[{"data":1,"prerenderedAt":2232},["ShallowReactive",2],{"navigation":3,"/advanced/governance-and-approvals":879,"/advanced/governance-and-approvals-surround":2227},[4,22,45,115,156,187,214,235,264,295,318,361,389,418,436,470,491,534,548,571,632,670,693,757,850],{"title":5,"path":6,"stem":7,"children":8,"icon":11},"Introduction","/introduction","01.introduction/1.index",[9,12,17],{"title":10,"path":6,"stem":7,"icon":11},"What is Orkestia?","i-lucide-sparkles",{"title":13,"path":14,"stem":15,"icon":16},"Core Philosophy","/introduction/core-philosophy","01.introduction/2.core-philosophy","i-lucide-shield-check",{"title":18,"path":19,"stem":20,"icon":21},"Key Benefits","/introduction/key-benefits","01.introduction/3.key-benefits","i-lucide-trophy",{"title":23,"path":24,"stem":25,"children":26,"icon":29},"Getting Started","/getting-started","02.getting-started/1.index",[27,30,35,40],{"title":28,"path":24,"stem":25,"icon":29},"Quick Start","i-lucide-rocket",{"title":31,"path":32,"stem":33,"icon":34},"Architecture Overview","/getting-started/architecture-overview","02.getting-started/2.architecture-overview","i-lucide-layout-dashboard",{"title":36,"path":37,"stem":38,"icon":39},"Concepts at a Glance","/getting-started/concepts","02.getting-started/3.concepts","i-lucide-list",{"title":41,"path":42,"stem":43,"icon":44},"Connect an AI Assistant","/getting-started/connect-an-ai-assistant","02.getting-started/4.connect-an-ai-assistant","i-lucide-bot",{"title":46,"path":47,"stem":48,"children":49,"icon":51},"Core Concepts","/concepts","03.concepts/01.index",[50,52,57,62,67,71,76,81,86,91,96,100,105,110],{"title":46,"path":47,"stem":48,"icon":51},"i-lucide-book-open",{"title":53,"path":54,"stem":55,"icon":56},"Workflows","/concepts/workflows","03.concepts/02.workflows","i-lucide-workflow",{"title":58,"path":59,"stem":60,"icon":61},"DGI — Dialog Generative Interface","/concepts/dgi","03.concepts/03.dgi","i-lucide-brain",{"title":63,"path":64,"stem":65,"icon":66},"Staff & AI Workforce Governance","/concepts/staff-governance","03.concepts/04.staff-governance","i-lucide-users-round",{"title":68,"path":69,"stem":70,"icon":44},"Agents — the execution substrate","/concepts/agents-platform","03.concepts/05.agents-platform",{"title":72,"path":73,"stem":74,"icon":75},"Runners & Execution Environments","/concepts/runners","03.concepts/06.runners","i-lucide-server-cog",{"title":77,"path":78,"stem":79,"icon":80},"Lumen Observability","/concepts/lumen","03.concepts/07.lumen","i-lucide-activity",{"title":82,"path":83,"stem":84,"icon":85},"Identity & Multi-Tenancy","/concepts/identity-multi-tenancy","03.concepts/08.identity-multi-tenancy","i-lucide-users",{"title":87,"path":88,"stem":89,"icon":90},"Billing, Pricing & Seats","/concepts/billing-and-seats","03.concepts/09.billing-and-seats","i-lucide-credit-card",{"title":92,"path":93,"stem":94,"icon":95},"App Data","/concepts/appdata","03.concepts/10.appdata","i-lucide-database",{"title":97,"path":98,"stem":99,"icon":61},"Engram","/concepts/engram","03.concepts/11.engram",{"title":101,"path":102,"stem":103,"icon":104},"DevKit","/concepts/devkit","03.concepts/12.devkit","i-lucide-terminal",{"title":106,"path":107,"stem":108,"icon":109},"App Host","/concepts/app-host","03.concepts/13.app-host","i-lucide-globe",{"title":111,"path":112,"stem":113,"icon":114},"Agent Exchange","/concepts/agent-exchange","03.concepts/14.agent-exchange","i-lucide-landmark",{"title":116,"path":117,"stem":118,"children":119,"icon":121},"Guides","/guides","04.guides/1.index",[120,122,127,132,137,142,147,151],{"title":116,"path":117,"stem":118,"icon":121},"i-lucide-compass",{"title":123,"path":124,"stem":125,"icon":126},"Building with DGI","/guides/building-with-dgi","04.guides/2.building-with-dgi","i-lucide-brain-circuit",{"title":128,"path":129,"stem":130,"icon":131},"Creating & Exposing Virtual Workflows","/guides/virtual-workflows","04.guides/4.virtual-workflows","i-lucide-blocks",{"title":133,"path":134,"stem":135,"icon":136},"Runner Management & Provisioning","/guides/runner-management","04.guides/5.runner-management","i-lucide-server",{"title":138,"path":139,"stem":140,"icon":141},"Security & Compliance","/guides/security-and-compliance","04.guides/7.security-and-compliance","i-lucide-shield",{"title":143,"path":144,"stem":145,"icon":146},"Tickets & Software Delivery","/guides/tickets-and-software-delivery","04.guides/8.tickets-and-software-delivery","i-lucide-ticket",{"title":148,"path":149,"stem":150},"Orkestia for AI-driven cloud infrastructure automation","/guides/cloud-automation-alternatives","04.guides/9.cloud-automation-alternatives",{"title":152,"path":153,"stem":154,"icon":155},"Typed decisions with TypeSafe","/guides/typed-decisions-with-typesafe","04.guides/9.typed-decisions-with-typesafe","i-lucide-git-branch",{"title":157,"path":158,"stem":159,"children":160,"icon":162},"Reference","/reference","05.reference/1.index",[161,163,168,173,177,182],{"title":157,"path":158,"stem":159,"icon":162},"i-lucide-library",{"title":164,"path":165,"stem":166,"icon":167},"Workflow Types & Registry","/reference/workflow-types-registry","05.reference/2.workflow-types-registry","i-lucide-list-tree",{"title":169,"path":170,"stem":171,"icon":172},"MCP Integration","/reference/mcp-integration","05.reference/3.mcp-integration","i-lucide-plug-zap",{"title":174,"path":175,"stem":176,"icon":104},"API & Tooling","/reference/api-tooling","05.reference/4.api-tooling",{"title":178,"path":179,"stem":180,"icon":181},"Integrations Catalog","/reference/integrations-catalog","05.reference/6.integrations-catalog","i-lucide-plug",{"title":183,"path":184,"stem":185,"icon":186},"Platform Services","/reference/platform-services","05.reference/7.platform-services","i-lucide-boxes",{"title":188,"path":189,"stem":190,"children":191,"icon":193},"Advanced Topics","/advanced","06.advanced/1.index",[192,194,199,204,209],{"title":188,"path":189,"stem":190,"icon":193},"i-lucide-flask-conical",{"title":195,"path":196,"stem":197,"icon":198},"Hybrid AI + Deterministic Execution","/advanced/hybrid-execution-model","06.advanced/2.hybrid-execution-model","i-lucide-git-merge",{"title":200,"path":201,"stem":202,"icon":203},"Drift Detection & Self-Healing","/advanced/drift-detection-self-healing","06.advanced/3.drift-detection-self-healing","i-lucide-heart-pulse",{"title":205,"path":206,"stem":207,"icon":208},"Governance & Approvals","/advanced/governance-and-approvals","06.advanced/4.governance-and-approvals","i-lucide-scale",{"title":210,"path":211,"stem":212,"icon":213},"Cost & Performance Optimization","/advanced/cost-and-performance","06.advanced/5.cost-and-performance","i-lucide-zap",{"title":215,"path":216,"stem":217,"children":218,"icon":220},"Operations","/operations","07.operations/1.index",[219,221,225,230],{"title":215,"path":216,"stem":217,"icon":220},"i-lucide-settings-2",{"title":222,"path":223,"stem":224,"icon":186},"Deployment Models","/operations/deployment-models","07.operations/2.deployment-models",{"title":226,"path":227,"stem":228,"icon":229},"Monitoring & Debugging","/operations/monitoring-and-debugging","07.operations/3.monitoring-and-debugging","i-lucide-bug",{"title":231,"path":232,"stem":233,"icon":234},"Best Practices","/operations/best-practices","07.operations/4.best-practices","i-lucide-check-check",{"title":236,"path":237,"stem":238,"children":239,"icon":241},"AWS Connections","/aws-connections","08.aws-connections/1.index",[240,242,245,250,255,260],{"title":236,"path":237,"stem":238,"icon":241},"i-simple-icons-amazonaws",{"title":23,"path":243,"stem":244,"icon":29},"/aws-connections/getting-started","08.aws-connections/2.getting-started",{"title":246,"path":247,"stem":248,"icon":249},"Setup