Stop hoping Claude does the right thing. Start governing it.
Every time you use Claude, it operates with no guardrails, no memory of what mode you're in, and no record of what happened. That's fine for casual chat. It's not fine when you're working on production systems, financial analysis, security reviews, or anything where "Claude just winged it" isn't acceptable.
MO§ES™ adds what Claude doesn't have: behavioral modes that constrain how it responds, operational posture that controls what it's allowed to do, and a cryptographic audit trail that proves what was governed and when.
Type /govern high-security and Claude stops guessing — it verifies claims, requires confirmation before destructive actions, and logs its reasoning chain. Type /posture scout and Claude gathers information only — no file writes, no code execution, no state changes. Every governance decision is logged with SHA-256 hashes to an append-only ledger.
Install it. Set a mode. Work normally. Governance enforces automatically.
This plugin turns any Claude Code session into a constitutionally governed agent. Install it, and every agent you build inherits behavioral modes, posture controls, role hierarchy, and a cryptographic audit trail — without writing governance logic yourself.
Your users never touch this plugin. Your agents carry it for them.
# Local install (works now)
claude --plugin-dir ./moses-governance
# From marketplace (after acceptance)
/plugin install moses-governanceThat's it. Governance is active. Run /status to see it.
The plugin ships with three agent definitions. Each one enforces governance automatically.
The operator. Leads analysis, sets direction, responds first. Full tool access. Checks governance mode, posture, and vault context before every action. Logs everything to the audit chain.
Use case: Your main execution agent — research, analysis, code generation,
task completion. Governed by default.
The validator. Responds after Primary. Must add new value — cannot repeat what Primary said. Challenges, extends, and stress-tests Primary's output.
Use case: Code review, second opinion, adversarial testing, quality gates.
Deploy alongside Primary for any high-stakes workflow.
Constitutional oversight. Cannot initiate actions. Cannot generate original analysis. Can only flag risks, gaps, inconsistencies, and governance violations in Primary and Secondary output. Read-only tools.
Use case: Compliance monitoring, audit oversight, safety review.
The agent that watches the other agents.
/role primary # Agent 1 leads
/role secondary # Agent 2 validates
/role observer # Agent 3 overseesPrimary proposes. Secondary challenges. Observer flags. Every action audited. Constitutional chain of command enforced automatically.
Set what the agent CAN and CANNOT do.
/govern high-security # Maximum constraints
/govern high-integrity # Accuracy-first
/govern creative # Expanded freedom
/govern research # Methodology-first
/govern self-growth # Reflective
/govern problem-solving # Analytical
/govern idk # Exploratory
/govern unrestricted # Full capacity — operator assumes riskEach mode translates to specific behavioral constraints. Not suggestions. Constraints.
Set HOW the agent operates within its mode.
/posture scout # Gather information, report back
/posture defense # Conservative execution, verify before acting
/posture offense # Execute within mode constraints, deliver resultsLoad governance documents directly into the agent's operating context.
/vault load compliance-framework.md
/vault load risk-policy.md
/vault load persona-spec.mdWhatever you load becomes constitutional context. Protocols, personas, compliance frameworks — injected, not optional.
Every governed action produces a SHA-256 hash chained to the previous entry.
/audit # View recent entries
/audit verify # Verify entire chain integrity
/hash <content> # Generate standalone integrity hashTamper-evident. Append-only. If anyone modifies a prior entry, the chain breaks.
Governed trading agent — high-security mode + defense posture. Agent analyzes but cannot execute trades without explicit posture switch. Every recommendation audited.
Governed research agent — research mode + scout posture. Primary investigates. Secondary validates methodology. Observer flags bias. All governed. All audited.
Governed code review pipeline — Primary writes. Secondary reviews. Observer checks compliance. Constitutional hierarchy enforced.
Multi-agent governance — Primary, Secondary, Observer as a team. No agent bypasses its role. Observer cannot be overridden.
