Model inventory and governance: trace deployed models and their dependencies as an append-only log
git for models β know what models you have deployed, where they run, what they depend on, and what changed.
π Documentation Β· Quickstart Β· Concepts Β· Governance
model-ledger is a model inventory for any organization with deployed models. It discovers models, heuristic rules, and ETL across your platforms, maps the dependency graph automatically, and records every change as an immutable event. Unlike registries tied to a single platform (MLflow, SageMaker, W&B), it spans all of them β as one connected graph β and it's built to be driven by AI agents through a native MCP server.
Benchmarked at production scale: full inventory reconstruction over a ledger of 28.8k models and 212k events runs in under a second (CHANGELOG, v0.7.4).
pip install model-ledger
Every model is a DataNode with typed input and output ports. When an output port name
matches an input port name, connect() creates the dependency edge β no hand-wiring.
from model_ledger import Ledger, DataNode
ledger = Ledger()
ledger.add([
DataNode("segmentation", platform="etl", outputs=["customer_segments"]),
DataNode("fraud_scorer", platform="ml", inputs=["customer_segments"], outputs=["risk_scores"]),
DataNode("fraud_alerts", platform="alerting", inputs=["risk_scores"]),
])
ledger.connect()
ledger.trace("fraud_alerts")
# ['segmentation', 'fraud_scorer', 'fraud_alerts']
Every mutation is recorded as an immutable Snapshot β an append-only event log that gives you full history and point-in-time reconstruction, because nothing is overwritten.
The MCP server is a first-class surface β point Claude (or any MCP agent) at it:
pip install "model-ledger[mcp]"
claude mcp add model-ledger -- model-ledger mcp --demo
You: if we deprecate
customer_features, what breaks?Claude: 3 models consume it directly, 2 more transitively.
Everything lives at block.github.io/model-ledger β and it can't drift, because the API reference is generated from source and every example runs in CI:
flowchart LR
subgraph Sources
C1[SQL / REST / GitHub / Prefect<br/>connectors]
end
subgraph Core
L[Ledger<br/>append-only event log,<br/>point-in-time reconstruction]
G[Dependency graph]
V[Compliance profiles<br/>SR 11-7/SR 26-2 Β· EU AI Act Β· NIST AI RMF]
end
subgraph Surfaces
S1[Python SDK]
S2[CLI]
S3[REST API]
S4[MCP server Β· 8 tools]
end
B1[(in-memory Β· SQLite Β· JSON Β·<br/>Snowflake Β· remote HTTP)]
C1 --> L
L --> G
L --> V
L --- B1
S1 --> L
S2 --> L
S3 --> L
S4 --> L
The OSS core handles discovery, graph building, change tracking, storage, the agent
protocol, and compliance validation β the SR 11β7/SR 26β2, EU AI Act Annex IV, and
NIST AI RMF profiles ship in model_ledger.validate. Your internal package provides
only the thin layer on top: connector configs, custom connectors for internal
platforms, and credentials. Thin config, not reimplemented logic.
See CONTRIBUTING.md. All commits require DCO sign-off.
See SECURITY.md for how to report vulnerabilities privately.
Apache-2.0. See LICENSE.
Created and maintained by Vignesh Narayanaswamy at Block.
Source-derived launch command. Check the maintainerβs required arguments and credentials before running:
uvx model-ledgerMerge this template into ~/Library/Application Support/Claude/claude_desktop_config.json. Keep existing servers. Add any arguments, credentials, and permissions required by the maintainer; this template has not been install-tested.
{
"mcpServers": {
"io-github-block-model-ledger": {
"command": "uvx",
"args": [
"model-ledger"
]
}
}
}Restart Claude Desktop completely for changes to take effect. Confirm the server appears connected in the clientβs tool list, then try a read-only example from its documentation.
Claude Desktop setup referencemodel-ledgerpypiModel Ledger works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.
~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.~/.cursor/mcp.jsonRestart Cursor for changes to take effect..vscode/mcp.jsonReload VS Code window for changes to take effect.~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect..mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.