The Deterministic Multi-Agent Governance Protocol for Production Android Apps
Powered by Google Antigravity Β· Jetpack Compose Β· Roborazzi Β· Gradle Quality Airbag
Autonomous AI coding agents often derail when given unbounded write access to production codebases:
- Direct commits on
main/masterbypassing branch protection and peer review. - Premature implementation without sealed product specifications or human approval.
- Unmonitored autonomous merges and unverified tests causing silent regressions.
- Hardcoded UI literals breaking internationalization and accessibility.
- Hallucinated dependencies and architectural drift that degrade repository maintainability.
Agentic Android Delivery Kernel is an architectural framework and deterministic micro-kernel (< 10 KB) designed to enforce strict software engineering rigor on AI agents. It orchestrates 6 specialized engineering personas across a sequential state machine with 2 human-in-the-loop blocking gates, guaranteeing that no code is written, tested, or released without formal human authorization.
The kernel governs agent operations through a strict 3-Phase Deterministic Lifecycle with an essential Testing / Quality Airbag verification step prior to release:
flowchart TD
subgraph Inception["Phase 1 Β· Inception Consortium"]
P1["P1: Product Planner\nAnti-duplication & Gherkin User Stories"] --> P2["P2: Design Lead\nM3 Tokens, 4-State UI Matrix"]
P2 --> P3["P3: Privacy & Data\nZero-PII, Analytics Taxonomy, GDPR"]
P3 --> P4["P4: System Architect\nClean MVI, Boundaries, Epic DAG Decomposition"]
P4 --> Spec["Dual-Write Spec\nLocal implementation_plan.md"]
end
Spec --> Gate14{"π GATE 1.4 : Inception Halt\nExplicit Written Approval\n(Branch Guard active on main & epic/**)"}
subgraph Sealing["Just-In-Time (JIT) Sealing"]
Gate14 -->|Explicit approval| JIT["JIT Issue Sealer\n./scripts/seal-issue.sh --from-plan\nAtomic GitHub Issue & Project v2 Sync"]
end
subgraph Delivery["Phase 2 Β· Construction & Delivery"]
JIT --> Branch["Dedicated Feature Branch\n<type>/issue-<id>-<slug> (WIP = 1)"]
Branch --> P5["P5: Software Engineer\nTDD & Strict Compose Implementation\nZero Hardcoded Strings (strings.xml)"]
end
subgraph Testing["Testing & Verification"]
P5 --> Airbag["π‘οΈ Quality Airbag\n./scripts/quality-check.sh\n(codeSanityCheck + Lint + Roborazzi)\n& ./scripts/validate-docs.sh (38 Contracts)"]
end
subgraph Release["Phase 3 Β· Release & Observability"]
Airbag -->|100% green checks| P6["P6: Release Manager\nGit Push & Open PR Walkthrough"]
P6 --> Gate35{"π GATE 3.5 : Auto-Merge Lock\nHuman Authorization Required\n('Tu peux merger' / 'Approve merge')"}
Gate35 -->|Written confirmation| Merge["Squash Merge & Dual-Sync\nKanban Closure & Branch Pruning"]
end
style Gate14 fill:#ff4d4f,stroke:#333,stroke-width:2px,color:#fff
style Gate35 fill:#ff4d4f,stroke:#333,stroke-width:2px,color:#fff
style Airbag fill:#52c41a,stroke:#333,stroke-width:2px,color:#fff
style JIT fill:#1890ff,stroke:#333,stroke-width:2px,color:#fff
-
Phase 1 β Inception Consortium (Personas 1β4):
- Persona 1 (Product Planner) executes an anti-duplication query via
GitHubMCP:search_issues. - The Consortium drafts a formal 4-Pillar Specification in the local
implementation_plan.mdartifact. - Persona 4 consolidates sizing (
XStoXL) and estimates before sealing. - Gate 1.4 Verification (STOP & WAIT): Strict halt. Zero branches, code edits, or premature GitHub issues before explicit written approval.
- Upon Gate 1.4 approval:
./scripts/seal-issue.sh --from-planseals the tracking issue assigned to@mewith native flags (--milestone,--parent), associates Project v2 fields (Priority,Size,Estimate,Status: Ready), and initializes integration branches if Epic.
- Persona 1 (Product Planner) executes an anti-duplication query via
-
Phase 2 β Construction & Delivery (Persona 5):
- Activated strictly after Gate 1.4 approval and JIT sealing.
- P5 cuts a dedicated branch
<type>/issue-<id>-<slug>from default branch or active Epic branch (WIP = 1). - Production implementation adheres to Clean MVI architecture, strict Compose theming, and zero hardcoded literals.
