Product · Team Baseline
One agreed setup, pulled by choice
Observe the team for up to thirty days, propose a baseline from what they actually do, let an administrator edit and approve it — then let developers adopt it with a command. KeepRails never pushes configuration to a machine.
How it works
Proposed by evidence, published by a person
The generation step is the easy one. The reason this works is the step where a human disagrees with it.
- 01
Observe, then classify
Up to thirty days of observation, resolving each asset to installed, observed used, not observed, project-specific, or unattributable — per developer and per repository.
- 02
Propose, do not publish
A proposed baseline is produced and left as a proposal. Nothing about it takes effect, and nobody is measured against it yet.
- 03
Edit, approve, version
An administrator sets global, repository-scoped, review-required, and exception entries, then approves a version. Later snapshots compare against that version, not against a moving target.
Adoption
A baseline you can install, not only be graded against
This is the part most governance tooling skips. An approved baseline is the team's working setup offered to the developer — not just a standard they are measured against and left to work through alone.
Pulled, never pushed
Adoption happens because a developer ran a command on their machine. There is no remote write path, and there never will be.
Version-pinned
A machine adopts a specific approved version and stays there. Nothing updates silently underneath someone mid-sprint.
Previewed and reversible
The exact changes are shown and confirmed on the machine, written over a backup, atomically, with a rollback — the same path every other KeepRails change takes.
Capabilities
What the baseline makes possible
Once one approved version exists, several questions that were previously arguments become lookups.
Approved, not just verifiable
Provenance can only be verifiable or unverifiable on one machine. Approved requires a team to have agreed — this is where that word becomes available.
Drift with a referent
Drift is measured against an approved version, so it names a real gap rather than a difference of opinion.
Onboarding in one command
A new developer adopts the team’s actual setup instead of reconstructing it from a wiki page that went stale two quarters ago.
Coverage
What a baseline is not
The boundaries matter more here than anywhere else in the product, because this is the feature most easily turned into something nobody wanted.
Not enforcement
V1 is advisory. Checks do not block merges by default. Hard-blocking may be evaluated only after teams trust the finding quality and ask for it.
Not a ranking
Baseline adherence is not a score, and it does not produce a leaderboard. Named views exist to explain variance and support exceptions, not to rank people.
Not a claim about quality
Adopting the baseline is not asserted to make anyone faster or better. The product reports setup differences, with confidence — not causality.
Where it stops
No payloads are read. A tool the collectors cannot defensibly match is counted as unattributable rather than guessed into a category.
Related
Each surface feeds the next: what the scan finds becomes a finding, and a finding becomes a reversible change.
FAQs about Team Baseline
Is the baseline generated automatically?
It is proposed automatically and published by a person. A proposal is never applied on its own — an administrator edits it, decides what is global versus repository-scoped, marks what needs review, records exceptions, and approves a version.
How does a developer get the baseline?
They pull it, with an explicit command. It previews the exact changes, waits for confirmation, writes through the standard backup-and-atomic path, and records which baseline version was adopted.
Can you push the baseline to my machine?
No. Adoption is always pull-based and version-pinned, and it never updates silently. There is no mechanism by which KeepRails writes to a developer machine from the cloud.
What is drift?
A machine that has moved away from the approved baseline version. Drift is reported against a specific approved version, so "drifted" always means drifted from something a person signed off on.
What is an exception?
A recorded, audited decision that a baseline rule does not apply somewhere, with a reason and an owner. It is a first-class object, not a dismiss button — which is why the panel calls it "add exception" rather than "ignore".
Why thirty days?
Because a baseline built from a week of data mostly encodes that week. The window is long enough that the proposal describes what the team does rather than what it happened to do while being watched.
See what your fleet is actually running
The scan runs locally and reports in your terminal. No account, no upload.
keeprails scan