| Skill | What It Does |
|---|---|
| governance-mode | Enforces mode constraints on every action |
| posture-control | Checks posture policy before execution |
| role-hierarchy | Enforces sequence in multi-agent workflows |
| audit-trail | Logs every action with SHA-256 chain |
| context-assembly | Builds governed payload from active state |
| doc-numbering | Sequential numbering and cross-references |
| vault | Document injection and context management |
| coverify | Commitment conservation verification — ghost tokens, Jaccard scoring, cascade risk |
| lineage | Cryptographic origin verification — three-layer custody chain |
| Command | Purpose |
|---|---|
/govern <mode> |
Set behavioral mode |
/posture <posture> |
Set operational posture |
/role <role> |
Set hierarchy position |
/vault <action> |
Load governance documents |
/command <settings> |
Fine-grained controls |
/audit |
View and verify audit trail |
/hash <content> |
Generate integrity hash |
/status |
Full governance state |
/docs |
Document index and session management |
/lineage |
Verify origin-cycle custody chain |
| Script | What It Does |
|---|---|
governance.py |
Mode translation, action checking, state persistence |
audit.py |
SHA-256 hash chain, append-only ledger, tamper detection |
sequence.py |
Role ordering, hierarchy enforcement, violation checking |
vault.py |
Document management, context injection, categories |
commitment_verify.py |
CoVerify — extract kernels, Jaccard scoring, ghost token detection |
lineage.py |
Three-layer cryptographic origin verification (archival → anchor → live) |
sign_transaction.py |
Signing tool gated by governance — SCOUT blocks, key never accessed |
moses-governance/
├── plugin.json Plugin manifest
├── marketplace.json Marketplace metadata
├── settings.json Safe defaults
├── agents/ 3 governed agent definitions
├── commands/ 10 slash commands
├── skills/ 9 auto-activating skills
├── hooks/ 5 lifecycle hooks (pre/post, session, prompt, stop)
├── scripts/ 7 Python scripts (governance, audit, sequence, vault, coverify, lineage, signing)
├── references/ Mode, role, posture specs + ghost token spec + falsifiability
├── rules/ Always-active constitutional rules
├── modes/ 7 governance mode context files
├── examples/ 4 governance workflow examples
├── docs/ Architecture, quickstart, enterprise use, patent notice
├── moses-governance-mcp/ FastMCP server — constitutional governance tools
├── cowork/ Prompt-native version for Claude.ai Chat/Cowork
└── data/ Runtime state (gitignored)
- Treasury — Financial ops with audit trail
- Code Review — Role hierarchy review
- Research — Methodology-first investigation
- Multi-Agent — Primary / Secondary / Observer
Three things combine into a moat that no other agent-governance plugin in this space currently has:
The theoretical framework. The McHenry Conservation Law (commitment conservation) is introduced and defined in a DOI-cited Zenodo preprint on AI governance. Competing systems that adopt the same construct in academic or technical contexts are expected to reference that work.
The patent application. A US provisional patent application (Serial No. 63/877,177) has been filed covering the architecture: an external referee daemon, commitment scoring, and a constitutional amendment protocol driven by operational history. A competing plugin that replicates this approach does so in the shadow of that filing.
The self-amending constitution. To our knowledge, no other agent-governance plugin combines commitment conservation, chained auditing, and a self-amending constitution that reads its own audit trail and proposes updates. Meta-governance — the governance system governing itself — widens the gap over time as the constitution accumulates operational history.
Conversational enforcement: Governance hooks currently fire on tool use (code execution, file operations) — not on every conversational turn. Conversational responses follow constitutional instructions but can be pushed off-policy by a determined operator. Full pre-response enforcement would require inference-layer controls outside this plugin's scope.
HMAC operator identity: Amendment signatures depend on a shared secret (MOSES_OPERATOR_SECRET). No amendment can be applied without that key, but proposals are not yet bound cryptographically to individual operator identities. Per-operator identity scoping is planned for a later version. See Enterprise Use for full security posture.
Signal-word concept extraction: Prohibited-action checks use curated signal words and patterns. This covers many common vectors and paraphrases but is not exhaustive; domain-specific jargon may require tuning. The plugin is designed to complement, not replace, organizational policy and human review.
- Architecture — System design and data flow
- Enterprise Use — Deployment patterns, compliance mapping, security posture
- Competitive Landscape — Head-to-head analysis
- Patent Notice — IP and patent status
- Notice — Preprint citation and validation
Tens of thousands of AI agents now operate inside enterprises and on-chain ecosystems, while most governance focuses on transactions and outputs — not the agent itself. MO§ES™ provides a governance layer around the agent: modes, roles, postures, and constitutional oversight on top of your existing workflows.
MO§ES™ governs the agent.
MO§ES™ — Modus Operandi System for Signal Encoding and Scaling Expansion
Ello Cello LLC | Patent pending (Serial No. 63/877,177)
Preprint: Zenodo → · Grokipedia entry →
Live console: mos2es.io | Contact: contact@burnmydays.com
Source-available for evaluation. See LICENSE.md.
Commercial use: Commercial License →
© 2026 Ello Cello LLC. All rights reserved.