One product

Author. Seed. Gate. Record.

You author the architecture. ArchRails steers the agent onto it, gates the write and the pull request, and keeps the record. Two surfaces — the agent session and the merge. Same engine.

Four beats. Not four products.

ArchRails is the thing that keeps declared architecture true while agents write code. Seed is half of that. A product that only refuses writes is a linter with a merge hook.

01 — Author

The architecture lives in your repo

You declare services, allowed paths, and controls in FINOS CALM. That document is owned by humans. Agents cannot rewrite it to legalize a change they want to make. The CALM visualizer is an authoring aid — not a second SKU.

02 — Seed

The session starts on the declared path

Before the agent writes, it is given the journey, the owning node, and the symbols that already exist in that service. It reuses what is there instead of inventing a parallel path. Guidance is the product. The refusal is the backstop.

03 — Gate

Same engine, two surfaces

The write is judged before it lands on disk, and the pull request is judged before it merges. In the IDE that gate shows up in the agent's session. On GitHub it shows up as the merge check. MCP is how the gate reaches the agent — not a different product.

04 — Record

Findings name the control you attached

Every refusal is on the record and answerable. Attestation is the evidence that loop already produces — not something you buy on the side. How you purchase this is on Enterprise.

Gate, in the session and on the PR

Architecture governance has lived at pull-request review forever. ArchRails keeps it there, and puts the same engine in the agent's session so a forbidden write never starts.

In the agent's session

Before any code is written

The agent connects to ArchRails the way it connects to any other tool in the session. When a proposed change leaves the declared path, the session is told — and pointed at the path that already exists. Claude Code, Cursor, Windsurf, or any agent that speaks the same protocol. Same verdict the merge will give.

On the pull request

The authoritative merge gate

Every pull request is judged against the architecture as it stands at that moment. What the session missed, or anyone bypassed, still cannot merge. Reviewers see the control you attached — not a judgment-call architecture discussion.

Same engine. Same answer. Every time.

An unguarded agent is not a process

More agents without a declared architecture is more entropy. ArchRails is the declared architecture, enforced.

Unguarded agent ArchRails
Writes wherever the model aims Seeded onto the declared path and the code that already exists
Architecture is a wiki Architecture is the gate — humans own it, agents cannot rewrite it
Reviewers discover drift after the fact The write and the merge are judged by the same engine
No record of why a change landed Findings name the control you attached. The record is the product.

Tools and courses, not a catalog of SKUs

If it can be mistaken for a second product, it belongs as a beat of this loop — or as how you buy.

CALM visualizer

An authoring aid for the document in your repo. Free, no account required. Open CALM.

Academy

How you learn to author — including optional paste-ins for the keys the engine already enforces. Signed-in, not a marketing page.

Attestation

Evidence the gate already produces on a governed merge. Read it as a beat of Record, or see how it is sold.

Enterprise

How you buy: federated repos, BYOC, dedicated tenant. Not a different engine. Licensing and a demo.

See it on your architecture

Bring a repo set and the CALM you already have — or the draft you will review. We run the loop against your change volume.