policy → standard → spec → code
Your artifacts already constrain each other. Nothing checks that they still agree.
A policy constrains a standard. A standard constrains a spec. A spec constrains the code. Every one of them changes on its own schedule.
The problem
Constraint relationships between documents are real, load-bearing, and written down nowhere.
So they drift: a policy is tightened and the four specs beneath it aren't.
Nobody finds out until an audit, an incident, or a customer does.
What dereq does
How it works
Declare
Draw the edges. An artifact is a policy, a standard, a spec, a file in a git repo. An edge means this one constrains that one. Pin an artifact to a commit, or track a branch and let it move.
Check
Ask an agent to read the whole hierarchy and report what no longer agrees. Findings name the artifacts, quote the conflicting content, and suggest a resolution.
Checks never write
Execute
Ask an agent to rewrite a downstream artifact so it honors everything upstream of it. It asks when the intent is ambiguous, and it explains which constraint drove which decision.
Agent tasks
The three kinds of agent task.
Two of them read and report. Only the third proposes a change — and never applies it without you.
| Task | Scope | Writes |
|---|---|---|
| Whole check | Every artifact and every edge. | never |
| Focused check | One artifact, its parents and its children. | never |
| Execution | Generate or update one artifact from its ancestors. | on approval |
The approval gate
Nothing writes without you.
An execution never writes on its own. It produces a proposal and a diff, and waits. You approve, and dereq commits to the tracked branch — one fast-forward commit, parented on what the agent actually read. You reject, and the proposal stays in the record. There is no auto-apply mode.