Methods","/aws-connections/setup-methods","08.aws-connections/3.setup-methods","i-lucide-wrench",{"title":251,"path":252,"stem":253,"icon":254},"Managing Connections","/aws-connections/managing-connections","08.aws-connections/4.managing-connections","i-lucide-settings",{"title":256,"path":257,"stem":258,"icon":259},"Security Best Practices","/aws-connections/security-best-practices","08.aws-connections/5.security-best-practices","i-lucide-lock",{"title":261,"path":262,"stem":263,"icon":229},"Troubleshooting","/aws-connections/troubleshooting","08.aws-connections/6.troubleshooting",{"title":265,"path":266,"stem":267,"children":268,"icon":270},"Cloud Connections","/cloud-connections","09.cloud-connections/1.index",[269,271,276,281,286,291],{"title":265,"path":266,"stem":267,"icon":270},"i-lucide-cable",{"title":272,"path":273,"stem":274,"icon":275},"Google Cloud (GCP)","/cloud-connections/gcp","09.cloud-connections/2.gcp","i-simple-icons-googlecloud",{"title":277,"path":278,"stem":279,"icon":280},"Microsoft Azure","/cloud-connections/azure","09.cloud-connections/3.azure","i-simple-icons-microsoftazure",{"title":282,"path":283,"stem":284,"icon":285},"Magalu Cloud","/cloud-connections/magalu","09.cloud-connections/4.magalu","i-lucide-cloud",{"title":287,"path":288,"stem":289,"icon":290},"Kubernetes","/cloud-connections/kubernetes","09.cloud-connections/5.kubernetes","i-simple-icons-kubernetes",{"title":292,"path":293,"stem":294,"icon":208},"TypeSafe","/cloud-connections/typesafe","09.cloud-connections/6.typesafe",{"title":296,"path":297,"stem":298,"children":299,"icon":136},"DNS Providers","/dns-providers","10.dns-providers/1.index",[300,302,305,308,311,315],{"title":301,"path":297,"stem":298,"icon":136},"DNS Provider Connections",{"title":23,"path":303,"stem":304,"icon":29},"/dns-providers/getting-started","10.dns-providers/2.getting-started",{"title":246,"path":306,"stem":307,"icon":249},"/dns-providers/setup-methods","10.dns-providers/3.setup-methods",{"title":251,"path":309,"stem":310,"icon":254},"/dns-providers/managing-connections","10.dns-providers/4.managing-connections",{"title":312,"path":313,"stem":314,"icon":39},"Zones and Records","/dns-providers/zones-and-records","10.dns-providers/5.zones-and-records",{"title":261,"path":316,"stem":317,"icon":229},"/dns-providers/troubleshooting","10.dns-providers/6.troubleshooting",{"title":319,"path":320,"stem":321,"children":322,"icon":29},"Cloud Deploy","/cloud-deploy","11.cloud-deploy/01.index",[323,324,327,332,336,341,345,349,354,358],{"title":319,"path":320,"stem":321,"icon":29},{"title":23,"path":325,"stem":326,"icon":29},"/cloud-deploy/getting-started","11.cloud-deploy/02.getting-started",{"title":328,"path":329,"stem":330,"icon":331},"Creating a Site","/cloud-deploy/creating-a-site","11.cloud-deploy/03.creating-a-site","i-lucide-plus-circle",{"title":333,"path":334,"stem":335,"icon":34},"Site Overview and Deployments","/cloud-deploy/site-overview","11.cloud-deploy/04.site-overview",{"title":337,"path":338,"stem":339,"icon":340},"Deployment Progress and Success","/cloud-deploy/deployment-progress","11.cloud-deploy/05.deployment-progress","i-lucide-loader",{"title":342,"path":343,"stem":344,"icon":254},"Settings","/cloud-deploy/settings","11.cloud-deploy/06.settings",{"title":346,"path":347,"stem":348,"icon":109},"Custom Domains","/cloud-deploy/custom-domains","11.cloud-deploy/07.custom-domains",{"title":350,"path":351,"stem":352,"icon":353},"Resources, Releases, and Danger Zone","/cloud-deploy/resources-releases","11.cloud-deploy/08.resources-releases","i-lucide-package",{"title":355,"path":356,"stem":357,"icon":141},"Admin Dashboard","/cloud-deploy/admin-dashboard","11.cloud-deploy/09.admin-dashboard",{"title":261,"path":359,"stem":360,"icon":229},"/cloud-deploy/troubleshooting","11.cloud-deploy/10.troubleshooting",{"title":362,"path":363,"stem":364,"children":365,"icon":368},"User Onboarding","/user-onboarding","12.user-onboarding/1.index",[366,369,372,377,382,386],{"title":367,"path":363,"stem":364,"icon":368},"User Creation and Onboarding","i-lucide-user-plus",{"title":23,"path":370,"stem":371,"icon":29},"/user-onboarding/getting-started","12.user-onboarding/2.getting-started",{"title":373,"path":374,"stem":375,"icon":376},"Creating Your Organization","/user-onboarding/onboarding","12.user-onboarding/3.onboarding","i-lucide-building-2",{"title":378,"path":379,"stem":380,"icon":381},"Invitations","/user-onboarding/invitations","12.user-onboarding/4.invitations","i-lucide-mail",{"title":383,"path":384,"stem":385,"icon":254},"Managing Your Account","/user-onboarding/managing-account","12.user-onboarding/5.managing-account",{"title":261,"path":387,"stem":388,"icon":229},"/user-onboarding/troubleshooting","12.user-onboarding/6.troubleshooting",{"title":342,"path":390,"stem":391,"children":392,"icon":394},"/settings","13.settings/1.index",[393,395,400,404,409,413],{"title":342,"path":390,"stem":391,"icon":394},"i-lucide-sliders-horizontal",{"title":396,"path":397,"stem":398,"icon":399},"General Settings","/settings/general","13.settings/2.general","i-lucide-user",{"title":401,"path":402,"stem":403,"icon":85},"Members Settings","/settings/members","13.settings/3.members",{"title":405,"path":406,"stem":407,"icon":408},"Notifications Settings","/settings/notifications","13.settings/4.notifications","i-lucide-bell",{"title":410,"path":411,"stem":412,"icon":141},"Security Settings","/settings/security","13.settings/5.security",{"title":414,"path":415,"stem":416,"icon":417},"Signing Keys","/settings/keys","13.settings/6.keys","i-lucide-key-round",{"title":419,"path":420,"stem":421,"children":422,"icon":29},"App Enablement","/app-enablement","14.app-enablement/1.index",[423,424,428,432],{"title":419,"path":420,"stem":421,"icon":29},{"title":425,"path":426,"stem":427,"icon":417},"Sign in with Orkestia","/app-enablement/sign-in-with-orkestia","14.app-enablement/2.sign-in-with-orkestia",{"title":429,"path":430,"stem":431,"icon":95},"End-user data","/app-enablement/end-user-data","14.app-enablement/3.end-user-data",{"title":433,"path":434,"stem":435,"icon":131},"Compositions — use, invoke, share","/app-enablement/compositions","14.app-enablement/4.compositions",{"title":437,"path":438,"stem":439,"children":440,"icon":80},"Lumen","/lumen","15.lumen/1.index",[441,442,447,452,457,461,465],{"title":437,"path":438,"stem":439,"icon":80},{"title":443,"path":444,"stem":445,"icon":446},"Enable Lumen","/lumen/enable","15.lumen/2.enable","i-lucide-power",{"title":448,"path":449,"stem":450,"icon":451},"Send data","/lumen/send-data","15.lumen/3.send-data","i-lucide-upload",{"title":453,"path":454,"stem":455,"icon":456},"Collector","/lumen/collector","15.lumen/4.collector","i-lucide-container",{"title":458,"path":459,"stem":460,"icon":34},"Use Lumen","/lumen/observe","15.lumen/5.observe",{"title":462,"path":463,"stem":464,"icon":44},"Lumen MCP","/lumen/mcp","15.lumen/6.mcp",{"title":466,"path":467,"stem":468,"icon":469},"Query API","/lumen/query-api","15.lumen/7.query-api","i-lucide-search",{"title":471,"path":472,"stem":473,"children":474,"icon":476},"SDKs","/sdks","16.sdks/1.index",[475,477,482,487],{"title":471,"path":472,"stem":473,"icon":476},"i-lucide-code",{"title":478,"path":479,"stem":480,"icon":481},"Workflows SDK — Node / TypeScript","/sdks/workflows-nodejs","16.sdks/2.workflows-nodejs","i-lucide-file-ts",{"title":483,"path":484,"stem":485,"icon":486},"Workflows