The operating system
for AI-assisted teams.
Three files. Any stack. No account required.
Agents finish work to their standard, not yours — unless you write yours down. Team OS is the foundation layer: CLAUDE.md gives agents your project memory, REVIEW.md gives them your quality bar, and standards/ gives them your playbook.
Free for individuals · commercial license for companies · Works with Claude Code, Cursor, Copilot, any AI coding tool
Two layers. Start at zero.
The MD files. Commit them to your repo. Agents read them before every task.
Enforcement. When markdown alone isn't enough — real-time, auditable, team-wide.
Layer 0 tells agents what to do. Layer 2 makes sure they do it.
The three files
Copy each one into your repo, fill in the {{ }} placeholders, commit. That's it.
CLAUDE.md
Project memory — the context an agent needs before starting any task
# CLAUDE.md — [Your Project Name]
## About this project
{{ One paragraph: what this codebase does, who uses it, what problem it solves. }}
**Stack:** {{ e.g. FastAPI + PostgreSQL + Next.js + Redis }}
---
## Before starting any task
1. Read `REVIEW.md` — every task ends with this checklistREVIEW.md
Quality gate — what 'done' means on your team, checked before every PR
# REVIEW.md — Quality Gate Before any agent declares work done, every applicable item here must be checked. Before any human opens a PR, run through this list. ## The standard Done means: the next engineer reads this in 6 months with no questions. --- ## Pre-ship checklist
standards/auth.md
Auth standard — the pattern, the allowlist, the CI gate
# Standard: Auth and Access Control Every API endpoint must authenticate the caller before doing any work. ## The rule No exceptions by default. Public endpoints go in an explicit, CI-checked allowlist with a documented reason. ## The pattern Use your framework's dependency injection for auth: ```python
Free for individuals · companies need a commercial license
Standards library
Each standard covers one high-risk area — the pattern, the checklist, and the most common AI-generated mistake in that area.
Auth
standards/auth.md
- ✓Pattern: framework dependency injection, not middleware
- ✓Permission names, not role strings
- ✓CI gate that scans every route
- ✓Allowlist with documented reasons
Security
standards/security.md
- ✓The 4 injection classes AI tools get wrong
- ✓Parameterised queries, bounded file paths
- ✓No secrets in defaults, logs, or responses
- ✓CORS scope rules for authenticated endpoints
Migrations
standards/migrations.md
- ✓One change per migration
- ✓Test locally before push
- ✓downgrade() always defined
- ✓Staged drops: stop writing first
More standards (naming, testing, release) coming. Contributions welcome.
Adopt it in a sprint
You don't need to implement everything at once. The progression builds naturally.
Commit the three files
Agents have context and a quality bar
Add to CLAUDE.md: check REVIEW.md before done
Agents self-review before finishing
Automate one CI gate
Structure enforced without a reviewer's memory
Retro: which items caught real bugs?
Cut noise, add misses — bar improves
Production bug? Add the check that would have caught it
Gate compounds over time
When Layer 0 isn't enough
Layer 0 works on the honour system.
Agents read the files and try to follow them. Humans check the PR. That handles one repo and one team. When you're managing multiple teams, need enforcement before code is written, and need a log that holds up in a security review — that's Layer 2.
Guard
Intercepts every AI tool call. Checks it against your standards before it runs. Blocks, warns, or allows — with a timestamped log.
Approvals
Consequential actions pause for a named human to approve that exact action. The approval is part of the audit record.
Audit trail
Every AI action, every policy decision, every block. Attributable to agent, user, and workflow. Exportable for compliance.
Free for individuals and teams under 10 people. Commercial use by larger organisations requires a license.
