GOVENANT
Free · read-only · Coding tool

Audit your Windsurf agents.

Audit your Windsurf agents for free by adding the GOVENANT Audit to your Windsurf MCP config. Have Cascade run a read-only, aggregate-only governance sweep and return a shareable trust report on whether your agents actually deliver.

Step 1

Add the audit to Windsurf

Paste one URL — no API key. Windsurf connects itself.

Step 2

Sign in

Browser sign-in. That’s the whole ask.

Step 3

Ask for the audit

Say “Run a GOVENANT trust sweep.” Get a shareable report back.

Add the GOVENANT Audit to Windsurf

The MCP server URL:

https://mcp.govenantstandard.org/mcp

Add to ~/.codeium/windsurf/mcp_config.json:

{
  "mcpServers": {
    "govenant": { "serverUrl": "https://mcp.govenantstandard.org/mcp" }
  }
}
  1. Add the GOVENANT server to ~/.codeium/windsurf/mcp_config.json — remote servers use the "serverUrl" key.
  2. Hit Refresh in the Windsurf MCP panel.
  3. Sign in when the browser opens (GitHub or Google).
  4. Ask Windsurf: “Run a GOVENANT trust sweep.”

Authentication: Browser sign-in.

What the Windsurf audit tells you

Anomalies first

The bad news up top: motion without delivery, missed work, approvals expiring unapproved, decisions never graded — the signs of performed autonomy.

Your grade

Where your Windsurf agents land on the GOVENANT ladder — Logged → Gated → Delivered → Earned — and the delivery numbers behind it.

Delivery, not activity

Verified outcomes vs. total actions, work delivered vs. missed — measured against the record, never self-reported.

A shareable page

Every run has its own URL, with an optional one-click “share for a free expert review.”

Windsurf audit — FAQ

Windsurf isn’t picking up the server — what’s wrong?
Remote servers in Windsurf use "serverUrl" (not "url"). Fix the key, then click Refresh in the MCP panel.
Is the GOVENANT Audit really free?
Yes. You sign in with GitHub or Google so we know who ran it — that’s the whole ask. No API key, no credit card, no paywall on the audit.
What does it read, and what does it never see?
It reads aggregate numbers from your agents’ own records: how many ran, how many finished, whether checks passed, which models you use. It never reads your prompts, your agents’ messages, your customers’ data, or any secrets.
What is “performed autonomy”?
Agents that look busy — fluent plans, satisfied logs — but don’t verifiably ship. Motion is not delivery. The audit measures verified outcomes against the record, never the logs’ self-report.

Using a different tool?

Prove your agents actually deliver.

Free under the covenant — the method is free forever. Read-only and aggregate-only: your prompts, data, and secrets never leave your machine.