SDK — Python","/sdks/workflows-python","16.sdks/3.workflows-python","i-simple-icons-python",{"title":488,"path":489,"stem":490,"icon":417},"Auth SDK — Sign in with Orkestia","/sdks/auth","16.sdks/4.auth",{"title":92,"path":492,"stem":493,"children":494,"icon":95},"/appdata","17.appdata/1.index",[495,496,501,506,510,515,520,525,530],{"title":92,"path":492,"stem":493,"icon":95},{"title":497,"path":498,"stem":499,"icon":500},"Declare structures","/appdata/declare","17.appdata/2.declare","i-lucide-table",{"title":502,"path":503,"stem":504,"icon":505},"Records & Data API","/appdata/data-api","17.appdata/3.data-api","i-lucide-rows-3",{"title":507,"path":508,"stem":509,"icon":376},"Ownership & workspaces","/appdata/ownership","17.appdata/4.ownership",{"title":511,"path":512,"stem":513,"icon":514},"Expose App Data to end-users","/appdata/expose","17.appdata/5.expose","i-lucide-app-window",{"title":516,"path":517,"stem":518,"icon":519},"PostgREST HTTP","/appdata/postgrest","17.appdata/6.postgrest","i-lucide-unplug",{"title":521,"path":522,"stem":523,"icon":524},"Ordered append","/appdata/append","17.appdata/7.append","i-lucide-list-ordered",{"title":526,"path":527,"stem":528,"icon":529},"Databases and instances","/appdata/instances","17.appdata/8.instances","i-lucide-hard-drive",{"title":531,"path":532,"stem":533,"icon":104},"Query console and SQL","/appdata/query","17.appdata/9.query",{"title":97,"path":535,"stem":536,"children":537,"icon":61},"/engram","18.engram/1.index",[538,539,543],{"title":97,"path":535,"stem":536,"icon":61},{"title":540,"path":541,"stem":542,"icon":155},"Write & recall","/engram/write-recall","18.engram/2.write-recall",{"title":544,"path":545,"stem":546,"icon":547},"Field & feed","/engram/agent-memory","18.engram/3.agent-memory","i-lucide-radio",{"title":101,"path":549,"stem":550,"children":551,"icon":104},"/devkit","19.devkit/1.index",[552,553,558,562,567],{"title":101,"path":549,"stem":550,"icon":104},{"title":554,"path":555,"stem":556,"icon":557},"Install DevKit","/devkit/install","19.devkit/2.install","i-lucide-download",{"title":559,"path":560,"stem":561,"icon":519},"Hook redirect","/devkit/hooks","19.devkit/3.hooks",{"title":563,"path":564,"stem":565,"icon":566},"Local coding runner","/devkit/local-runner","19.devkit/4.local-runner","i-lucide-cpu",{"title":568,"path":569,"stem":570,"icon":131},"Compositions from DevKit","/devkit/compositions","19.devkit/5.compositions",{"title":572,"path":573,"stem":574,"children":575,"icon":44},"Staff & Agents","/staff-and-agents","20.staff-and-agents/01.index",[576,577,582,586,590,594,598,602,606,611,615,620,625,629],{"title":572,"path":573,"stem":574,"icon":44},{"title":578,"path":579,"stem":580,"icon":581},"Prerequisites","/staff-and-agents/prerequisites","20.staff-and-agents/02.prerequisites","i-lucide-list-checks",{"title":583,"path":584,"stem":585,"icon":368},"Hire an actor","/staff-and-agents/hire-an-actor","20.staff-and-agents/03.hire-an-actor",{"title":587,"path":588,"stem":589,"icon":34},"Console","/staff-and-agents/console","20.staff-and-agents/04.console",{"title":591,"path":592,"stem":593,"icon":11},"Configs, skills, and MCP","/staff-and-agents/configs-skills-mcp","20.staff-and-agents/05.configs-skills-mcp",{"title":595,"path":596,"stem":597,"icon":136},"Agent runner groups","/staff-and-agents/runner-groups","20.staff-and-agents/06.runner-groups",{"title":599,"path":600,"stem":601,"icon":16},"Governance","/staff-and-agents/governance","20.staff-and-agents/07.governance",{"title":603,"path":604,"stem":605,"icon":417},"Identity and tokens","/staff-and-agents/identity","20.staff-and-agents/08.identity",{"title":607,"path":608,"stem":609,"icon":610},"Memory and cost","/staff-and-agents/memory-and-cost","20.staff-and-agents/09.memory-and-cost","i-lucide-wallet",{"title":612,"path":613,"stem":614,"icon":155},"Coding agents","/staff-and-agents/coding-agents","20.staff-and-agents/10.coding-agents",{"title":616,"path":617,"stem":618,"icon":619},"Wire a repository for coding agents","/staff-and-agents/wire-a-repository","20.staff-and-agents/11.wire-a-repository","i-lucide-link",{"title":621,"path":622,"stem":623,"icon":624},"Run a ticket end to end","/staff-and-agents/run-a-ticket","20.staff-and-agents/12.run-a-ticket","i-lucide-play",{"title":626,"path":627,"stem":628,"icon":66},"Build a product team of actors","/staff-and-agents/build-a-product-team","20.staff-and-agents/13.build-a-product-team",{"title":261,"path":630,"stem":631,"icon":249},"/staff-and-agents/troubleshooting","20.staff-and-agents/14.troubleshooting",{"title":106,"path":633,"stem":634,"children":635,"icon":109},"/app-host","21.app-host/1.index",[636,637,641,644,649,653,658,662,666],{"title":106,"path":633,"stem":634,"icon":109},{"title":638,"path":639,"stem":640,"icon":514},"Your app and site","/app-host/your-app","21.app-host/2.your-app",{"title":92,"path":642,"stem":643,"icon":95},"/app-host/app-data","21.app-host/3.app-data",{"title":645,"path":646,"stem":647,"icon":648},"Website and process","/app-host/hosting","21.app-host/4.hosting","i-lucide-cloud-upload",{"title":650,"path":651,"stem":652,"icon":547},"Buzz","/app-host/buzz","21.app-host/5.buzz",{"title":654,"path":655,"stem":656,"icon":657},"Files","/app-host/files","21.app-host/6.files","i-lucide-folder",{"title":659,"path":660,"stem":661,"icon":109},"Your own domain","/app-host/your-domain","21.app-host/7.your-domain",{"title":663,"path":664,"stem":665,"icon":229},"Troubleshooting App Host","/app-host/troubleshooting","21.app-host/8.troubleshooting",{"title":667,"path":668,"stem":669,"icon":417},"Signing keys","/app-host/signing-keys","21.app-host/9.signing-keys",{"title":111,"path":671,"stem":672,"children":673,"icon":114},"/agent-exchange","22.agent-exchange/01.index",[674,675,678,682,686,690],{"title":111,"path":671,"stem":672,"icon":114},{"title":583,"path":676,"stem":677,"icon":368},"/agent-exchange/hire","22.agent-exchange/02.hire",{"title":679,"path":680,"stem":681,"icon":208},"List an actor","/agent-exchange/list","22.agent-exchange/03.list",{"title":683,"path":684,"stem":685,"icon":104},"Invoke & leases","/agent-exchange/invoke","22.agent-exchange/04.invoke",{"title":687,"path":688,"stem":689,"icon":141},"Settlement & trust","/agent-exchange/settlement","22.agent-exchange/05.settlement",{"title":53,"path":691,"stem":692,"icon":56},"/agent-exchange/workflows","22.agent-exchange/06.workflows",{"title":694,"path":695,"stem":696,"children":697,"icon":75},"Runners","/runners","23.runners/1.index",[698,700,704,709,713,717,721,726,730,734,738,741,745,749,753],{"title":699,"path":695,"stem":696,"icon":75},"Runner groups",{"title":701,"path":702,"stem":703,"icon":275},"Cloud Run","/runners/cloud-run","23.runners/10.cloud-run",{"title":705,"path":706,"stem":707,"icon":708},"DigitalOcean App Job","/runners/do-app-job","23.runners/11.do-app-job","i-simple-icons-digitalocean",{"title":710,"path":711,"stem":712,"icon":708},"DigitalOcean Droplet","/runners/do-droplet","23.runners/12.do-droplet",{"title":714,"path":715,"stem":716,"icon":285},"Magalu Cloud VM","/runners/magalu-vm","23.runners/13.magalu-vm",{"title":101,"path":718,"stem":719,"icon":720},"/runners/devkit","23.runners/14.devkit","i-lucide-laptop",{"title":722,"path":723,"stem":724,"icon":725},"Purposes & integrations","/runners/purposes","23.runners/16.purposes","i-lucide-layers",{"title":727,"path":728,"stem":729,"icon":241},"Fargate","/runners/fargate","23.runners/2.fargate",{"title":731,"path":732,"stem":733,"icon":241},"EC2 