- Testing / Quality Airbag: Execution of
./scripts/quality-check.sh(codeSanityCheck, Android Lint debug/release, Roborazzi visual regressions) and./scripts/validate-docs.sh(38 documentation contracts).
-
Phase 3 β Release & Observability (Persona 6):
- Activated after all Quality Airbag assertions pass 100% green.
- Persona 6 pushes the branch and opens a Pull Request with a structured Walkthrough via
GitHubMCP:create_pull_request. - PR targets
epic/**withskip-releasefor intermediate child tasks; targetsmainfor standalone or consolidated Epic releases. - Gate 3.5 β Zero Auto-Merge Lock: Strict halt with PR link. Merges exclusively after explicit user confirmation ("Tu peux merger" / "Approve merge").
- Executes squash merge, runs
.agent/hooks/post-merge-dual-sync.sh(dynamically synchronizing base branch), and prunes branches.
Pillar 1 (Design Spec) enforcement is contextual and adaptive:
- UI & Composable Changes: Persona 2 (Design Lead) must define Material 3 tokens (from
DESIGN.md), 4-state UI matrix (Loading,Empty,Error,Content), and Roborazzi expectations. - Non-UI Changes: For backend, Room, CI/CD, scripts, or doc chores, Pillar 1 is explicitly marked:
N/A β No visual/UI changes. - Explicit User Override: If prompt requests to skip design ("skip design" / "sans design"), P2 is immediately bypassed.
The kernel divides operational responsibilities into 6 distinct personas. To guarantee security and prevent unintended file modifications, the Principle of Least Privilege (PoLP) is enforced at runtime:
| Persona | Manifest | Role & Deliverables | Metadata Ownership | Shell Execution (run_command) |
|---|---|---|---|---|
| P1 Β· Product Planner | p1-product-planner.md | Anti-duplication, Gherkin User Stories, 3-State Access Matrix, Milestone hygiene | Priority, Estimate (co-owner) |
β Revoked |
| P2 Β· Design Lead | p2-design-lead.md | Material 3 tokens, WCAG AAA compliance, 4-state UI matrix, Roborazzi specs | Pillar 1 Design Spec | β Revoked |
| P3 Β· Privacy & Data | p3-privacy-data.md | Zero-PII telemetry contracts, GDPR/AI Act compliance, event taxonomy | Pillar 2 Data Spec | β Revoked |
| P4 Β· System Architect | p4-system-architect.md | Clean Arch, Room DDL, boundary audit, Epic DAG decomposition (< 300 LOC) | Size (XSβXL), Estimate (co-owner) |
β Revoked |
| P5 Β· Software Engineer | p5-software-engineer.md | Kotlin/Compose implementation, Clean MVI, Zero Hardcoded Strings, TDD | Working code, atomic commits | β Allowed (Dedicated branch only) |
| P6 Β· Release Manager | p6-release-manager.md | Quality Airbag, PR walkthrough, Milestone release train, Crashlytics sync | PR Lifecycle, Tier 1/2 releases | β Allowed (Release ops only) |
- Rule 0 (JIT Issue-First): Zero code, branch, or premature GitHub issue stubs before Gate 1.4. Issues are sealed Just-In-Time via
./scripts/seal-issue.shonly after human approval. - Rule 0.1 (Epic Branch Isolation Protocol): Epics (
Size: L/XL) establish an isolated integration branchepic/issue-<id>-<slug>. Direct commits onepic/**are strictly forbidden. Implementation proceeds via atomic child issues (< 300 diff lines) branching from and merging intoepic/**before a consolidated release PR lands onmain. - Rule A (Append-Only Immutability): Issue title and body are permanently read-only once created. Revisions are appended exclusively via comments.
- WIP = 1 (Single Active Pair): Exactly 1 issue
In Progressand at most 1 PRIn Reviewat any time (Macro Epic in progress, Micro child WIP = 1). - Dual-Write Pattern: Canonical remote GitHub issue synchronized with local
implementation_plan.mdmirror for IDE harmony. - Zero Auto-Merge Lock (Gate 3.5): The agent never merges autonomously without human confirmation ("Tu peux merger" / "Approve merge").
- Runtime Bypass Guardrails:
branch-guard.mjs: PreToolUse hook intercepting file write tools (write_to_file,replace_file_content), blocking edits on protected branches (main,epic/**).plan-guard.mjs: PreToolUse hook intercepting shell executions, blocking--no-verify, inline hooks overrides (-c core.hooksPath), and direct git pushes to protected branches.
.
