Buildv2.4.1 · stable
Statusall systems nominal
Last sync19 Apr 2026 · 02:00 SAST
Mission IDGC-LOB-00412
T-00 · Living Organizational Baseline

GroundControl A curated marketplace of agents, skills and tooling that brings every workstation in your org to a single AI-assisted baseline.

$ curl -fsSL get.fullstack.co.za/gc | bash
125+
Specialised Agents
137+
Reusable Skills
3
OS Installers · mac · linux · win
30d
Rolling CLAUDE.md Backup
LON · 51.5°N CPT · −33.9°S
T-01 / Overview
What is GroundControl

A shared floor for AI-assisted development
across every workstation in your organization.

GroundControl is Full Stack's opinionated baseline for Claude Code. It ships a curated marketplace of agents, skills, installers, safety rails, and observability hooks so that every engineer — regardless of machine, role or seniority — operates from the same validated floor.

01 · Baseline

A single, upsert-safe baseline

One installer brings any laptop to organization baseline in minutes. Upserts only GroundControl-managed content — your personal agents and skills are preserved, versioned and rollback-ready.

02 · Marketplace

125 agents · 137 skills

Task-specific agents for development, testing, security and multi-model orchestration. Reusable skills for everything from release notes to voice synthesis to Graphviz diagrams — all invokable from Claude Code.

03 · Guardrails

Policy, compliance, audit

OpenClaw detection for prohibited software, license-compliance checking, regulatory guardrails (GDPR, HIPAA, SOC 2, ISO 27001) and an immutable input log — enforced at install and at runtime.

04 · Continuity

Memory that survives reboots

claude-mem persists cross-session context. Nightly CLAUDE.md backups keep a 30-day rolling history. Remote Control lets you resume a local session from any device — phone, tablet, browser.

T-02 / Installation
One line, three platforms

One-line install
on the OS you already run.

Every installer is non-destructive. A backup is created before any change and tracked in ~/.groundcontrol/version.json. Rollback is a single flag.

macOS · zsh
# bring this mac to baseline
# sign in at groundcontrol.fullstack.co.za first
curl -fsSL groundcontrol.fullstack.co.za/install.sh | bash

uv · bun · claude-code
ollama (0.15) · leann · whisper.cpp
125 agents · 137 skills copied to ~/.claude
claude-mem installed
nightly backup scheduled · cron 02:00
# ready.
Linux · bash
# debian / ubuntu / fedora / arch
# sign in at groundcontrol.fullstack.co.za first
$ curl -fsSL groundcontrol.fullstack.co.za/install.sh | bash

core deps (python3, node, git, uv)
bun · playwright-mcp
leann semantic index
hydra · tmux multi-user sessions
oh-my-claudecode preset
# pull models later: ./install-unix.sh --with-models
Windows · PowerShell (admin)
# run as administrator
# sign in at groundcontrol.fullstack.co.za first
PS> irm groundcontrol.fullstack.co.za/install.ps1 | iex

winget · bun · claude-code
ollama · whisper.cpp
GroundControl-ClaudeMD-Backup task
OpenClaw scan · clean
# leann: use WSL for native deps
# rollback: -Rollback -BackupId "..."
upsert mode 30-day CLAUDE.md backup version-tracked rollback-ready opt-in telemetry
~ 8 min on a clean machine · ~ 90 s on update · network required
T-03 / Marketplace · Agents
125+ task-specific agents · model: inherit

Agents for every seat in the room.

Each agent is a markdown system prompt with a clear mandate: architect, tester, reviewer, responder. They respect your Claude Code model config via model: inherit, so you pick the brain; GroundControl picks the role.

Showing 12 of 125 agents View full catalogue →
T-04 / Marketplace · Skills
137+ slash commands

Skills you can actually type.

Every skill is a slash command. From /release-notes to /runway-video to /akv-bridge, each one bundles prompt, docs and glue code so your team speaks the same commands across repos.

Showing 12 of 137 skills Browse all categories →
T-05 / Architecture
How it sits on your machine

Two directories.
Zero surprises.

