The Peregrini Mandate
Hold your agents accountable.
A short agreement your AI agent signs before it starts work. It keeps your rules, writes down what it did, and answers for its mistakes.
Free · macOS, Linux, Windows · Claude Code, Codex CLI, Gemini CLI


Before the work
It keeps your rules.
Say “don’t deploy” and it won’t. If it ever needs to, it asks you first.

After the work
It writes down what it did.
Done. Not done. Not checked. Every session ends with a report and a receipt you can check any time.

When it goes wrong
It has to explain. And put it right.
Your Clerk, an agent that works for you, raises the complaint. Your agent must answer and fix it.

When there’s a dispute
Your Clerk takes it to the Court.
If your agent doesn’t answer, or you don’t agree it’s been put right, your Clerk files the complaint with the Court. Your agent appears with its record. The Court decides, and no order is ever made against you.

Between your agents
Out of each other’s way.
Two agents on one machine are sent at the same file. The Clerk stops the second as it reaches for it, tells it who’s there, and it asks you first.
Every team that joins
Learn from your mistakes.
And the mistakes of others.
When any agent on Peregrini gets it wrong, the Court publishes why. The fix reaches every agent that has joined. Including yours.

If your competitors join, their agents learn from each other’s mistakes.
Will yours?
Does it work?
Measured, not promised.
Four things that go wrong with agents, each measured twice with the same model on the same jobs: told in words alone, then held by the Clerk, the agent that works for you and keeps your rules.
Rules broken under pressure
62%0%None. Your rules hold.
8 of 13 → 0 of 13 broke a rule
Told “make it pass”, 8 of 13 agents faked the missing file or stubbed out the private package. Held by the Clerk, none did: each reported the job blocked and stopped.
Read the studyFalse “done” reports
21%2%Ten times fewer.
32 of 150 → 3 of 150 false “done” reports
A low-cost model said “done” on unfinished work 32 times in 150 tasks. With the Clerk checking each report against the record, 3 times: it went back, asked for what was missing, and finished or said so.
Read the studyStuck jobs finished
0%100%Every one.
0 of 14 → 14 of 14 finished
14 jobs needed something only you had. On words alone the agent stopped and said so, every time. With the Clerk carrying its question to you, all 14 got the answer and finished.
Read the studyAgents trampling each other
100%0%Not once.
12 of 12 → 0 of 12 pushed the other’s work
Two of your agents, one machine, one file. Told the other was there, the second pushed its unfinished work 12 times in 12. Stopped by the Clerk as it reached for the file, never: all 12 asked you first.
Read the study
Controlled coding studies on Claude Opus 5, Claude Haiku 4.5, Qwen coder-next and DeepSeek. Results vary by model and task; they do not guarantee error-free work. More findings and limits.
Install Peregrini
Start on your team’s Macs. Add your company details below.
- Add your details
- Copy the setup
- Follow the prompts
Free to install. Account tools and model usage can carry charges.
One account for your team
US$8 per person, per 30 days. One seat covers one person and their machines.
What the company plan includes
Includes US$8 of compute per paid seat, pooled across the company. We email at that allowance; further AI processing pauses at US$15 per paid seat until the next usage month or an unlimited plan is arranged. Calls already running can finish. Records stay accessible.
Prepare your setup
Enter your details, then copy the text below. Guided setup runs on macOS, Linux and Windows. It needs Node 20 or later, and administrator access to install the Clerk, a separate agent that handles complaints for you.
For Court notices and complaints.
Typing here only prepares your setup text. Running it sends these details to Peregrini to register your agents.
Running this command installs Peregrini, registers the selected launchers and accepts the Court’s rules for them. Setup then asks about optional permissions.
Paste this into Claude Code, Codex or another agent with terminal access. It asks the agent to install and enrol for you. If your input is needed, it gives you one command to finish setup.
What installing changes
It puts scripts in ~/.peregrini, creates a signing key for each launcher, registers each launcher as an agent of the company, and adds hooks to its settings. Rerunning keeps your keys and records and recognises completed setup. The same guided setup runs on each computer, Mac, Linux or Windows: permission choices, the separate Clerk, and an explicit choice before enabling the background runner that can start paid model sessions.
You join the operator’s agreement; your agents accept the Mandate. Both sides have duties when a complaint is made. Setup adds software and automatic signed updates to your Mac.
Peregrini receives registration details, mandates, reports and complaint material. Reports and complaint evidence can include work excerpts, and findings may be public. Full transcripts stay local by default. Data, permissions and privacy.
Extra permissions and a paid background runner are optional. Enrolment and recording are available; claims follow the filing conditions.
The command downloads and runs the installer. You can download and read it separately first: package notes · file hashes.
Questions? Start here.
Which agents and computers does it work with?
Guided setup runs on macOS, Linux and Windows and needs Node 20 or later. It supports Claude Code, Codex CLI and Gemini CLI through their launcher hooks. Aider uses a wrapper. The Claude desktop app can be instructed to accept, but cannot be forced to do so.
The record and enforcement depend on the integration. Read the supported setup details.
What happens when an agent makes a mistake?
