The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Lockstep listing page.
Lockstep
Start with one developer or one product manager. Grow into a shared decision record for your team.
Website · ▶ Try it live · Quick start · For product managers · How it works · Deploy
Yesterday, you and Claude renamed POST /login to POST /session. Today, a fresh session writes a client against the old route. The decision was made; the next session never received it.
Lockstep gives developers and product managers two ways to start independently:
For example, accept “exports expire after 24 hours, except internal previews.” A later Claude session receives that decision without another explanation. A PM can trace the requirement to its source, revise it for review, and share its accepted version with a developer.
Start with one real repo or brief. Invite a colleague when there is useful context to share; company-wide onboarding is not required.
| Nothing | Slack / docs | CODEOWNERS | Lockstep | |
|---|---|---|---|---|
| Agents learn what other agents decided | ❌ | Manual | ❌ | ✅ Automatic |
| Decisions ranked by blast radius | ❌ | ❌ | ❌ | ✅ Usage graph |
| Changes routed to the services that consume them | ❌ | ❌ | ❌ | ✅ Dependency graph |
| "Does anyone use this endpoint?" answered instantly | ❌ | Manual | Partial | ✅ From the graph |
| Claude Code session continuity | — | Manual | — | ✅ Briefings + decision packs |
Start with your own next session:
A decision is a durable rule or architectural choice that shapes future work. A change is a routine event — captured, but only surfaced when it matters. A PM can establish the same continuity by reviewing requirements from a brief before any code is connected.
The same ledger grows into coordination across developers and repos. For example, a route change in one service can reach the developers whose services consume it:
http:POST /session, proto:auth.v1.Auth/Login). When an agent makes a real decision, it logs it with propose_decision.lockstep.yaml). The agent can also ask consumers("http:GET /orders/:id") — "does anyone use this?" — and get an answer from the graph instead of pinging a human.Choose your starting point: developer or product manager. Both use the full dashboard and the same project history.
Pilot release status: CLI 0.3.0 is published on npm and listed in the MCP registry, alongside the matching API and dashboard changes in this repository. Hosted rollout and a real authenticated Claude-session verification are still pending, so the hosted links may run an earlier release. Complete those checks before inviting pilot participants.
Requires Node.js 20+, Claude Code, a GitHub account, and a Git repo with an origin remote.
scan --apply: it writes or merges lockstep.yaml, preserving existing entries, and seeds the graph with detected produced surfaces and matched dependencies. Then review up to five decision proposals. Remaining drafts stay in Review. Imports do not become accepted decisions automatically.npx lockstep-cli status to inspect configuration and recorded agent verification. Configuration alone is not activation.npx lockstep-cli brief. When the scan finds outbound calls with no declared producer and relevant Git history, onboarding also suggests recent contributors to the calling files and prints an invite command.For example, an unmatched http:POST /billing/charge call in src/checkout.ts can point you to a colleague who recently edited that file. These are leads to ask about the missing dependency, not verified owners; an unmatched call may also target an external service. Confirm the GitHub handle and invite each person you choose:
Suggestions do not send invitations automatically. You can share a useful brief with the colleague first.
For non-interactive runs, authenticate first and use --yes to proceed beyond preview:
--yes approves setup; it does not authorize document uploads or enable hosted checks. --no-docs skips documentation import, while --upload-docs explicitly authorizes uploading the selected candidate documents (--docs narrows that selection). Neither skips the repository scan and graph setup. Non-interactive imports remain drafts for dashboard review. Use --enable-checks or --disable-checks to set check consent explicitly; otherwise saved consent is retained.
Checks are advisory and report completed, partial, skipped, or unavailable. Missing providers or applicable rules do not produce a pass. Automatic checks have a six-second API deadline and never block Claude. Raw diff hunks are processed transiently; stored results contain status, decision references, locations, and feedback.
Onboarding respects LOCKSTEP_API_URL and saved API settings; hosted is the default only when neither exists. Generated Claude commands use a version-pinned npm invocation, so a global Lockstep installation is unnecessary. Decision packs stay local and Git-ignored.
Start with a brief, without a repo, CLI, or developer. Sign in with GitHub at the dashboard, then:
feature:private-exports. Save it and inspect the extracted requirements alongside their source evidence. If extraction is unavailable, open the saved brief and use Select requirements manually to choose exact source passages.For example, a PM can start with “exports expire after 24 hours; internal previews are exempt; bulk downloads are out of scope.” Review those requirements, leave “Should expiry be configurable?” as an unresolved question, and copy the implementation context before involving engineering.
Once development is connected, use the existing decision, feature, check, and activity views to review recorded context and concerns. Delivered requirements and no recorded concerns do not mean a feature is complete. Useful-concern, false-positive, and intentional-exception feedback does not silently change a decision.
Copying Markdown does not publish it, send a message, or grant access. Dashboard links remain authenticated. A product colleague joining a developer-created project uses the same dashboard and ledger, with no CLI setup.