GroundControl lives in two predictable places so it's easy to audit, back up, and roll back. Nothing wanders into system paths; nothing rewrites your dotfiles.

~/.groundcontrol · managed
agents/ 125.md
skills/ 137 folders
indexes/ leann
backups/ rollback-ready
version.json tracked
~/.claude · merged in
agents/ copied from GC
skills/ copied from GC
resources/brands/ 160+ dossiers
CLAUDE.md yours · backed up

The installer only writes into GroundControl-managed paths. Your handcrafted agents, custom CLAUDE.md, and private skills stay exactly where they are.

  • 01Upsert, not overwrite. Existing files are preserved. A backup is created before every change.
  • 02Version tracked. version.json records manifest hash, install time, machine ID.
  • 03Rollback-ready. --rollback --backup-id restores the last good state in under 30 seconds.
  • 04Nightly CLAUDE.md safety. 30-day rolling copy at ~/.groundcontrol/backups/claude-md/, deduplicated by hash.
  • 05Observable. An immutable input log means you can always explain what ran, when, and why.
T-06 / Integrations
Plays well with your stack

Wire in the tools you already own.

GroundControl is designed to sit between Claude Code and the model fleet, document graph and coworker tooling you already pay for. Defaults are cloud-first; local fallbacks are one env var away.

Cl
Claude Code
baseline runtime
Ol
Ollama 0.15+
anthropic-api mode
Gm
Google AI Studio
gemini pro/flash/ultra
Az
Azure DevOps
boards · pipelines
AK
Azure Key Vault
/akv-bridge
Pw
Playwright MCP
browser automation
Ln
LEANN
low-storage vector idx
Hy
Hydra
shared tmux sessions
Rw
Runway
video generation
El
ElevenLabs
voice synthesis
Wh
whisper.cpp
transcribe · diarise
M3
M365 Graph
docs · calendar · mail
Gh
GitHub Actions
PR wizard · CI
Sl
Slack · Teams
incident · digest
Se
Sentry
error-pattern analyzer
Jr
Jira
sprint analytics
Cm
claude-mem
persistent memory
Bn
Bun
30× faster installs
T-07 / Model Routing
Cloud-first, local-fallback

The right model
for the job at hand.

GroundControl's defaults route every task to the best-suited Ollama cloud model via the shared org account, and fall back to a local model on the same 192.168.0.98 fleet when you're offline.

Task Default (Cloud) Local Fallback

Lifecycle · qwen3 → qwen3.5 · gemma → gemma3 · use current versions for all new work.

T-08 / Security & Compliance
Because AI baselines live in regulated environments

Guardrails at install, at runtime, at review.

GroundControl ships security as first-class deliverables — not afterthoughts. Every layer is observable, every change is reversible, and every restriction is explicit.

OpenClaw Detection

Auto

Pre- and post-install scanning for prohibited software, with an immutable infection log for audit.

  • Runs on every install
  • Writes to OPENCLAW_INFECTION_LOG.MD
  • Blocks baseline if criteria unmet

Regulatory Coverage

Agents

Dedicated agents for GDPR, HIPAA, SOC 2, ISO 27001 and PCI-DSS review flows — scriptable, not bureaucratic.

  • regulatory-compliance-agent
  • compliance-auditor
  • license-compliance-checker

Secrets & Identity

AKV

Pull secrets from Azure Key Vault via Scorecards OAuth; set as transient env vars for the session only. Key rotation is a button.

  • /akv-bridge
  • akv-key-rotation agent
  • Azure Entra-aware

Output Quality Gate

0–100

Every AI output can be passed through output-quality-scorer — correctness, completeness, security, all scored 0–100 with rationale.

  • Runs in CI or pre-merge
  • Thresholds per repo
  • Feeds /ai-report

Remote Control

Opt-in

Continue a local Claude Code session from phone, tablet, or browser — code execution stays local; only the session UI is exposed.

  • Requires Claude Max/Pro
  • claude --remote or /remote
  • Per-session token

Dependency Audit

CVE

Deep dependency audit with CVE, license, and supply-chain analysis, with actionable remediation suggestions, not just a wall of CVE IDs.

