gap is the point. A rules file is re-read and half-applied every session. A rule here is attached to the code it governs and verified against it, so it survives the session boundary without you in the middle.

A rule is plain text

You write what must be true and why. The reviewer reads it and checks your code against it.

markdown
# Audit logging on payment mutations

Every function that changes a payment record must call
auditLog.emit() before it returns. A mutation with no
audit event is a refusal.

When a script can decide it, you write the rule as a small local script instead. It runs for free, with no model at all, whenever a check fills verdicts — yg check --approve, or the yg check --approve --only-deterministic step CI and pre-commit run to keep it cheap and keyless. A plain yg check is a pure read: it re-hashes the verdicts already recorded and re-runs the built-in relation-conformance pass, but it does not execute the script fresh. (Unless the repo sets auto_approve in yg-config.yaml, which makes a bare yg check fill verdicts too — see The lock. It is also why the keyless-CI guarantee above is stated with the flags: CI passes them explicitly — yg check --approve --only-deterministic, then yg check --no-approve — and explicit flags always win over the config, so a repo on auto_approve: full cannot quietly turn the CI step into a reviewer fill that verifies an unverified change instead of refusing it.)

See it catch a mistake

The rule above is in place. The agent writes a refund and skips the audit call.

ts
async function refund(req) {
  await payments.refund(req.body.chargeId)
  return { ok: true }
}
ts
async function refund(req) {
  await payments.refund(req.body.chargeId)
  await audit('refund', req.body.chargeId) // added
  return { ok: true }
}

The reviewer refused the first version at yg check --approve: "refund changes a charge with no audit event." The agent added the call, re-ran, and passed. You reviewed nothing.

Two limits, before you start

It enforces structure, not runtime behaviour. It can require that you call the audit utility. It cannot prove the audit fired in production.

A green check is only as good as the rule behind it. A shallow rule passes shallow code. The enforcement is real; deciding what is worth enforcing stays yours.

Next

New here? Read How it works for the model, then Get started. If you are adopting this on an existing codebase, read Phase 0 first — the honest version of what it costs before it pays.