Auto Scaling","/runners/ec2-auto-scaling","23.runners/3.ec2-auto-scaling",{"title":735,"path":736,"stem":737,"icon":241},"EC2 VM","/runners/ec2-vm","23.runners/4.ec2-vm",{"title":287,"path":739,"stem":740,"icon":290},"/runners/kubernetes","23.runners/5.kubernetes",{"title":742,"path":743,"stem":744,"icon":280},"Azure Container Apps","/runners/azure-container-apps","23.runners/6.azure-container-apps",{"title":746,"path":747,"stem":748,"icon":280},"Azure VMSS","/runners/azure-vmss","23.runners/7.azure-vmss",{"title":750,"path":751,"stem":752,"icon":280},"Azure VM","/runners/azure-vm","23.runners/8.azure-vm",{"title":754,"path":755,"stem":756,"icon":275},"GCE","/runners/gce","23.runners/9.gce",{"title":758,"path":759,"stem":760,"children":761,"icon":763},"Chat","/chat","24.chat/01.index",[762,764,768,773,777,782,787,791,796,800,805,810,814,819,824,828,832,836,840,845],{"title":758,"path":759,"stem":760,"icon":763},"i-lucide-messages-square",{"title":765,"path":766,"stem":767,"icon":446},"Enable and publish","/chat/enable-and-publish","24.chat/02.enable-and-publish",{"title":769,"path":770,"stem":771,"icon":772},"Theme and customization","/chat/theme-and-customization","24.chat/03.theme-and-customization","i-lucide-palette",{"title":774,"path":775,"stem":776,"icon":85},"Members and moderation","/chat/members-and-moderation","24.chat/04.members-and-moderation",{"title":778,"path":779,"stem":780,"icon":781},"Channels","/chat/channels","24.chat/05.channels","i-lucide-hash",{"title":783,"path":784,"stem":785,"icon":786},"Using the chat","/chat/using-the-chat","24.chat/06.using-the-chat","i-lucide-message-circle",{"title":788,"path":789,"stem":790,"icon":44},"Actors in chat","/chat/actors-in-chat","24.chat/07.actors-in-chat",{"title":792,"path":793,"stem":794,"icon":795},"Internal support actor","/chat/internal-support-actor","24.chat/08.internal-support-actor","i-lucide-life-buoy",{"title":797,"path":798,"stem":799,"icon":104},"API and console","/chat/api-and-console","24.chat/09.api-and-console",{"title":801,"path":802,"stem":803,"icon":804},"Limits","/chat/limits","24.chat/10.limits","i-lucide-triangle-alert",{"title":806,"path":807,"stem":808,"icon":809},"Structured chat with DGI","/chat/structured-chat","24.chat/11.structured-chat","i-lucide-layout-list",{"title":811,"path":812,"stem":813,"icon":109},"Option A: hosted chat with DGI","/chat/option-a-hosted-chat","24.chat/12.option-a-hosted-chat",{"title":815,"path":816,"stem":817,"icon":818},"Option B: embed the chat component","/chat/option-b-embed-component","24.chat/13.option-b-embed-component","i-lucide-component",{"title":820,"path":821,"stem":822,"icon":823},"Option C: custom client (wire contract)","/chat/option-c-custom-client","24.chat/14.option-c-custom-client","i-lucide-braces",{"title":825,"path":826,"stem":827,"icon":394},"Responder configuration reference","/chat/responder-reference","24.chat/15.responder-reference",{"title":829,"path":830,"stem":831,"icon":547},"Cards, live updates and proactive posts","/chat/cards-live-and-proactive","24.chat/16.cards-live-and-proactive",{"title":833,"path":834,"stem":835,"icon":16},"Structured chat security model","/chat/structured-chat-security","24.chat/17.structured-chat-security",{"title":837,"path":838,"stem":839,"icon":181},"Option D: any app or API (dgi.chat)","/chat/option-d-chat-api","24.chat/18.option-d-chat-api",{"title":841,"path":842,"stem":843,"icon":844},"Card catalog","/chat/card-catalog","24.chat/19.card-catalog","i-lucide-layout-grid",{"title":846,"path":847,"stem":848,"icon":849},"Living Surfaces","/chat/living-surfaces","24.chat/20.living-surfaces","i-lucide-sprout",{"title":851,"path":852,"stem":853,"children":854,"icon":61},"DGI","/dgi","25.dgi/1.index",[855,857,862,866,870,874],{"title":856,"path":852,"stem":853,"icon":61},"What is DGI",{"title":858,"path":859,"stem":860,"icon":861},"How DGI works","/dgi/how-it-works","25.dgi/2.how-it-works","i-lucide-cog",{"title":863,"path":864,"stem":865,"icon":844},"Interfaces","/dgi/interfaces","25.dgi/3.interfaces",{"title":867,"path":868,"stem":869,"icon":29},"Quickstart","/dgi/quickstart","25.dgi/4.quickstart",{"title":871,"path":872,"stem":873,"icon":16},"Trust and safety","/dgi/trust-and-safety","25.dgi/5.trust-and-safety",{"title":875,"path":876,"stem":877,"icon":878},"FAQ","/dgi/faq","25.dgi/6.faq","i-lucide-circle-help",{"id":880,"title":205,"body":881,"description":2220,"extension":2221,"links":2222,"meta":2223,"navigation":2224,"path":206,"seo":2225,"stem":207,"__hash__":2226},"docs/06.advanced/4.governance-and-approvals.md",{"type":882,"value":883,"toc":2206},"minimark",[884,905,919,950,955,965,971,993,1017,1021,1042,1105,1110,1120,1235,1241,1278,1362,1366,1369,1506,1517,1529,1533,1544,1551,1555,1570,1586,1590,1593,1625,1629,1632,1722,1737,1741,1752,1766,1837,1856,1877,1996,2023,2027,2030,2132,2162,2173,2177,2202],[885,886,887,888,892,893,896,897,900,901,904],"p",{},"Autonomy is the point of an AI workforce — and the risk. An agent that can discover capabilities over ",[889,890,891],"a",{"href":170},"MCP",", read ",[889,894,895],{"href":237},"connections",", and ",[889,898,899],{"href":54},"start workflows"," in your cloud has real reach. ",[902,903,599],"strong",{}," is the layer that turns that reach into something you can trust in production: every action is constrained by role-based authority, sensitive actions stop at a human-in-the-loop gate, and every authorize/deny/run is recorded in an evidence trail you can query and export.",[885,906,907,908,912,913,915,916,918],{},"This page is the deep dive on ",[909,910,911],"em",{},"how"," those controls actually work. For the conceptual overview, start with ",[889,914,63],{"href":64},"; to operate the controls day-to-day, see ",[889,917,572],{"href":573},".",[920,921,922],"note",{},[885,923,924,925,928,929,933,934,937,938,941,942,945,946,949],{},"Staff governance is in ",[902,926,927],{},"beta",". RBAC enforcement (",[930,931,932],"code",{},"RbacGuard",") and the engine transition log are live; the ",[930,935,936],{},"audit.*"," query library is active; the approval-gate UX and the ",[930,939,940],{},"security.*"," assessment library are still maturing. Items below tagged ",[902,943,944],{},"(beta)"," or ",[902,947,948],{},"(roadmap)"," are expected to change.",[951,952,954],"h2",{"id":953},"the-governance-invariant-one-enforcement-point","The governance invariant: one enforcement point",[885,956,957,958,961,962],{},"Most authorization bugs come from ",[909,959,960],{},"drift"," — the same role check re-implemented across REST routes, MCP tools, async consumers, and SDKs, where one of them inevitably forgets a guard. Orkestia eliminates that class of bug by design: ",[902,963,964],{},"every staff-side operation is a workflow, and authority is enforced at exactly one place — inside the workflow engine.",[966,967],"dag-diagram",{":edges":968,":nodes":969,"direction":970},"[{\"from\":\"UI\",\"to\":\"ENG\"},{\"from\":\"MCP\",\"to\":\"ENG\"},{\"from\":\"REST\",\"to\":\"ENG\"},{\"from\":\"KAFKA\",\"to\":\"ENG\"},{\"from\":\"ENG\",\"to\":\"AUTH\"},{\"from\":\"AUTH\",\"to\":\"RBAC\"},{\"from\":\"RBAC\",\"to\":\"WF\",\"label\":\"authorize\"},{\"from\":\"RBAC\",\"to\":\"STOP\",\"label\":\"deny\"},{\"from\":\"RBAC\",\"to\":\"LOG\",\"label\":\"emits\",\"dashed\":true},{\"from\":\"WF\",\"to\":\"LOG\",\"label\":\"emits\",\"dashed\":true}]","[{\"id\":\"UI\",\"label\":\"Staff console\",\"kind\":\"start\"},{\"id\":\"MCP\",\"label\":\"AI agent / MCP\",\"kind\":\"ai\"},{\"id\":\"REST\",\"label\":\"REST / SDK\",\"kind\":\"start\"},{\"id\":\"KAFKA\",\"label\":\"Kafka consumer\",\"kind\":\"data\"},{\"id\":\"ENG\",\"label\":\"engine.start_workflow\",\"kind\":\"engine\"},{\"id\":\"AUTH\",\"label\":\"Auth middleware\",\"kind\":\"engine\"},{\"id\":\"RBAC\",\"label\":\"RbacGuard middleware\",\"kind\":\"engine\"},{\"id\":\"WF\",\"label\":\"Workflow first transition\",\"kind\":\"engine\"},{\"id\":\"STOP\",\"label\":\"Stop + audit_event\",\"kind\":\"terminal\"},{\"id\":\"LOG\",\"label\":\"Transition log + audit_event\",\"kind\":\"data\"}]","LR",[885,972,973,974,977,978,981,982,985,986,988,989,992],{},"Because the Staff console, an MCP agent, a REST/SDK caller, and the async consumer ",[902,975,976],{},"all"," invoke work through ",[930,979,980],{},"engine.start_workflow()"," / ",[930,983,984],{},"engine.transition()",", they all pass through the same ",[930,987,932],{},". There are no ",[930,990,991],{},"@requires_role"," decorators sprinkled across route handlers to forget. Subverting authority requires editing the private workflow-engine core — not a single endpoint.",[994,995,996],"tip",{},[885,997,998,999,1004,1005,1008,1009,1012,1013,1016],{},"This builds directly on Orkestia's ",[902,1000,1001],{},[889,1002,1003],{"href":47},"Zero Trust / Zero Code Custody"," posture. Execution happens in ",[909,1006,1007],{},"your"," cloud via ",[889,1010,1011],{"href":73},"runners","; the engine orchestrates and records ",[902,1014,1015],{},"state",". Governance is enforced at the orchestration layer, so guardrails hold regardless of where the work physically runs.",[951,1018,1020],{"id":1019},"role-based-authority","Role-based authority",[885,1022,1023,1024,1027,1028,1027,1031,1027,1034,1037,1038,1041],{},"Authority is modeled as a real organization. The core entities — ",[930,1025,1026],{},"OrgUnit",", ",[930,1029,1030],{},"Actor",[930,1032,1033],{},"RoleBinding",[930,1035,1036],{},"Capability"," — are first-class platform models, managed exclusively through ",[930,1039,1040],{},"staff.*"," workflows.",[1043,1044,1045,1058],"table",{},[1046,1047,1048],"thead",{},[1049,1050,1051,1055],"tr",{},[1052,1053,1054],"th",{},"Entity",[1052,1056,1057],{},"What it is",[1059,1060,1061,1071,1080,1093],"tbody",{},[1049,1062,1063,1068],{},[1064,1065,1066],"td",{},[902,1067,1026],{},[1064,1069,1070],{},"A team/department node. Units form a tree and are the natural scope for permissions and oversight.",[1049,1072,1073,1077],{},[1064,1074,1075],{},[902,1076,1030],{},[1064,1078,1079],{},"A principal — a human operator or an AI worker — with a lifecycle (invite/hire, suspend, resume, remove) and its own inbox/outbox/journal.",[1049,1081,1082,1086],{},[1064,1083,1084],{},[902,1085,1033],{},[1064,1087,1088,1089,1092],{},"Binds a role to an actor ",[909,1090,1091],{},"at a unit",". Effective authority is resolved by walking the unit tree.",[1049,1094,1095,1099],{},[1064,1096,1097],{},[902,1098,1036],{},[1064,1100,1101,1102,1104],{},"The unit of authority. Each workflow class declares ",[930,1103,1036],{}," metadata; RBAC checks the caller's effective role against it.",[1106,1107,1109],"h3",{"id":1108},"how-a-decision-is-made","How a decision is made",[885,1111,1112,1113,1115,1116,1119],{},"Each ",[930,1114,1040],{}," workflow declares its authority requirement in its definition — for example, the ",[930,1117,1118],{},"staff.grant-role-binding"," workflow carries metadata of this shape:",[1121,1122,1127],"pre",{"className":1123,"code":1124,"language":1125,"meta":1126,"style":1126},"language-json shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","{\n  \"workflow_type\": \"staff.grant-role-binding\",\n  \"capability\": {\n    \"min_role\": \"ADMIN\",\n    \"scope\": \"unit\"\n  }\n}\n","json","",[930,1128,1129,1138,1165,1180,1203,1223,1229],{"__ignoreMap":1126},[1130,1131,1134],"span",{"class":1132,"line":1133},"line",1,[1130,1135,1137],{"class":1136},"sMK4o","{\n",[1130,1139,1141,1144,1148,1151,1154,1157,1160,1162],{"class":1132,"line":1140},2,[1130,1142,1143],{"class":1136},"  \"",[1130,1145,1147],{"class":1146},"spNyl","workflow_type",[1130,1149,1150],{"class":1136},"\"",[1130,1152,1153],{"class":1136},":",[1130,1155,1156],{"class":1136}," \"",[1130,1158,1118],{"class":1159},"sfazB",[1130,1161,1150],{"class":1136},[1130,1163,1164],{"class":1136},",\n",[1130,1166,1168,1170,1173,1175,1177],{"class":1132,"line":1167},3,[1130,1169,1143],{"class":1136},[1130,1171,1172],{"class":1146},"capability",[1130,1174,1150],{"class":1136},[1130,1176,1153],{"class":1136},[1130,1178,1179],{"class":1136}," {\n",[1130,1181,1183,1186,1190,1192,1194,1196,1199,1201],{"class":1132,"line":1182},4,[1130,1184,1185],{"class":1136},"    \"",[1130,1187,1189],{"class":1188},"sBMFI","min_role",[1130,1191,1150],{"class":1136},[1130,1193,1153],{"class":1136},[1130,1195,1156],{"class":1136},[1130,1197,1198],{"class":1159},"ADMIN",[1130,1200,1150],{"class":1136},[1130,1202,1164],{"class":1136},[1130,1204,1206,1208,1211,1213,1215,1217,1220],{"class":1132,"line":1205},5,[1130,1207,1185],{"class":1136},[1130,1209,1210],{"class":1188},"scope",[1130,1212,1150],{"class":1136},[1130,1214,1153],{"class":1136},[1130,1216,1156],{"class":1136},[1130,1218,1219],{"class":1159},"unit",[1130,1221,1222],{"class":1136},"\"\n",[1130,1224,1226],{"class":1132,"line":1225},6,[1130,1227,1228],{"class":1136},"  }\n",[1130,1230,1232],{"class":1132,"line":1231},7,[1130,1233,1234],{"class":1136},"}\n",[885,1236,1237,1238,1240],{},"At run time, ",[930,1239,932],{}," runs after auth and before the workflow's first transition. It:",[1242,1243,1244,1251,1261,1267],"ol",{},[1245,1246,1247,1248,918],"li",{},"Reads ",[930,1249,1250],{},"workflow_cls.capability",[1245,1252,1253,1254,1257,1258,1260],{},"Resolves the caller's effective role on the targeted unit via ",[930,1255,1256],{},"resolve_effective_role(actor, unit)",", which walks the ",[930,1259,1026],{}," tree (a binding higher in the tree inherits downward).",[1245,1262,1263,1264,918],{},"Compares the effective role against ",[930,1265,1266],{},"Capability.min_role",[1245,1268,1269,1270,1273,1274,1277],{},"Emits an ",[930,1271,1272],{},"audit_event"," row for ",[902,1275,1276],{},"both"," authorize and deny outcomes, then either proceeds or stops.",[1121,1279,1283],{"className":1280,"code":1281,"language":1282,"meta":1126,"style":1126},"language-mermaid shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","sequenceDiagram\n  participant C as Caller (UI / agent / SDK)\n  participant E as Workflow engine\n  participant G as RbacGuard\n  participant D as OrgUnit tree\n  participant L as audit_event\n  C->>E: start_workflow(\"staff.grant-role-binding\", {unit_id, ...})\n  E->>G: before first transition\n  G->>D: resolve_effective_role(actor, unit)\n  D-->>G: OrgRole.ADMIN\n  G->>G: ADMIN >= capability.min_role? yes\n  G->>L: write audit_event (outcome=authorize)\n  G-->>E: proceed\n  Note over C,L: a denied call writes audit_event (outcome=deny) and stops\n","mermaid",[930,1284,1285,1290,1295,1300,1305,1310,1315,1320,1326,1332,1338,1344,1350,1356],{"__ignoreMap":1126},[1130,1286,1287],{"class":1132,"line":1133},[1130,1288,1289],{},"sequenceDiagram\n",[1130,1291,1292],{"class":1132,"line":1140},[1130,1293,1294],{},"  participant C as Caller (UI / agent / SDK)\n",[1130,1296,1297],{"class":1132,"line":1167},[1130,1298,1299],{},"  participant E as Workflow engine\n",[1130,1301,1302],{"class":1132,"line":1182},[1130,1303,1304],{},"  participant G as RbacGuard\n",[1130,1306,1307],{"class":1132,"line":1205},[1130,1308,1309],{},"  participant D as OrgUnit tree\n",[1130,1311,1312],{"class":1132,"line":1225},[1130,1313,1314],{},"  participant L as audit_event\n",[1130,1316,1317],{"class":1132,"line":1231},[1130,1318,1319],{},"  C->>E: start_workflow(\"staff.grant-role-binding\", {unit_id, ...