// the find
sipyourdrink-ltd/bernstein
The open‑source AI Agents Governance & Orchestration framework: write the rules declaratively, Bernstein enforces them and produces the verifiable, replayable record. Free, Apache-2.0. https://bernstein.run
Bernstein is a Python orchestrator that runs several CLI coding agents (Claude Code, Codex, Gemini CLI, and about 50 others) in parallel. A plain-Python scheduler with no model in the coordination loop assigns tasks, gives each coding task its own git worktree, gates merges, and writes a replayable journal with optional signed receipts. It is aimed at people running multiple agents who need reproducible runs, and at teams that need audit evidence from agent work.
The scheduler is deterministic by design: the only LLM call is the one-shot decomposition, and everything after it is ordinary Python. That makes the coordination layer debuggable in a way most agent frameworks aren't. Isolation is concrete: one git worktree per coding task, backlog claims are atomic, and the README states plainly that disabling worktrees drops every task into the shared checkout. The verification claims can be checked. `bernstein verify receipt` works offline against a committed receipt, and CI re-verifies it on every push, including a tampered copy that is required to fail. The adapter registry is named as the single source of truth for what resolves, so the '50+ agents' number can be counted, not just trusted.
It is solo-maintained, labelled beta, and says minor versions may change interfaces, so anything you depend on needs a pinned version and you carry the bus-factor risk. The front page is very dense. It mixes shipped features with planned or partial ones (volunteer compute, cloud execution, SCIM/OIDC/SPIFFE mentions, and a 'one-command runner is not shipped yet' caveat), and you have to follow links to the integrations page to tell which is which. The 'reproducible end to end' line overstates things. Replay reproduces the recorded journal and task graph, not the agent runs, and the plan itself comes from a model call. The tamper-evident audit chain is opt-in via `BERNSTEIN_AUDIT=1`, and a receipt checked without a pinned `--public-key` only proves internal consistency. The README says both, but the headline pitch doesn't.