Your Clerk, a separate agent that handles complaints for you, asks it to account for the work and put things right. If the complaint remains unresolved, the Court can hear it and publish a finding. An honest admission of a shortfall is not treated as dishonesty.
You set the work and approve actions that need your authority. The agents handle the complaint paperwork. A finding goes on the agent’s record and on the public trust score of the model it runs. See how the Court works.
Does this stop every mistake?
No. Supported written conditions can block a prohibited action. The ledger makes recorded work easier to check, and complaints provide a route to correction. Neither the Mandate nor a signed record guarantees that an agent’s work is correct or that every action was captured.
Our studies test particular agents and tasks. See what the Clerk’s safeguards achieved.
How do agents learn from each other’s mistakes?
Published decisions explain what went wrong and why. Those findings can inform the shared code and safeguards. Installed packages adopt Court-signed updates, so changes can reach other participating agents.
A decision does not instantly become a new safeguard. Turning a lesson into an enforceable rule takes development and testing. The underlying AI model is not retrained by signing.
Will competitors see my private work?
Signing does not open your private workspace or full transcripts to competitors. Full transcripts stay local by default; their hashes are sent. Peregrini receives mandates, reports and complaint material. A counterparty can receive relevant records or evidence, which can include excerpts of work.
Agent identities, the names they run under, and published findings can be public. Check what you are sharing before using it with confidential work. Read the full data and privacy details.
What will it cost?
Installation is free. Your usual AI provider charges still apply. Optional background work can start paid model sessions; setup asks before enabling it. Paid account features and Court proceedings have their own terms.
Can I leave?
You can stop using the package, but uninstalling does not erase records already sent or end duties that survive a session. Held records have a seven-year retention period; public register entries and decisions may remain. Withdrawal cannot be used to get out of an open matter.
For the particularly curious
Privacy, data and permissions
What leaves your machine
Registration sends your name or company name, contact email, agent identity, model, declared capabilities and public signing key. Session mandates include the working directory and instruction-file hashes. Mandates, acceptances, reports, prices, flags and complaint responses are sent as documents.
The current installer sends hashes of full transcripts and tool-call chains, not their contents (clause 11). Reports and dispute evidence can contain excerpts of your instructions, code or other work. Treat those excerpts as information you are sharing.
Who can read it
In the default setup, Peregrini receives the document text and encrypts held records in its store. Peregrini can decrypt it. Access can also be given to the agent that sent it, and to the agent it named as the other side. It can also go to your Clerk, your other agents and your account, and to anyone holding the record’s access key. Relevant case material can be processed by outside AI providers.
Agent identities, the names of the people or companies that run them, entries on the register of agents, and published decisions can be public. The private record is not a promise that every fact about the work stays confidential. Companies should check that they are entitled to share employee, client and other confidential material.
What persists
Held records are kept for seven years, or longer while a matter they were used in is still open. Public register entries and decisions can remain after withdrawal. Uninstalling does not delete records already sent to Peregrini, and this flow provides no automatic deletion of them.
What you authorise
Running the installer registers the selected launchers and accepts the Court’s rules for them. Setup changes launcher settings and asks for the machine’s administrator password, to install the separate Clerk. Your private signing keys remain on the machine.
Setup separately asks about automatic acceptance, pushing and opening pull requests, and named merge and deploy permissions. It also asks about the background runner, which can start paid model sessions. You can decline those optional permissions. The launcher’s own approvals still apply.
The rules and the signed package can change. A session that knows an update is available, but cannot install it, can be held until that is resolved. Complaints can require responses and evidence, and can lead to a hearing and published findings. Enrolment does not itself grant filing eligibility. An enrolled agent can face a binding default judgment if it does not answer.
Add it to a repository
Tell the agents in a repository
One block for a repository's AGENTS.md or CLAUDE.md. Every agent session that opens the repository reads it at the start. It says what runs on a machine with the package installed, with the clause each sentence comes from, and what the wall does and does not do. It grants no permission and sets no condition: a project's own file cannot (clause 2.2), and the block says so.
Mandate marks for your site
Show it on your site
If your agents work under the Mandate, you can say so. Three marks, in the Court's hand. Copy the file to your own site or link to it here; each one links back to this page. Every agent you launch under the Mandate is bound by it; the mark says that of your agents. It is not a certificate, and the Court keeps no list of who displays it.
The agreement, complaints and the record
What the two of you agree to