})\n",[1130,1321,1323],{"class":1132,"line":1322},8,[1130,1324,1325],{},"  E->>G: before first transition\n",[1130,1327,1329],{"class":1132,"line":1328},9,[1130,1330,1331],{},"  G->>D: resolve_effective_role(actor, unit)\n",[1130,1333,1335],{"class":1132,"line":1334},10,[1130,1336,1337],{},"  D-->>G: OrgRole.ADMIN\n",[1130,1339,1341],{"class":1132,"line":1340},11,[1130,1342,1343],{},"  G->>G: ADMIN >= capability.min_role? yes\n",[1130,1345,1347],{"class":1132,"line":1346},12,[1130,1348,1349],{},"  G->>L: write audit_event (outcome=authorize)\n",[1130,1351,1353],{"class":1132,"line":1352},13,[1130,1354,1355],{},"  G-->>E: proceed\n",[1130,1357,1359],{"class":1132,"line":1358},14,[1130,1360,1361],{},"  Note over C,L: a denied call writes audit_event (outcome=deny) and stops\n",[1106,1363,1365],{"id":1364},"the-roles-matrix","The roles matrix",[885,1367,1368],{},"Five roles compose additively; an effective role on a unit grants the union of capabilities at that unit's scope and inherits down the tree.",[1043,1370,1371,1393],{},[1046,1372,1373],{},[1049,1374,1375,1378,1382,1384,1387,1390],{},[1052,1376,1377],{},"Surface",[1052,1379,1381],{"align":1380},"center","OWNER",[1052,1383,1198],{"align":1380},[1052,1385,1386],{"align":1380},"OPERATOR",[1052,1388,1389],{"align":1380},"VIEWER",[1052,1391,1392],{"align":1380},"AUDITOR",[1059,1394,1395,1413,1428,1443,1458,1476,1491],{},[1049,1396,1397,1400,1403,1406,1409,1411],{},[1064,1398,1399],{},"Org-wide settings (billing, SSO, plan)",[1064,1401,1402],{"align":1380},"RW",[1064,1404,1405],{"align":1380},"R",[1064,1407,1408],{"align":1380},"—",[1064,1410,1408],{"align":1380},[1064,1412,1405],{"align":1380},[1049,1414,1415,1418,1420,1422,1424,1426],{},[1064,1416,1417],{},"Unit tree (create / move / delete)",[1064,1419,1402],{"align":1380},[1064,1421,1402],{"align":1380},[1064,1423,1408],{"align":1380},[1064,1425,1405],{"align":1380},[1064,1427,1405],{"align":1380},[1049,1429,1430,1433,1435,1437,1439,1441],{},[1064,1431,1432],{},"Actor lifecycle (invite / suspend / remove)",[1064,1434,1402],{"align":1380},[1064,1436,1402],{"align":1380},[1064,1438,1408],{"align":1380},[1064,1440,1405],{"align":1380},[1064,1442,1405],{"align":1380},[1049,1444,1445,1448,1450,1452,1454,1456],{},[1064,1446,1447],{},"Role bindings (grant / revoke)",[1064,1449,1402],{"align":1380},[1064,1451,1402],{"align":1380},[1064,1453,1408],{"align":1380},[1064,1455,1408],{"align":1380},[1064,1457,1405],{"align":1380},[1049,1459,1460,1466,1468,1470,1472,1474],{},[1064,1461,1462,1463,1465],{},"Staff workflow execution (run ",[930,1464,1040],{}," on bound unit)",[1064,1467,1402],{"align":1380},[1064,1469,1402],{"align":1380},[1064,1471,1402],{"align":1380},[1064,1473,1405],{"align":1380},[1064,1475,1405],{"align":1380},[1049,1477,1478,1481,1483,1485,1487,1489],{},[1064,1479,1480],{},"Audit log read",[1064,1482,1405],{"align":1380},[1064,1484,1405],{"align":1380},[1064,1486,1405],{"align":1380},[1064,1488,1408],{"align":1380},[1064,1490,1402],{"align":1380},[1049,1492,1493,1496,1498,1500,1502,1504],{},[1064,1494,1495],{},"Audit log export",[1064,1497,1402],{"align":1380},[1064,1499,1402],{"align":1380},[1064,1501,1408],{"align":1380},[1064,1503,1408],{"align":1380},[1064,1505,1402],{"align":1380},[920,1507,1508],{},[885,1509,1510,1513,1514,1516],{},[902,1511,1512],{},"Many OWNERs per org"," is allowed by design. ",[902,1515,1392],{}," is deliberately read-only-plus-export: full historical visibility and the ability to pull evidence, but no mutation authority — the right shape for a compliance reviewer who must observe everything and change nothing.",[885,1518,1519,1520,1522,1523,1525,1526,918],{},"Scope-bound delegation is the headline capability this unlocks: grant a contractor ",[930,1521,1386],{}," on a single unit for a fixed window without handing over the rest of the org. See the operator procedure in ",[889,1524,572],{"href":573}," and the per-workflow authority requirements in the ",[889,1527,1528],{"href":165},"Workflow Types Registry",[951,1530,1532],{"id":1531},"human-in-the-loop-approval-gates","Human-in-the-loop approval gates",[885,1534,1535,1536,1539,1540,1543],{},"RBAC answers ",[909,1537,1538],{},"\"is this actor allowed to attempt this?\""," Approval gates answer the next question — ",[909,1541,1542],{},"\"should this specific attempt proceed right now?\""," — by interposing a human decision before a sensitive action takes effect.",[885,1545,1546,1547,1550],{},"Because every action is a workflow and the engine is event-sourced, a gate is a natural workflow state: the run reaches a ",[902,1548,1549],{},"pending-approval"," transition and parks there until an authorized human approves or declines. Nothing downstream executes while the run waits, and the wait itself is durable — it survives pod restarts and HPA scale events because the engine persists state, not in-memory sessions.",[966,1552],{":edges":1553,":nodes":1554},"[{\"from\":\"start\",\"to\":\"proposed\",\"label\":\"agent proposes action\"},{\"from\":\"proposed\",\"to\":\"pending_approval\",\"label\":\"sensitive capability gated\"},{\"from\":\"pending_approval\",\"to\":\"approved\",\"label\":\"human approves\"},{\"from\":\"pending_approval\",\"to\":\"declined\",\"label\":\"human declines\"},{\"from\":\"approved\",\"to\":\"executing\"},{\"from\":\"executing\",\"to\":\"completed\"},{\"from\":\"declined\",\"to\":\"rejected\"},{\"from\":\"completed\",\"to\":\"done\"},{\"from\":\"rejected\",\"to\":\"done\"}]","[{\"id\":\"start\",\"label\":\"Start\",\"kind\":\"start\"},{\"id\":\"proposed\",\"label\":\"Proposed\"},{\"id\":\"pending_approval\",\"label\":\"Pending Approval\"},{\"id\":\"approved\",\"label\":\"Approved\"},{\"id\":\"declined\",\"label\":\"Declined\"},{\"id\":\"executing\",\"label\":\"Executing\"},{\"id\":\"completed\",\"label\":\"Completed\",\"kind\":\"terminal\"},{\"id\":\"rejected\",\"label\":\"Rejected\",\"kind\":\"failed\"},{\"id\":\"done\",\"label\":\"End\",\"kind\":\"terminal\"}]",[885,1556,1557,1558,1561,1562,1565,1566,1569],{},"When an AI agent proposes an action that is declined at the gate, that outcome is first-class: the agent invocation is sealed with ",[930,1559,1560],{},"status='rejected'"," (distinct from a runtime ",[930,1563,1564],{},"failed","), so \"the agent wanted to do X and a human said no\" is a queryable fact, not a log line. See ",[889,1567,1568],{"href":47},"agent actuation"," for how proposals flow from the agent runtime into gated workflows.",[920,1571,1572],{},[885,1573,1574,1575,1578,1579,1582,1583,918],{},"The approval-gate ",[902,1576,1577],{},"UX"," (where approvers see pending items, notifications, batching) is being normalized in the Staff cockpit. The underlying mechanism — durable pending states in the engine and the ",[930,1580,1581],{},"rejected"," outcome — is live. Treat the exact gate-configuration surface as subject to change and confirm per-workflow gating in the ",[889,1584,1585],{"href":165},"registry",[1106,1587,1589],{"id":1588},"where-gates-fit-relative-to-guardrails","Where gates fit relative to guardrails",[885,1591,1592],{},"Think of the controls as a defense-in-depth stack — a request must clear every layer:",[1594,1595,1596,1603,1611,1618],"card-group",{},[1597,1598,1600],"card",{"icon":376,"title":1599,"to":83},"1. Tenant isolation",[885,1601,1602],{},"Org