Skip to content
Iria Monitor

HOW IT WORKS

No magic. Just hooks, git, and standards.

We don't read your code. We don't run AI to detect AI. We use hooks the agents already provide and we use git itself as the database.

The complete flow

From Claude editing a file to your dashboard

  1. The agent fires a PreToolUse hook

    Before Claude Code (or Cursor, Codex, Windsurf) edits a file, it calls a registered hook with the tool name and target file. We capture a snapshot.

    The agent fires a PreToolUse hook

    # ~/.claude/settings.json

    $ "PreToolUse": [{ "command": "iria-monitor ai-checkpoint claude-code" }]

  2. The agent edits the file

    Normal Claude/Cursor behavior. Nothing intercepted. The user accepts or rejects in their normal flow.

  3. PostToolUse fires — we diff

    The agent calls the post-hook. We compare snapshot vs current. The new lines are AI's. The unchanged ones are human's. We attribute, we don't guess.

    PostToolUse fires — we diff

    # lines 5-18 are now attributed to:

    $ claude-code/claude-sonnet-4-6 (session abc123)

  4. Append to the working log

    Attribution gets stored in .git/ai/working_logs/a1b2c3d.jsonl. Append-only, file-locked, safe under concurrent edits.

  5. git commit triggers post-commit hook

    Our git post-commit hook reads the working log, builds an Authorship Log, and stores it as a git note under refs/notes/ai.

    git commit triggers post-commit hook

    # view the note for any commit

    $ git notes --ref=ai show HEAD

  6. Local CLI works immediately

    No network needed. The local CLI reads the git note and shows attribution immediately.

    Local CLI works immediately

    # for individual developers, this is enough

    $ iria-monitor blame foo.py

    $ iria-monitor blame src/auth.py

    $ iria-monitor stats --durability

  7. Optional: push to your team dashboard

    If your org uses Iria Monitor cloud, the post-commit hook also POSTs the note to your tenant. Or you install our GitHub App and we read the notes via GitHub API on push events.

  8. Three views of the same data

    Personal (private to the dev), Vendor (the team/org), Enterprise (a buyer comparing multiple vendors). Same git notes underneath. Different lenses on top.

What the data looks like

A single file, attributed line by line. Multiplied by every commit, every repo, every vendor.

src/auth.py — Vendor A / payments-core
78% written by AI · 35 lines
  1. 1import oshuman
  2. 2import hmachuman
  3. 3from datetime import datetimehuman
  4. 4
  5. 5class AuthManager:claude-code
  6. 6 """Handle authentication lifecycle."""claude-code
  7. 7 def __init__(self, db):claude-code
  8. 8 self.db = dbclaude-code
  9. 9 self.cache = {}claude-code
  10. 10 def create_token(self, user_id):claude-code
  11. 11 return jwt.encode({"sub": user_id}, SECRET)claude-code
  12. 12
  13. 13 def authenticate(self, email, pwd):human
  14. 14 user = self.db.get_user(email)human
  15. 15 if not user: raise HTTPException(401)human
  16. 16 def validate_token(self, tok):cursor
  17. 17 try: return jwt.decode(tok, SECRET)cursor
  18. 18 except JWTError: return Nonecursor
claude-code · 7 linescursor · 3 lineshuman · 8 lines

Aggregated upward — this is what the dashboards run on.

Architecture

Local-first, cloud-optional

DEVELOPER'S MACHINE
Local-first, cloud-optional
AI agents
  • Claude Code
  • Cursor
  • Codex
  • Windsurf
PreToolUse · PostToolUse
iria-monitor CLI
  • Python · stdlib only
  • computes diff
  • attributes lines
.git/ai/working_logs/

JSONL + flock (concurrent-safe)

git commit
refs/notes/ai · git-ai v3.0.0

git notes --ref=ai show HEAD

git push (notes only)
IRIA MONITOR CLOUD · OPTIONAL
FastAPI + React · Prerendered public pages
GitHub App
  • iria-monitor-code-metrics
  • webhook receiver
fetches
Postgres
  • orgs · repos
  • commits · blame
3 Dashboards
  • Enterprise
  • Vendor
  • Personal

Source code never leaves the developer's machine. Only metadata.

Things you might be wondering

Do you read my source code?
No. The CLI reads files locally to compute diffs, but only line metadata (number, agent, model) leaves your machine — never the content. The cloud only stores attribution metadata, not source.
What if the agent doesn't fire hooks?
We support Claude Code, Cursor, Codex, Windsurf via official hooks. If an agent doesn't fire a hook, that edit is treated as human. We don't try to detect after the fact.
What happens if I rebase or amend?
Our post-rewrite hook updates the git notes to follow the new commit SHAs. Attribution survives rebase, amend, and cherry-pick. Force-push is the only thing that can break it.
What if a human edits an AI-generated line?
That line gets re-attributed to the human. We track who currently owns each line, not history. The "durability" metric measures exactly this: how much AI code stays AI-owned over time.
Is the git note format proprietary?
No. We use the open git-ai standard v3.0.0. Your notes are portable to any tool that reads the same format. If you stop using Iria Monitor, your data leaves with you.
Hook latency — does this slow me down?
Hook cycle is sub-100ms for normal files. The CLI is Python stdlib only — no heavy imports, no network calls, no LLM in the path. We measured.

Try it.

Two commands. No account needed for the CLI.

Get started