K9X Inspector
What it does
K9-AIF's value is architectural: ABB contracts, three-layer decoupling, one governed model path, governance by construction with k9x Shield and Granite Guardian, Zero Trust at the orchestrator, and Kafka ownership. A solution (SBB) keeps those properties only if its code keeps to them. Inspector checks that, every time the code changes.
Point it at a GitHub repository (or, for an administrator, a folder on the server). It reads the solution — Python as syntax trees, YAML as data, never importing or running anything — applies the framework's inspection rules, and produces a compliance report (verdict, rule pass rate, findings ranked critical / violation / warning / recommendation, each with file, line and fix) and a guidelines document: a remediation plan in priority order, why each rule exists, and the framework configuration that closes the governance findings.
When it runs
| Trigger | What happens |
|---|---|
| GitHub push | A webhook (HMAC-signed) re-inspects every tracked application on that repository and branch. |
| Schedule | Daily or every few hours; an application is re-inspected only when its branch has moved. |
| Inspect now | Any signed-in user can inspect a tracked application or any public GitHub repository. |
| CI | k9aif inspect <folder> --fail-on violation runs the same rules and fails the build. |
Tracked applications are listed in the server's .env (INSPECTOR_APPS), any number of them,
each with repository, branch and optional subfolder.
Where the rules live
The rules are part of the framework itself (k9_aif_abb.k9_inspect, k9-aif 1.15): each is a
BaseInspectionRule registered with InspectionRuleRegistry, so the CLI, CI and this
service apply exactly the same checks, and an organisation adds its own rules without changing the framework.
Inspector is itself an SBB: it installs k9-aif from PyPI and builds on that ABB.
What it does not claim
Inspection is static. It shows that the structure the framework relies on is in place — for example, that
governance is configured and every model call goes through llm_invoke() — not that a running
deployment behaves correctly. Runtime containment is what k9x_satan tests; human decisions are
recorded in K9X HIL.
The K9X ecosystem
Built on the K9-AIF framework — architecture-first, governed multi-agent systems.
| Component | Role |
|---|---|
| K9X Studio | Design and build solutions on the framework |
| K9X Inspector | Inspects solutions built on the K9-AIF framework |
| K9X Sentinel | Keeps the framework current with new threats |
| K9X Satan | Security analysis: red-team attacks against a governed pipeline |
| K9X Repository | Enterprise architecture repository |
| K9X HIL | Human-in-the-loop review and decisions |