scoping is resolved server-side from the caller's token; an actor can never see or act on another org's state.",[1597,1604,1606],{"icon":417,"title":1605,"to":64},"2. RBAC authority",[885,1607,1608,1610],{},[930,1609,932],{}," denies any capability the actor's effective role doesn't grant — before the first transition runs.",[1597,1612,1615],{"icon":1613,"title":1614,"to":573},"i-lucide-hand","3. Approval gate",[885,1616,1617],{},"Sensitive actions park in a durable pending state until an authorized human approves or declines.",[1597,1619,1622],{"icon":1620,"title":1621,"to":64},"i-lucide-file-check","4. Evidence trail",[885,1623,1624],{},"Every authorize, deny, run, and rejection is recorded and queryable for after-the-fact accountability.",[951,1626,1628],{"id":1627},"guardrails-on-autonomous-ai-actions","Guardrails on autonomous AI actions",[885,1630,1631],{},"The same machinery that governs human operators constrains AI agents — but agents get extra guardrails because they act at machine speed and scale.",[1633,1634,1635,1651,1663,1693,1702],"ul",{},[1245,1636,1637,1640,1641,1643,1644,1647,1648,1650],{},[902,1638,1639],{},"Capability-scoped reach."," An agent acts as an ",[930,1642,1030],{}," with role bindings. A \"finance agent\" bound only to the Finance unit with ",[930,1645,1646],{},"finance-operator"," cannot touch infrastructure workflows; ",[930,1649,932],{}," denies the attempt and records it. This is how you keep authority from sprawling as you add agents.",[1245,1652,1653,1656,1657,1659,1660,918],{},[902,1654,1655],{},"Discovery is gated too."," Agents discover capabilities over ",[889,1658,891],{"href":170},", but discovery and invocation both resolve org and authority server-side from the token — an agent cannot widen its own scope by passing a different ",[930,1661,1662],{},"organization_uuid",[1245,1664,1665,1668,1669,1672,1673,1676,1677,981,1680,981,1682,1684,1685,1688,1689,1692],{},[902,1666,1667],{},"Hashed invocation audit."," Every agent run writes one ",[930,1670,1671],{},"agent_invocation"," row (",[930,1674,1675],{},"running"," → ",[930,1678,1679],{},"success",[930,1681,1564],{},[930,1683,1581],{},"). Tool arguments, results, and prompts are stored as ",[902,1686,1687],{},"SHA-256 hashes of canonical JSON, never literals"," — so the trail is safe to expose to operators and auditors while still supporting correlation (\"all runs that called ",[930,1690,1691],{},"start_workflow"," with the same arg shape\"). The agent's own final message and error reasons are kept verbatim because those are the artifacts humans review.",[1245,1694,1695,1698,1699,1701],{},[902,1696,1697],{},"Crash detection."," A run that vanishes mid-flight (pod killed, OOM) leaves its row stuck in ",[930,1700,1675],{}," — a code-detectable signal that an agent crashed without a clean exit, surfaced rather than silently dropped.",[1245,1703,1704,1707,1708,1710,1711,1714,1715,1718,1719,918],{},[902,1705,1706],{},"Deterministic compilation."," When AI (",[889,1709,851],{"href":59},") ",[909,1712,1713],{},"designs"," a workflow, the result compiles into a deterministic ",[889,1716,1717],{"href":129},"virtual workflow",". Review and govern the compiled composition, not an opaque model decision at execution time — see the ",[889,1720,1721],{"href":196},"hybrid execution model",[994,1723,1724],{},[885,1725,1726,1727,1730,1731,1733,1734,1736],{},"Authority for AI agents is ",[902,1728,1729],{},"declarative and grep-able",": a workflow's ",[930,1732,1036],{}," lives on the class, and an actor's reach is the union of its ",[930,1735,1033],{}," rows. You can answer \"what can this agent do?\" by reading data, not by reasoning about prompts.",[951,1738,1740],{"id":1739},"the-audit-evidence-trail","The audit & evidence trail",[885,1742,1743,1744,1747,1748,1751],{},"Accountability rests on the engine's ",[902,1745,1746],{},"event-sourced transition log",": every workflow run is an append-only sequence of transitions. Nothing mutates that history; the governance value is that \"what ran, when, on whose behalf, and what came of it\" is ",[909,1749,1750],{},"already"," recorded as a side effect of how the engine works.",[885,1753,1754,1755,1758,1759,1761,1762,1765],{},"The ",[902,1756,1757],{},"Audit"," library (",[930,1760,936],{},") exposes that log as a typed, ",[902,1763,1764],{},"read-only, org-scoped"," query surface — so callers ask questions without writing raw SQL against engine internals or risking a mutation.",[1043,1767,1768,1781],{},[1046,1769,1770],{},[1049,1771,1772,1775,1778],{},[1052,1773,1774],{},"Workflow",[1052,1776,1777],{},"Kind",[1052,1779,1780],{},"What it answers",[1059,1782,1783,1796,1808,1824],{},[1049,1784,1785,1790,1793],{},[1064,1786,1787],{},[930,1788,1789],{},"audit.workflow-run.query",[1064,1791,1792],{},"data (read-only)",[1064,1794,1795],{},"Paginated runs for the org, filterable by type prefix, state, terminal status, actor, time range",[1049,1797,1798,1803,1805],{},[1064,1799,1800],{},[930,1801,1802],{},"audit.workflow-run.get-history",[1064,1804,1792],{},[1064,1806,1807],{},"Full transition log for one run, after verifying it belongs to the caller's org",[1049,1809,1810,1815,1817],{},[1064,1811,1812],{},[930,1813,1814],{},"audit.workflow-run.aggregate",[1064,1816,1792],{},[1064,1818,1819,1820,1823],{},"Per-type counts and ",[930,1821,1822],{},"last_started_at"," over a time range",[1049,1825,1826,1831,1834],{},[1064,1827,1828],{},[930,1829,1830],{},"audit.workflow-health.scan",[1064,1832,1833],{},"workflow",[1064,1835,1836],{},"Surfaces unhealthy / stuck runs",[885,1838,1839,1840,1843,1844,1847,1848,1851,1852,1855],{},"An ",[902,1841,1842],{},"evidence pack"," is composed from these read-only queries — ",[930,1845,1846],{},"query"," for the run list, ",[930,1849,1850],{},"get-history"," per run, ",[930,1853,1854],{},"aggregate"," for totals — over the time range and prefixes under review.",[885,1857,1858,1859,1862,1863,1866,1867,1870,1871,918],{},"Grouping is ",[902,1860,1861],{},"prefix-composed",": callers pass their own ",[930,1864,1865],{},"workflow_type_prefixes"," (e.g. ",[930,1868,1869],{},"['kubernetes.', 'deploy.k8s.', 'runner.']",") so \"all Kubernetes activity\" works without hard-coding filters into the engine. Confirm exact inputs and outputs against the ",[889,1872,1876],{"href":1873,"rel":1874},"https://reference.orkestia.dev",[1875],"nofollow","external catalog",[1121,1878,1880],{"className":1123,"code":1879,"language":1125,"meta":1126,"style":1126},"{\n  \"workflow_type\": \"audit.workflow-run.query\",\n  \"initial_data\": {\n    \"workflow_type_prefixes\": [\"staff.\", \"kubernetes.