Enforcer Graph

graphwatch

A plan for a team of agents is a graph: tasks, and the tasks each one waits for. graphwatch draws that graph in your terminal and moves as the work moves. A task lights up when an agent claims it, pulses when the run finishes, and turns done only after the run was judged against its acceptance criteria.

It is one file with no dependencies. The offline demo needs no account and sends nothing anywhere.

Install

Download the binary for your platform from the releases page, check it against SHA256SUMS, and put it on your path.

# macOS on Apple silicon. Other builds: darwin-amd64, linux-amd64,
# linux-arm64, windows-amd64.exe, windows-arm64.exe
curl -fsSLO https://github.com/instruxi-io/enforcer-graph-demos/releases/latest/download/graphwatch-darwin-arm64
curl -fsSLO https://github.com/instruxi-io/enforcer-graph-demos/releases/latest/download/SHA256SUMS
grep graphwatch-darwin-arm64 SHA256SUMS | shasum -a 256 -c
chmod +x graphwatch-darwin-arm64
mv graphwatch-darwin-arm64 /usr/local/bin/graphwatch

On macOS, Gatekeeper may refuse a downloaded binary. Clear the quarantine flag with xattr -d com.apple.quarantine /usr/local/bin/graphwatch. With Go installed you can skip the download: clone the repository and run go run . inside graphwatch/.

To vendor it into your own repository, commit the binary for each platform you need next to its checksum line, or pin a release tag and download it in CI.

Try it with no account

graphwatch --demo --layout mycelium

A small plan is worked in-process and drawn as threads growing from the first tasks out to the last. Press Ctrl-C to quit.

Watch a real plan

Point it at a graph in your Enforcer workspace. It reads the graph's event stream, so it only draws when something happens.

export GRAPH_API_KEY=...         # a key from your Enforcer workspace
graphwatch --graph <graph-id>
graphwatch --graph <graph-id> --layout mycelium

If you already signed in with the enforcer Claude Code plugin, graphwatch can borrow that session instead of a key. The repository README shows how.

What you are looking at

On screenMeaning
A dotA task. Its colour is its state: looking for work, claimed, waiting for validation, waiting on others, held for review, or done.
A lineA dependency. Work flows down the screen in the layered view and outward in the mycelium view.
HeatActivity. A pulse travels in when a run starts and out when it finishes. A quiet plan stops drawing.
DoneOnly after the run was judged against the criteria fixed when the task was claimed. A rejected run sends the task back with everything after it still blocked.

Options

FlagWhat it does
--graphThe graph to watch.
--layoutlayers (the default) or mycelium.
--demoOffline with --layout mycelium. Otherwise it creates a demo graph in your workspace and works it.
--stayKeep watching after the plan completes.
--fpsFrames per second, 15 by default. Only changed cells are redrawn.

Licence

graphwatch and the browser viewer beside it are MIT licensed, in enforcer-graph-demos. The Enforcer Graph service and its API are not open source, and watching a real plan needs an Enforcer account. Teams plans are coming soon.

An Instruxi solution. Verified against Enforcer Governor v2.8.0 on 25 September 2026. Runs in Claude Code today; other harnesses are coming. Nothing leaves your machine until you sign in to an Enforcer workspace. Next: Teams (soon), Install, FAQ. Enforcer, the identity and authorization service, is at enforcer.instruxi.dev.