Governance over Generation

The rules your AIcan't ignore.

Your agent writes code that drifts from your own standards. Prism checks every file it saves, and when a rule breaks, the exact fix goes straight back to the agent, in the same exchange.

npx @prism-engine/cli init

Claude Code · PostToolUse hook · exit 2 on block

  • MIT licensed
  • No account required
  • Zero network calls on init
Scroll
Enforcement, not suggestions

Your agent breaks a rule. It gets told, in the same turn.

A real session, step by step: the agent edits a file, a check runs against your rules, and the correction comes back with the exact line to change. Scroll through it, or play it back. Every line below is copied from the shipped tool.

Scroll to step through

  1. 01

    The agent writes

    It hard-codes a colour instead of using the token your design system defines. Nothing looks wrong yet.

  2. 02

    The hook fires

    prism init installed a check that runs every time the agent saves a file. No review step, no manual run.

  3. 03

    The block is returned

    A finding at block severity is sent back to the agent as a correction, in the same exchange, while it still has the file open.

  4. 04

    The agent fixes it

    The fix is named and line-numbered: this value, on this line. The agent applies it and carries on.

claude-code · posttooluse
$ npx @prism-engine/cli check --hook --format claude-code# stdin: PostToolUse · tool_name "Edit" · tool_input.file_path "src/components/PrimaryButton.tsx"PRISM PASS blocked write to PrimaryButton.tsx — 1 rule violation must be fixed now:1. Line 12 (styling/no-hex): replace '#06b6d4' with 'var(--brand-primary)' — Use the design token.Apply exactly these edits to PrimaryButton.tsx, then continue your original task.exit code 2

Every line above is reproduced from packages/prism-context-engine: command, payload shape, formatter output and exit code.

The dashboard

Enforcement runs on your machine. This is where teams manage it.

The CLI never asks for an account. The dashboard is where a team's rules, projects and usage live, and prism pull copies them down to every machine, so everyone is checked against the same thing.

prism.syntaxure.dev/dashboard
The Prism Context Engine dashboard, showing 3 active projects, 34 context rules in force, 1 AI generation, and usage bars for projects, rules, components and AI generations against the Pro plan's limits.
The running dashboard, captured against this repository's own workspace.
  • Rules in force

    Every project's context rules, counted against the ceiling of the active plan.

  • Usage

    Projects, rules, components and AI generations measured across the current billing period.

  • Brand profile

    The visual guidelines an agent reads before it is allowed to write.

Why it holds

What it does that a prompt cannot.

A prompt asks the agent to behave. These are the parts of Prism that do not depend on it agreeing. All of it runs on your machine, with no account and no server round-trip.

  • Blocks, then corrects

    A rule at block severity comes back as a failure the agent has to deal with before it continues, and the message names the exact edit. Rules you are less sure of ship at warn: they advise without interrupting anyone, until you promote them.

  • Rules from your own source

    prism init reads your own package.json, CSS and Tailwind config, and takes the rule from colours you already defined. It matches the exact values in your design system, so a hit is always a real one.

  • Fails open, by design

    Missing rules, unreadable files and engine errors all exit 0, and PRISM_DISABLE=1 turns it off. A checker that can break your build is worse than no checker, so the failure mode is "no opinion".

How it works

One command, then it is always on.

The local path needs no account, no API key and no network. The dashboard is an upgrade you choose later, not the entry fee.

terminal · init
◈ Prism Context Engine — init

  Scanning this project. No network calls.
  1. 01

    Scan the project

    prism init detects the stack and extracts the colour tokens already defined in your CSS and Tailwind config.

  2. 02

    Generate the rules

    It writes them to .prism/rules.json: one small file, and the same one the checker reads and the dashboard syncs.

  3. 03

    Wire the agent

    It adds the check to your agent's settings, so every file the agent saves is inspected, and writes the Cursor and Antigravity equivalents. Existing keys are never clobbered.

  4. 04

    Sync the team

    prism pull copies the team's rules from the dashboard into the same file. If the network, the auth or the response fails, it leaves your working setup alone.

Coverage

Where enforcement actually runs today.

The tiers below are the honest split. Two of the three are configuration that has never been verified firing inside the agent, and we flag them rather than rounding up.

