Open Source Software (OSS) governance, not Pull Request (PR) review

The consistency layer for teams without an OSS Program Manager.

Steward gives small Commercial Open Source Software (COSS) teams the discipline a dedicated OSS Program Manager (PM) provides — automated PR triage, contributor reputation, supply-chain risk, governance enforcement — without staffing one.

The wedge

We score the contributor, not just the diff.

AI PR-review tools review the patch. They don't tell you whether the stranger who opened it is a credible contributor or a drive-by risk. For an OSS maintainer drowning in unsolicited PRs, that's the question that matters — and it's the one structural gap in the AI-PR-review category.

Contributor reputation

Reproducible signal across thousands of repos. The PR-author lens a human PM provides with experience and intuition, available at PR open.

9-dimension PR evaluation

Risk, supply chain, scope alignment, maintenance cost, governance math, and more. Deterministic + Large Language Model (LLM) synthesized markdown reports you can paste into a review or share with your board.

Multi-repo governance

Fleet dashboards across your org's public surface. Per-repo governance.pxf config — the policy is data, not a Slack thread.

What Steward is and isn't

Honest about the operational gap we fill.

An OSS Program Manager does community work, strategic alignment, and contributor mentorship Steward doesn't touch. Steward is the operational half — the part you'd otherwise do in your margins.

CategoryWhat Steward doesWhat an OSS PM does that Steward doesn't
PR triage9-dim evaluation, risk scoring, contributor reputation, markdown reports.Judgment calls ("this PR is risky but politically important; let's land it").
Contributor relationsReputation scoring, first-PR welcomes, mentorship state, dormancy detection, mentor handoff.Strategic mentorship, conflict mediation, performance feedback.
Governancegovernance.pxf policy-as-code, Developer Certificate of Origin (DCO) sign-off, individual + corporate Contributor License Agreement (CLA) gates (per-commit enforcement).Sets the policy in the first place; arbitrates disputes.
Risk & complianceSupply-chain (license, pinned, mission-drift, alternatives — manual + behavioral + LLM); Service Organization Control 2 (SOC2) shaped audit-bundle export.Negotiates with downstream packagers; manages security disclosures.
Community & strategyNot what we do.Slack/Discord, events, DevRel, roadmap alignment, open-core boundary calls.

Public, private, or both

Not just for OSS. Most of what Steward does travels to internal repos.

The OSS framing leads because reputation-on-drive-by-PRs is the sharpest wedge against AI-PR-review tooling. But policy-as-code, supply-chain enforcement, CLA evidence, audit exports, and the multi-repo fleet dashboard apply identically to internal codebases — and for some buyers (compliance-driven companies, engineering leadership at growing teams) the private-repo angle is the stronger pull.

Works harder inside the company

  • Policy-as-code over Slack-thread rules — governance.pxf lives next to the code.
  • Supply-chain exposure is identical: a proprietary monolith pulling 400 npm packages has the same liability surface as an OSS library.
  • CLA / DCO covers internal Intellectual Property (IP) chain hygiene — contractor onboarding, acquisition diligence, joint-venture code.
  • Audit-bundle export sized for SOC2 / International Organization for Standardization (ISO) / Health Insurance Portability and Accountability Act (HIPAA). Most OSS projects don't need this; most compliance-driven private companies need it badly.
  • Single Sign-On (SSO) via OpenID Connect (OIDC) at the Business tier — Okta, Azure AD, Keycloak, Google Workspace. Drops Steward into the same Identity Provider (IdP) flow your engineers already authenticate through.
  • Multi-repo fleet with bulk-apply templating — one ProjectManager surface across 30 internal repos.

Less central inside a known team

  • Contributor reputation loses its edge — you already know your engineers' track record. Still useful for contractor or agency code; not the headline capability.
  • First-PR welcomes + mentor handoff are tuned for repeat new-contributor onboarding, which internal teams don't do every day.
  • Sponsor-a-Repo billing is specifically the public-OSS sponsorship product; skipped for purely-internal portfolios.

One product, both audiences. If you're an engineering manager tired of re-litigating PR-review rules every quarter, or a compliance lead who wants CLA evidence, SOC2-shaped audit exports, and SSO into your existing Identity Provider without writing custom workflow glue — the OSS framing doesn't mean Steward isn't for you.

Anchor

A fraction of the cost of doing this any other way.

The natural alternative isn't another PR-review tool — it's hiring an OSS Program Manager (~$200k/yr fully loaded) or continuing to triage drive-by contributions on Saturday afternoons. Business tier starts at $299/mo.

If you're a Series A–C startup with a public OSS surface — your core product or a critical open dependency — and your maintainers are doing the program- manager work in their margins, Steward is built for you.

Tell us about your repository →