It skips ahead
Straight to the implementation, before anyone agreed on what was being built.
Open source · Apache 2.0 · 100% free
Dilux Agentic Workflow is a development pipeline your agent has to walk through: six phases in order, gates it cannot talk its way past, auditors that did not write the code they review, and state that survives closing the terminal.
It is 100% free and always will be: no paid edition, no SaaS, no account to create.
The problem
None of them is fixed by writing a better prompt. They are structural, and structure is what fixes them.
Straight to the implementation, before anyone agreed on what was being built.
Forty messages in, the decision you made an hour ago is gone, and the code drifts away from it without anyone noticing.
Give it forty rules and it will follow the ones that happened to stay near the end of the context window.
Six months later nobody can say what was decided, why, or against which spec it was built.
How a request flows
You never invoke a phase by hand. Every arrow needs your explicit approval, and each phase commits what it produced as it closes.
Works out what you are asking for, reads your stack, opens a ticket and a branch. You confirm the classification.
The what and the why: the PRD. It takes the one you already have — a ticket, a doc, a paragraph — and validates it against the codebase.
The how and what could go wrong: the spec and a threat model. Gate enforced by a hook: no approved spec, no code.
Implemented block by block, each with its tests. Gate: suite green, SAST clean.
An agent that did not write the code cross-checks it against the PRD and the spec, and writes the verdict to a report. If it fails, back to CODE.
CHANGELOG, pull request, ticket, closeout. What happened is written into the repo history, not into a chat.
The distinction it all rests on
Before every write, code outside the model reads the state and refuses two different things: a transition the graph does not carry, and a write of product source from a phase that forbids it. There is no talking past it, because the decision never reaches the model at all.
Security
Two controls, at two moments, each catching what the other cannot. Both produce a report, not just a flag — including what you dismissed and why.
Looks at the design before it exists. Blind to implementation bugs — which is exactly what the other control sees.
Looks at the code without running it. Blind to business logic and authorization — which is exactly what the threat model saw.
The VERIFY phase is run by an agent that did not write that code. Nobody reviews their own work.
PRD, spec, threat model, SAST report and verification report live under docs/, committed phase by phase.
In action
Real captures of the pipeline working on a repository: the phase diagram, a gate closing, a hook refusing a write, and a phase closing with evidence.
Everything you see here gets committed to your repository, phase by phase. Six months later someone can read why it was done this way.
This one is easy: it costs nothing and there is no better version waiting behind a paywall.
The whole framework
FREE · forever
Installation and configuration are on you, at your own risk.
Optional services
Custom
The framework is already published: you can clone and install it right now. Leave your details if you want us to support your rollout or notify you on every release.
You are on the private preview list. We will email you at the address you provided as soon as a seat opens.
Request number: —