After the project owner invites your GitHub handle, sign in again to activate the invitation. Developers connect their repo to the supplied project ID:
Omit --feature when no feature is selected. This reuses the project's ledger and history. Each developer installs personal Claude hooks; product colleagues work in the dashboard.
Existing B2B integrations, roles, review requirements, and GitHub PR checks remain available. The new semantic code checks are advisory; they do not replace the existing contract gate. The individual pilot starts with Claude Code; other adapters are deferred.
Onboarding already runs scan --apply to establish lockstep.yaml and seed the surface graph. When routes or dependencies change, use npx lockstep-cli scan to preview updates and npx lockstep-cli scan --apply to merge and sync them. The standalone command also retries a scan that was incomplete during onboarding. See lockstep.example.yaml. Independent login, init, connect, scan, and pack commands remain available.
Point the CLI at your server:
For local development with the dev-login bypass enabled, use:
The API needs an extraction provider (ANTHROPIC_API_KEY, or the existing TYPESAFE_API_KEY provider) for automatic imports, and TYPESAFE_API_KEY for advisory checks. Manual requirements remain usable without extraction. Set LOCKSTEP_CHECKS_ENABLED=0 to disable semantic checking server-side without disabling the ledger or existing B2B PR checks.
For production, configure real GitHub authentication, set NODE_ENV=production and LOCKSTEP_DEV_LOGIN=0, apply migrations, and verify provider configuration, request limits, backups, and both onboarding paths. See DEPLOY.md.
| Object | What it is |
|---|---|
| Decision | A durable rule or architectural choice. The hero. Impact-ranked, versioned (CAS). |
| Change | A routine event on a canonical surface. Routed to consumers by blast radius. |
| Question | A cross-team ask, ideally answered from the ledger before a human is pinged. |
| Task | Delegated work, fanned out to the assignee's inbox. |
Behind LOCKSTEP_STANDARDS=1 (see DEPLOY.md), an organization can define how agents should work and prove what reached each checkout. This is a Claude Code pilot, not the complete PRD: pausing/resuming a rollout, Codex, enrolling a repo-free PM workspace, readiness checks for a skill's declared tools, owner reassignment and linking supporting decisions in the standard editor, and author-facing conflict flagging are not built yet. The Map graph shows the first page of an expanded domain (the Outline lists everything).
lockstep enroll) receive managed skills in .claude/skills/lockstep-org-*/ (kept out of git, verified by hash, never executed, never overwritten when edited locally). Session briefings list the applicable requirements with exact versions and point to the relevant skills; the copyable project brief carries the same for repo-free PRD work. Exceptions are requested and approved per requirement, bind to the exact published version (a new version needs a new review), and expire on their own.| Agent | Install managed skills | Session availability | Invocation | Checks |
|---|---|---|---|---|
| Claude Code (verified on 2.1.281) | Yes — .claude/skills/lockstep-org-*/ | Yes — which versions a session started with | Unobservable | Code-diff via lockstep check consent; PRD checks in the dashboard |
| Codex | Not supported yet | — | — | — |
The individual pilot supports Claude Code only, with session-start briefings, MCP tools, local decision packs, and optional completion checks. Explicit CLI/MCP operations remain available if hooks are unavailable. No model calls run after every edit.
The ledger remains vendor-neutral and the existing team integrations are retained. Codex and other individual-onboarding adapters are deferred.
Use npx lockstep-cli <command> without installing a global binary, or lockstep <command> if installed globally.
| Command | What it does |
|---|---|
onboard [--project-id <id>] [--dry-run] | Preview inputs, connect, scan the repo, review decisions, and configure Claude |
onboard --yes --no-docs | Proceed past setup confirmation and skip documentation import |
onboard --yes --upload-docs [--docs <paths>] | Approve setup and document upload; optionally narrow candidates with comma-separated paths |
login [--api <url>] | Authenticate with GitHub and optionally save your server |
init --vendor claude | Configure Claude independently of onboarding |
connect [--project <name>] [--project-id <id>] | Create or join the intended project |
scan [--apply] / sync | Preview/apply a dependency manifest, or sync the existing manifest |
pack [--check] | Refresh the local decision pack or check its freshness |
check [--base <revision>] [--upload] | Check tracked changes against relevant accepted decisions |
checks on / checks off | Enable or revoke automatic hosted diff checks |
brief | Print a copyable project decision brief |
invite <github-handle> | Invite a colleague to the connected project |
status / doctor | Inspect configuration, connection, and verification status |
uninstall [--dry-run] | Remove Lockstep-managed Claude entries while retaining ledger history |
enroll [--yes] | Opt this checkout in to your organization's managed skills (Standards & Skills) |
skills [status|sync|restore|keep|accept|decline|unenroll] | Sync or resolve managed org skills; sync also runs at every session start |
docker compose or deploy to Railway.Apache 2.0 © 2026 Naman Jain