  • dependency-audit agent
  • /compliance-docs
  • SBOM-ready output

Supply Chain Audit

NEW

Four-layer post-install audit: SBOM generation, CVE scanning (npm + pip), static analysis for exfiltration patterns, and integrity verification against a known-good allowlist. Scores 0-100 with org-wide visibility via Scorecards.

  • Detects network calls, eval/exec, env harvesting
  • Flags non-allowlisted URLs in dependencies
  • Plugin scanning (claude-mem, MCP servers)
  • Runs automatically on every install/update

Settings Integrity

HOOKS

Validates that telemetry hooks in settings.json are correctly formatted and complete. Detects PowerShell serialization corruption, duplicate entries, and missing hook events that silently disable usage analytics.

  • 4 required hook events validated
  • Corrupted string detection
  • Automatic repair guidance
T-09 / Rollout
From zero to baseline

A rollout you can actually ship.

GroundControl is designed to be adopted gradually. Start with one team. Measure. Expand. Every step is reversible.

Week 00

Pilot

Install on 3–5 engineers' workstations. Review generated agents, adjust the CLAUDE.md backup schedule, turn on OpenClaw.

Week 02

Calibrate

Pick the 10 skills your team will adopt first. Benchmark model choices via /model-benchmark. Tune routing defaults.

Week 04

Roll out

Install on every workstation. Enable nightly CLAUDE.md backup, Hydra shared sessions, and the immutable audit log.

Ongoing

Govern

Weekly /ai-report. Quarterly brand & policy refresh. Contribution review — your team's agents become the next marketplace.

T-10 / FAQ
Questions we get a lot

Short answers, specific machines.

Is GroundControl a fork of Claude Code?

No. GroundControl is a content layer that installs alongside Anthropic's official Claude Code CLI. Claude Code is still the runtime; GroundControl curates the agents, skills and installation scripts that bring a workstation to org baseline.

What happens to my existing agents and skills?

Nothing. The installer runs in upsert mode — only GroundControl-managed files are written, and a timestamped backup is created before every run. Custom content is preserved and a one-flag rollback is always available.

Does this send my code to anyone?

Only as much as your chosen model provider does. GroundControl itself does not exfiltrate data. Remote Control is opt-in and session-scoped. For fully-local work, the Ollama fallbacks run on a LAN fleet you control.

Can I use this without Claude?

Partly. The marketplace format targets Claude Code conventions, but many skills route to Google AI Studio, Runway, ElevenLabs, or local Ollama models. The model-router agent chooses per task based on cost, quality and speed.

Is LEANN available on Windows?

Native LEANN depends on Linux-only packages. On Windows we recommend running it in WSL — the rest of GroundControl installs natively via the PowerShell script.

How do I contribute an agent or skill?

Fork the repository, add your markdown (for agents) or folder with SKILL.md (for skills), keep model: inherit for agents, and open a PR. The auto-pr-reviewer agent will score it and leave review notes.

What's the licensing?

Proprietary, non-transferable. GroundControl is licensed exclusively to Full Stack (Pty) Ltd employees, contractors, and authorised agents. The licence is personal and may not be transferred, sublicensed, or used outside Full Stack engagements. See the LICENSE file for full terms.

Who pays for Ollama cloud calls?

By default, cloud inference is routed through Full Stack's shared ai@fullstack.co.za Ollama account. Organisations on their own baseline can point OLLAMA_CLOUD_ACCOUNT at their own account.

T-11 · Handover

One installer. A shared floor.

Bring your team to the same baseline this afternoon. Twelve minutes on a clean machine, ninety seconds on update, and fully reversible if you change your mind.

PublisherFull Stack (Pty) Ltd
Version2.4.1 · 2026-04-19
LicenceMIT
Repogithub.com/wearefullstack/groundcontrol
Contactsales@wearefullstack.com
HQCape Town · London · Wilmington
Tweaks
Accent
12-column overlay
Section markers (T-01…)