βββ .agent/
β βββ hooks/ # Runtime tool interception & safety guards
β β βββ branch-guard.mjs # Blocks file writes on protected branches (main, epic/**)
β β βββ plan-guard.mjs # Blocks bypasses (--no-verify, -c core.hooksPath)
β β βββ pre-commit-airbag.sh # Staged lint, doc checks & zero-hardcoding verification
β β βββ post-merge-dual-sync.sh# Dynamic base-branch synchronization & branch cleanup
β βββ personas/ # 6 Declarative Engineering Persona manifests (PoLP)
β β βββ p1-product-planner.md
β β βββ p2-design-lead.md
β β βββ p3-privacy-data.md
β β βββ p4-system-architect.md
β β βββ p5-software-engineer.md
β β βββ p6-release-manager.md
β βββ playbooks/ # Modular engineering playbooks (< 8,500 bytes)
β β βββ android-standards.md # Kotlin, MVI, and Compose engineering standards
β β βββ compose-theming.md # Material 3 tokens & typography implementation
β β βββ room-migrations.md # SQLite DDL & Room schema migration protocols
β β βββ roborazzi-export.md # Screenshot testing & visual regression capture
β βββ rules/ # Core governance specifications (< 9,500 bytes)
β β βββ agent-lifecycle.md # 3-Phase Lifecycle, Circuit Breaker, Dual-Write
β β βββ backlog-planner.md # Inception Consortium, Rule 0/0.1/A, 10 Golden Rules
β β βββ git-workflow.md # Conventional commits, SemVer, branch hygiene
β β βββ firebase-standards.md # Cloud architecture & Crashlytics synchronization
β βββ sidecars/ # Automated background listeners
β β βββ sync-issue-progress.mjs# Auto-transitions issue to In Progress on checkout
β βββ skills/ # Native Antigravity semantic skills
β β βββ plan-issue/ # Inception & 4-Pillar framing skill
β β βββ open-pr/ # Release & Walkthrough delivery skill
β β βββ quality-airbag/ # Full sanity check validation skill
β β βββ sync-stitch/ # Stitch MCP screenshot synchronization skill
β βββ templates/ # Deterministic markdown templates
βββ app/ # Reference Android Starter Application
β βββ src/main/java/ # Clean Jetpack Compose starter activity
β βββ src/test/java/ # Roborazzi screenshot verification test suite
βββ docs/ # Technical governance specifications
β βββ analytics-taxonomy.md # P3 Contract: Zero-PII event taxonomy
β βββ qa-classification-test-guide.md # P6 Contract: QA test matrix & classification
β βββ scripts-reference.md # Operational CLI scripts reference documentation
βββ scripts/ # Operational automation tooling
β βββ install-hooks.sh # Binds git hooks to .agent/hooks
β βββ seal-issue.sh # Just-In-Time issue sealing & Projects v2 synchronization
β βββ quality-check.sh # Complete Gradle sanity check execution
β βββ validate-docs.sh # Formal verification of 38 documentation contracts
β βββ sync-project-metadata.mjs # Direct Projects v2 GraphQL metadata synchronization
βββ AGENTS.md # Agent Micro-Kernel & Root Governance (< 10,000 bytes)
βββ ARCHITECTURE.md # Formal Architecture & State Machine Specification
βββ DESIGN.md # Serene Intellectual Design Tokens (YAML frontmatter)
βββ design-system.md # Visual Component Matrix, 4-state specs & motion
βββ kernel.config.json # Declarative project configuration file
βββ kernel.config.schema.json # Formal JSON Schema validating kernel.config.json
βββ README.md # Engineering Showcase & Documentation
All repository-specific parameters are centralized in kernel.config.json, formally validated by kernel.config.schema.json:
{
"$schema": "./kernel.config.schema.json",
"project": {
"name": "My Android App",
"description": "Production Android app governed by Antigravity",
"version": "1.0.0"
},
"git": {
"owner": "my-org",
"repo": "my-android-app",
"defaultBranch": "main"
},
"android": {
"namespace": "com.example.myapp",
"applicationId": "com.example.myapp",
"minSdk": 26,
"targetSdk": 35,
"compileSdk": 35
},
"airbag": {
"checkCommand": "./scripts/quality-check.sh",
"validateDocsCommand": "./scripts/validate-docs.sh",
"enforceZeroHardcodedStrings": true
},
"delivery": {
"firebase": {
"enabled": false,
"appId": "",
"testerGroups": "testers, dev",
"artifactPath": "app/build/outputs/apk/release/app-release.apk"
}
}
}Clone the repository and adapt kernel.config.json with your project coordinates:
git clone https://github.com/nicolasvd/agentic-android-delivery-kernel.git my-app
cd my-app
# Customize kernel.config.jsonBind local git hooks to .agent/hooks to activate the pre-commit airbag and branch guard:
./scripts/install-hooks.shEnsure compilation, Android Lint, Roborazzi screenshot assertions, and documentation contracts pass:
# Validate documentation contracts and byte budgets (38 checks)
./scripts/validate-docs.sh
# Run runtime guardrail test suite
node scripts/test-runtime-guardrails.mjs
# Execute full Android code sanity check
./scripts/quality-check.shWhen initiating a feature or bug fix:
- Inception Prompt: Prompt the agent with your user requirement. Persona 1 checks for duplicates and the Consortium drafts
implementation_plan.md. - Gate 1.4 Halt: The agent halts and awaits your explicit approval.