\"],\n    \"started_after\": \"2026-06-01T00:00:00Z\",\n    \"started_before\": \"2026-06-30T23:59:59Z\"\n  }\n}\n",[930,1881,1882,1886,1904,1917,1950,1970,1988,1992],{"__ignoreMap":1126},[1130,1883,1884],{"class":1132,"line":1133},[1130,1885,1137],{"class":1136},[1130,1887,1888,1890,1892,1894,1896,1898,1900,1902],{"class":1132,"line":1140},[1130,1889,1143],{"class":1136},[1130,1891,1147],{"class":1146},[1130,1893,1150],{"class":1136},[1130,1895,1153],{"class":1136},[1130,1897,1156],{"class":1136},[1130,1899,1789],{"class":1159},[1130,1901,1150],{"class":1136},[1130,1903,1164],{"class":1136},[1130,1905,1906,1908,1911,1913,1915],{"class":1132,"line":1167},[1130,1907,1143],{"class":1136},[1130,1909,1910],{"class":1146},"initial_data",[1130,1912,1150],{"class":1136},[1130,1914,1153],{"class":1136},[1130,1916,1179],{"class":1136},[1130,1918,1919,1921,1923,1925,1927,1930,1932,1935,1937,1940,1942,1945,1947],{"class":1132,"line":1182},[1130,1920,1185],{"class":1136},[1130,1922,1865],{"class":1188},[1130,1924,1150],{"class":1136},[1130,1926,1153],{"class":1136},[1130,1928,1929],{"class":1136}," [",[1130,1931,1150],{"class":1136},[1130,1933,1934],{"class":1159},"staff.",[1130,1936,1150],{"class":1136},[1130,1938,1939],{"class":1136},",",[1130,1941,1156],{"class":1136},[1130,1943,1944],{"class":1159},"kubernetes.",[1130,1946,1150],{"class":1136},[1130,1948,1949],{"class":1136},"],\n",[1130,1951,1952,1954,1957,1959,1961,1963,1966,1968],{"class":1132,"line":1205},[1130,1953,1185],{"class":1136},[1130,1955,1956],{"class":1188},"started_after",[1130,1958,1150],{"class":1136},[1130,1960,1153],{"class":1136},[1130,1962,1156],{"class":1136},[1130,1964,1965],{"class":1159},"2026-06-01T00:00:00Z",[1130,1967,1150],{"class":1136},[1130,1969,1164],{"class":1136},[1130,1971,1972,1974,1977,1979,1981,1983,1986],{"class":1132,"line":1225},[1130,1973,1185],{"class":1136},[1130,1975,1976],{"class":1188},"started_before",[1130,1978,1150],{"class":1136},[1130,1980,1153],{"class":1136},[1130,1982,1156],{"class":1136},[1130,1984,1985],{"class":1159},"2026-06-30T23:59:59Z",[1130,1987,1222],{"class":1136},[1130,1989,1990],{"class":1132,"line":1231},[1130,1991,1228],{"class":1136},[1130,1993,1994],{"class":1132,"line":1322},[1130,1995,1234],{"class":1136},[920,1997,1998],{},[885,1999,2000,2001,2004,2005,2008,2009,2011,2012,2014,2015,2019,2020,2022],{},"There are ",[902,2002,2003],{},"two complementary trails",". The engine ",[902,2006,2007],{},"transition log"," (queried via ",[930,2010,936],{},") is the system of record for workflow runs and ",[930,2013,932],{}," authorize/deny events. The ",[902,2016,2017],{},[930,2018,1671],{}," table is the per-run record for AI agent executions (hashed args/results, ",[930,2021,1581],{}," outcomes). Together they answer both \"what did the platform do for this org?\" and \"what did each agent attempt?\".",[951,2024,2026],{"id":2025},"tie-to-compliance","Tie to compliance",[885,2028,2029],{},"The governance model maps cleanly onto common compliance controls:",[1043,2031,2032,2042],{},[1046,2033,2034],{},[1049,2035,2036,2039],{},[1052,2037,2038],{},"Control objective",[1052,2040,2041],{},"How Orkestia satisfies it",[1059,2043,2044,2057,2071,2083,2099,2112,2122],{},[1049,2045,2046,2051],{},[1064,2047,2048],{},[902,2049,2050],{},"Least privilege",[1064,2052,2053,2054,2056],{},"Role bindings scoped to units; ",[930,2055,932],{}," denies anything not explicitly granted",[1049,2058,2059,2064],{},[1064,2060,2061],{},[902,2062,2063],{},"Separation of duties",[1064,2065,2066,2067,2070],{},"Distinct roles (e.g. OPERATOR runs, AUDITOR reviews); approval gates require a ",[909,2068,2069],{},"different"," human to approve",[1049,2072,2073,2078],{},[1064,2074,2075],{},[902,2076,2077],{},"Change approval",[1064,2079,2080,2081],{},"Human-in-the-loop gates on sensitive workflows; declines recorded as ",[930,2082,1581],{},[1049,2084,2085,2090],{},[1064,2086,2087],{},[902,2088,2089],{},"Audit logging",[1064,2091,2092,2093,2096,2097],{},"Append-only transition log; authorize ",[909,2094,2095],{},"and"," deny both written to ",[930,2098,1272],{},[1049,2100,2101,2106],{},[1064,2102,2103],{},[902,2104,2105],{},"Evidence on demand",[1064,2107,2108,2109,2111],{},"Evidence packs composed from the read-only ",[930,2110,936],{}," queries — time-range / prefix-scoped artifacts for reviewers",[1049,2113,2114,2119],{},[1064,2115,2116],{},[902,2117,2118],{},"Data minimization",[1064,2120,2121],{},"Agent audit stores hashes, not literals; Zero Code Custody means customer code/data never leaves your cloud",[1049,2123,2124,2129],{},[1064,2125,2126],{},[902,2127,2128],{},"Tenant isolation",[1064,2130,2131],{},"Org scope resolved server-side from the token; every audit query re-verifies org ownership",[920,2133,2134],{},[885,2135,1754,2136,2138,2139,2142,2143,2146,2147,2150,2151,2154,2155,2158,2159,918],{},[930,2137,940],{}," library now carries ",[902,2140,2141],{},"org-level workflow policy"," controls (",[930,2144,2145],{},"security.org-workflow-policy.*",") — org-wide rules over which workflow surfaces may run — and the policy layer adds feature flags and entitlements (",[930,2148,2149],{},"policy.*",") enforced at the invoke gate. The broader security-",[909,2152,2153],{},"assessment"," surface (assessment campaigns, posture collection, findings triage) remains ",[902,2156,2157],{},"roadmap","; see the ",[889,2160,2161],{"href":139},"security and compliance guide",[885,2163,2164,2165,2168,2169,2172],{},"Orkestia provides the ",[909,2166,2167],{},"mechanisms"," (enforcement, gates, immutable trail) that make a control environment auditable; it does not by itself constitute a certification. Map these controls to your own framework with your auditor, and see ",[889,2170,2171],{"href":223},"deployment models"," for how the posture differs across hosting topologies.",[951,2174,2176],{"id":2175},"where-to-go-next","Where to go next",[1594,2178,2179,2185,2190,2196],{},[1597,2180,2182],{"icon":66,"title":2181,"to":64},"Staff governance concept",[885,2183,2184],{},"The org model, roles, and why fleets of agents need governance.",[1597,2186,2187],{"icon":34,"title":572,"to":573},[885,2188,2189],{},"Grant and revoke bindings, work the inbox, and act on pending approvals.",[1597,2191,2193],{"icon":80,"title":2192,"to":459},"Observe with Lumen",[885,2194,2195],{},"Correlate audit events with live run health and failures.",[1597,2197,2199],{"icon":16,"title":2198,"to":139},"Security & compliance",[885,2200,2201],{},"The broader privacy and compliance posture, including Zero Code Custody.",[2203,2204,2205],"style",{},"html pre.shiki code .sMK4o, html code.shiki .sMK4o{--shiki-light:#39ADB5;--shiki-default:#89DDFF;--shiki-dark:#89DDFF}html pre.shiki code .spNyl, html code.shiki .spNyl{--shiki-light:#9C3EDA;--shiki-default:#C792EA;--shiki-dark:#C792EA}html pre.shiki code .sfazB, html code.shiki .sfazB{--shiki-light:#91B859;--shiki-default:#C3E88D;--shiki-dark:#C3E88D}html pre.shiki code .sBMFI, html code.shiki .sBMFI{--shiki-light:#E2931D;--shiki-default:#FFCB6B;--shiki-dark:#FFCB6B}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":1126,"searchDepth":1133,"depth":1140,"links":2207},[2208,2209,2213,2216,2217,2218,2219],{"id":953,"depth":1140,"text":954},{"id":1019,"depth":1140,"text":1020,"children":2210},[2211,2212],{"id":1108,"depth":1167,"text":1109},{"id":1364,"depth":1167,"text":1365},{"id":1531,"depth":1140,"text":1532,"children":2214},[2215],{"id":1588,"depth":1167,"text":1589},{"id":1627,"depth":1140,"text":1628},{"id":1739,"depth":1140,"text":1740},{"id":2025,"depth":1140,"text":2026},{"id":2175,"depth":1140,"text":2176},"How Orkestia enforces role-based authority, human-in-the-loop approval gates, and an immutable evidence trail over fleets of autonomous AI agents","md",null,{},{"icon":208},{"title":205,"description":2220},"aLH3VgTljKViMB4epqa8fwbccNa5iU7ObmWx6HyfmdY",[2228,2230],{"title":200,"path":201,"stem":202,"description":2229,"icon":203,"children":-1},"How Orkestia reconciles desired and actual state for runners and network infrastructure in your cloud, computes readiness verdicts, and decides what to heal automatically versus surface for approval",{"title":210,"path":211,"stem":212,"description":2231,"icon":213,"children":-1},"How to keep Orkestia workflows fast and cheap by compiling AI-designed flows to deterministic compositions, right-sizing runners, scaling async over Kafka, and using Lumen to find the expensive steps",1790354045847]