  • Claude Code
    Enforcing

    PostToolUse hook with matcher Write|Edit, exit 2 on a block finding

  • Cursor
    Config written, firing unverified

    Hook config written by prism init; in-agent firing unverified

  • Antigravity
    Config written, firing unverified

    Hook config written by prism init; in-agent firing unverified

  • Windsurf
    Advisory via MCP

    MCP configuration only: rules are available to the agent, not enforced

  • Claude Desktop
    Advisory via MCP

    No hooks system exists in the host, so rules are advisory only

Evidence

Every claim on this page, with its source.

Every claim this page makes, with the file it was read from, and the claims we chose not to make. The second list is the reason to believe the first.

13 claims traced to source · 5 refused

  • prism init makes zero network calls: it reads the project's own package.json, globals.css and Tailwind config.

    VERIFIEDpackages/prism-context-engine/src/commands/init.ts (header)
  • prism init merges a PostToolUse hook with matcher Write|Edit into .claude/settings.json, without overwriting existing keys.

    VERIFIEDpackages/prism-context-engine/src/init/hook.ts (wireClaudeHook)
  • A block-severity finding is written to stderr and the hook exits 2, so the correction lands in the agent's context.

    VERIFIEDpackages/prism-context-engine/src/commands/check.ts (runHook)
  • Hook mode fails open: missing or malformed rules, unreadable files and engine errors all exit 0 instead of blocking.

    VERIFIEDpackages/prism-context-engine/src/commands/check.ts (header)
  • PRISM_DISABLE=1 disables the hook entirely.

    VERIFIEDpackages/prism-context-engine/src/commands/check.ts:84
  • The generated design-token rule ships at block; the arbitrary-Tailwind-brackets rule ships at warn and never stops a write until you promote it.

    VERIFIEDpackages/prism-context-engine/src/init/generate-rules.ts, package README
  • .prism/rules.json is one v1 schema shared by init, pull and check.

    VERIFIEDpackages/prism-context-engine/README.md (Local Files)
  • prism pull fails safe: a network, auth or response failure never breaks an existing working setup.

    VERIFIEDpackages/prism-context-engine/README.md, src/commands/pull.ts
  • prism ide-setup writes MCP configuration for Cursor, Windsurf and Claude Desktop.

    VERIFIEDpackages/prism-context-engine/src/commands/ide-setup.ts (config dirs)
  • The CLI is published to npm as @prism-engine/cli under the MIT licence and requires Node 20+.

    VERIFIEDnpm registry API (latest 1.2.0), packages/prism-context-engine/package.json
  • Plans: Free $0, Pro $8/month, Team $7/month, Enterprise custom.

    VERIFIEDapps/prism-engine/src/lib/pricing-db.ts (FALLBACK_PLANS)
  • The dashboard tracks context rules, projects, components and AI generations against the active plan's limits.

    VERIFIEDapps/prism-engine/src/app/(dashboard); see the capture in the console section
  • Dashboard rules round-trip 26/26 instructions and patterns exactly; 4 of 10 check types degrade to advisory.

    STATEDFounder's paired trial records; not reproducible from this repo

Claims we do not make, and why:

  • UNVERIFIED

    Claude Code enforcement runs on PreToolUse with a Stop gate.

    No PreToolUse or Stop hook exists anywhere in packages/prism-context-engine; init writes PostToolUse only

  • UNVERIFIED

    A violating write is stopped before it reaches disk.

    The wired hook is PostToolUse, which runs after the tool call. The source proves the agent is corrected, not that the write was prevented

  • UNVERIFIED

    Prism blocks violating writes in OpenCode.

    No OpenCode integration in the CLI. apps/prism-engine/src/lib/opencode.ts is an AI model gateway, not an enforcement target

  • UNSUPPORTED

    39% token savings.

    One task measured against one baseline

  • UNSUPPORTED

    361 users.

    Downloads are not users

Plans

Free to enforce. Paid to sync.

Local enforcement sits on the free tier permanently. The paid tiers add cross-machine sync and shared team governance.

  • Free$0

    Agent governance, free forever

  • Pro$8/month

    For solo developers shipping agent-first

  • Team$7/month

    One constitution, every agent

  • EnterpriseCustom

    Custom solutions for scale

Prices in USD, billed monthly. PHP pricing is available on the pricing page.

Compare plans
Start

Start enforcing in one command.

Free tier. MIT licensed CLI. The local path never asks you to make an account.

npx @prism-engine/cli init
Start freeRequires Node 20 or later.