One Source, Many Agents
The core governance model in SigmaShake is simple: you keep one .sigmashake/rules/*.rules source and let each host apply the same policy through its own native integration.
One rule source, many integrations
You do not copy rule files per client. Instead, you install SigmaShake for each host (ssg init --client=<name>), and each host gets its own integration path while reading the same source file. The effect is policy continuity across environments, without per-tool drift.
Shared source, runtime-native enforcement
One live .sigmashake/rules/*.rules source. Claude Code and Codex both evaluate it live, at runtime, for every supported local tool call — Claude Code via an automatic PreToolUse hook (ssg hook eval); Codex via a native hook (ssg hook codex --source=native), which needs a one-time /hooks trust step in Codex CLI. The ssg-governance MCP registration adds explicit governance tools (like ssg_evaluate) directly to the agent — it doesn't itself intercept calls. Neither host gets a copy of your rules. Other hosts each get their own integration via ssg init --client=<name> — see the adapter reference for exact mechanics per host.
Why this is manageable
You get three advantages:
- Consistency: one canonical policy source.
- Host-specific integration: the evaluation mechanism is chosen by the host implementation, not by duplicated logic.
- Upgrade safety: stale install artifacts are retired on re-init, and new hosts can be added without rewriting rules.
Grok Bot uses the same rule ideas via the hosted SigmaShake Guardrails MCP (https://mcp.sigmashake.com/mcp) — a remote control plane with honest-agent safeguards, not a local hook. It does not read your on-disk .sigmashake/rules/ unless those rules are loaded into the hosted engine. See Grok Bot.
For client-specific behavior and install details, see Client Adapters.