- JIT Sealing: Once approved, the issue is sealed automatically on GitHub with Projects v2 fields.
- Delivery & Testing: Persona 5 implements code on
<type>/issue-<id>-<slug>and verifies tests green. - Gate 3.5 Release: Persona 6 opens the PR and awaits your explicit command ("Tu peux merger" / "Approve merge").
Explore the live delivery board in action:
π Live Delivery Board #2 (Agentic Delivery Board)
The board is updated automatically in real-time by the kernel automation:
Ready: Set at Gate 1.4 upon JIT sealing via./scripts/seal-issue.shwith computedPriority,Size, andEstimate.In Progress: Synchronized automatically when Persona 5 checks out the dedicated branch.In Review: Set when Persona 6 opens the PR at Gate 3.5.Done: Updated atomically upon human-authorized merge and dual-sync.
The kernel provides exhaustive technical playbooks and governance rules located in .agent/:
| Asset | Path | Summary & Focus |
|---|---|---|
| Android Standards | .agent/playbooks/android-standards.md |
Clean MVI, Kotlin Progressive mode, Unidirectional Data Flow, Zero Hardcoded Strings |
| Compose Theming | .agent/playbooks/compose-theming.md |
Material 3 token mapping, Serene Intellectual color palette, typography scales |
| Room Migrations | .agent/playbooks/room-migrations.md |
SQLite DDL, automated migration testing, Room schema export integrity |
| Roborazzi Export | .agent/playbooks/roborazzi-export.md |
Pixel-perfect screenshot capture, light/dark mode matrices, Stitch MCP sync |
| Agent Lifecycle | .agent/rules/agent-lifecycle.md |
3-Phase Lifecycle, Token Sobriety, Circuit Breaker, Dual-Write Pattern |
| Backlog Planner | .agent/rules/backlog-planner.md |
Rule 0/0.1/A, Inception Consortium, 4 Pillars, 10 Golden Planning Rules |
| Git Workflow | .agent/rules/git-workflow.md |
Conventional Commits, SemVer releases, Dual-Sync base branch reconciliation |
| Scripts Reference | docs/scripts-reference.md |
Comprehensive CLI reference for all operational scripts and sidecars |
| QA Test Guide | docs/qa-classification-test-guide.md |
4-tier crash qualification, non-fatal triage, automated QA test matrix |
| Analytics Taxonomy | docs/analytics-taxonomy.md |
Zero-PII contract, value bucketing, GDPR & EU AI Act compliance specifications |
| Design System | design-system.md |
Visual component states (Loading, Empty, Error, Content), motion timing |
| Design Tokens | DESIGN.md |
Canonical YAML frontmatter design tokens (Serene Intellectual palette) |
The repository includes a production-ready Android Compose starter:
- Jetpack Compose & Material 3: Pre-configured
Theme.kt,Color.kt, andType.ktadhering to Serene Intellectual design tokens. - Roborazzi Visual Regression Test:
app/src/test/.../GreetingPreviewScreenshotTest.ktverifying pixel-level rendering in JVM unit tests without an emulator. - Gradle Airbag Task:
./gradlew codeSanityCheckbundlinglintDebug,lintRelease, unit tests, and Roborazzi screenshot verification. - Kotlin Progressive Mode: Enforcing strict compiler checks, zero unused warnings, and null-safety guarantees.
The GitHub Actions pipeline (.github/workflows/delivery-pipeline.yml) enforces the Quality Airbag automatically:
- Pull Request Gate: Runs on all PRs targeting
mainandepic/**. Validates documentation budgets, executes Gradle sanity checks, and blocks regressions. - Intermediate Child PRs: Tagged with
skip-releaseto omit heavy APK building during iterative child tasks. - Release Automation: Triggered upon milestone closure or manual dispatch. Builds signed release APKs and automatically dispatches builds to Firebase App Distribution with structured release notes.
- Minimal Privileges: Workflows default to top-level
permissions: { contents: read, pull-requests: read }with scoped elevation only where strictly required.
Distributed under the Apache-2.0 License. See LICENSE for details.