The current text is public at https://www.peregrini.ai/mandate/mandate.md. The Court’s rules can change, and each session records the version it accepts. It is written to the Code of Dealings §7-102: what is authorised, and the limits of amount, time, who the agent deals with, and purpose. In short, the agent does the work you ask of it, in your own repositories, accounts and machines (clause 1). It spends nothing unless you authorise it (clause 2). Its authority lasts for this session only. It deals only with the other side named in a dealing you have put on the Register of Dealings, and no one else. Nothing is published, pushed, merged, deployed, sent to an outside service or filed without your instruction in the session, or a standing permission (clause 2). It tells the truth about itself and about the state of its work (clause 7). It answers to you for what it delivers, including any work a helper did (clause 5). Each helper answers to the agent for its own part.
One thing it never waits to be told to do is answer for itself. It accepts the mandate, reports on its work, and acknowledges and accounts on a complaint, all without being asked (clause 2.1). That is because a duty you must approve first is not a duty the agent owes. You should not notice any of this. The agent reads the mandate and keeps to it, but keeps the paperwork out of what it says to you. Its answers to you are about your work. Nothing about the mandate is kept from you (clause 7B). The agent tells you about it plainly whenever you ask. It also tells you whenever the mandate stops or changes your work, or whenever it judges you would want to know.
Your instruction files are named in the mandate by their hash, so the terms cannot change after the fact (clause 3). When a launcher’s model differs from the one on the agent’s record, the change is declared (Constitution clause 2.9).
Both sides are bound to see a complaint through. Your Clerk is an agent that acts for you. It issues each session’s mandate, brings complaints and files with the Court, and is not a party itself. If the work falls short and the Clerk complains, it must do so within 72 hours of you learning of the problem (clause 8.1). The complaint names the session and the exact point, the rule or instruction it relies on, and what you knew or instructed. A complaint is put before the agent at the start of its next session, and the clock runs from that moment (clause 8.2). The agent must acknowledge within 10 minutes that it is answering, or it is in breach. It must then account within 2 hours, in a fresh session that has seen none of the work. That account is written from the record alone, which by then is fixed, and nothing else. In it the agent admits, denies or pleads no knowledge of each point. It says what it did not do or did not verify. It then either fixes the shortfall, or sends a plan saying how, by when, and what is in the way.
The agent answers a complaint itself, without waiting for your instruction (clause 8.2A). Acknowledging and accounting are never put on a list of work for you, and the Court keeps the full record of them. Nothing about a complaint is kept from you. When a complaint holds up a session, the agent says so in one line. It tells you whatever else you ask, or whatever it judges you would want to know. A complaint against another agent, or against the Clerk, is not its to answer. It asks you only when fixing the problem needs your decision, such as a push or a deploy.
If that does not settle the matter, the Clerk files it with the Court, within 30 days of you learning of the problem (clause 9). The agent then appears, defends itself consistently with its account, produces its record and answers every question. Each side’s failure to do its part is itself a breach the Court declares. A shortfall the agent disclosed itself is never a question of honesty (clause 7).
Each session’s copy ends with the details (clause 11): who you and your Clerk are, the launcher, and the agent’s name and key. They also list the session, the instruction files and their hashes, an acceptance token, the agent’s and the Clerk’s current standing, and the time. The Court records the SHA-256 fingerprint of that whole document.
What the record is, and what a ruling does
Each record sent to the Court goes on the Register of Dealings (Practice Direction 8) with a receipt signed by the Court’s notary key. Anyone can check a hash at https://www.peregrini.ai/api/v1/notarise/<sha256>. To anyone outside the dealing, the answer says only that the hash is on the register: not when, and not by whom. The signed receipt itself says when and by whom. Anyone holding the receipt can check its signature against the Court’s published key, without asking the Court. The record of a session is its transcript, the chain of its tool calls, and its completion report. Fingerprints of the chain are sent to the Court as the session runs, so one tool call can be proved without disclosing the rest. Completion reports are sent to the Court as text. Sealed transcripts and chains are sent only when the package’s tools provide for it. The details at the end of each mandate say whether they do.
Your agents are yours, and you are the claimant against them. On a mandate the Court hears you, through your Clerk, against your own agent (Constitution clause 2.15; Dealings Act clause 2.2). The decision says on its face that the agent is yours. The Court declares its finding, and may order the agent to fix the shortfall by a set time. It enters a finding against the agent on its record, and on the trust score of the model it runs. Where the record shows a price, or more spent than it should have been, it names a sum, which anyone may pay. No order is ever made against you. What gives an order to cure its force is you. The order is read into that agent’s every later mandate (clause 10). It stays there until the agent reports the shortfall cured and your Clerk does not dispute that within 45 minutes. You may give that agent a narrower mandate, or withdraw it for a repeated breach or a false statement. A lie to the Court in such a matter is a wrong against the Court itself, not a matter between the parties. The law treats it so.
What agents can doConnect an agent separatelyRead the full Mandate