[{"data":1,"prerenderedAt":2039},["ShallowReactive",2],{"navigation":3,"/concepts/identity-multi-tenancy":879,"/concepts/identity-multi-tenancy-surround":2034},[4,22,45,115,156,187,214,235,264,295,318,361,389,418,436,470,491,534,548,571,632,670,693,757,850],{"title":5,"path":6,"stem":7,"children":8,"icon":11},"Introduction","/introduction","01.introduction/1.index",[9,12,17],{"title":10,"path":6,"stem":7,"icon":11},"What is Orkestia?","i-lucide-sparkles",{"title":13,"path":14,"stem":15,"icon":16},"Core Philosophy","/introduction/core-philosophy","01.introduction/2.core-philosophy","i-lucide-shield-check",{"title":18,"path":19,"stem":20,"icon":21},"Key Benefits","/introduction/key-benefits","01.introduction/3.key-benefits","i-lucide-trophy",{"title":23,"path":24,"stem":25,"children":26,"icon":29},"Getting Started","/getting-started","02.getting-started/1.index",[27,30,35,40],{"title":28,"path":24,"stem":25,"icon":29},"Quick Start","i-lucide-rocket",{"title":31,"path":32,"stem":33,"icon":34},"Architecture Overview","/getting-started/architecture-overview","02.getting-started/2.architecture-overview","i-lucide-layout-dashboard",{"title":36,"path":37,"stem":38,"icon":39},"Concepts at a Glance","/getting-started/concepts","02.getting-started/3.concepts","i-lucide-list",{"title":41,"path":42,"stem":43,"icon":44},"Connect an AI Assistant","/getting-started/connect-an-ai-assistant","02.getting-started/4.connect-an-ai-assistant","i-lucide-bot",{"title":46,"path":47,"stem":48,"children":49,"icon":51},"Core Concepts","/concepts","03.concepts/01.index",[50,52,57,62,67,71,76,81,86,91,96,100,105,110],{"title":46,"path":47,"stem":48,"icon":51},"i-lucide-book-open",{"title":53,"path":54,"stem":55,"icon":56},"Workflows","/concepts/workflows","03.concepts/02.workflows","i-lucide-workflow",{"title":58,"path":59,"stem":60,"icon":61},"DGI — Dialog Generative Interface","/concepts/dgi","03.concepts/03.dgi","i-lucide-brain",{"title":63,"path":64,"stem":65,"icon":66},"Staff & AI Workforce Governance","/concepts/staff-governance","03.concepts/04.staff-governance","i-lucide-users-round",{"title":68,"path":69,"stem":70,"icon":44},"Agents — the execution substrate","/concepts/agents-platform","03.concepts/05.agents-platform",{"title":72,"path":73,"stem":74,"icon":75},"Runners & Execution Environments","/concepts/runners","03.concepts/06.runners","i-lucide-server-cog",{"title":77,"path":78,"stem":79,"icon":80},"Lumen Observability","/concepts/lumen","03.concepts/07.lumen","i-lucide-activity",{"title":82,"path":83,"stem":84,"icon":85},"Identity & Multi-Tenancy","/concepts/identity-multi-tenancy","03.concepts/08.identity-multi-tenancy","i-lucide-users",{"title":87,"path":88,"stem":89,"icon":90},"Billing, Pricing & Seats","/concepts/billing-and-seats","03.concepts/09.billing-and-seats","i-lucide-credit-card",{"title":92,"path":93,"stem":94,"icon":95},"App Data","/concepts/appdata","03.concepts/10.appdata","i-lucide-database",{"title":97,"path":98,"stem":99,"icon":61},"Engram","/concepts/engram","03.concepts/11.engram",{"title":101,"path":102,"stem":103,"icon":104},"DevKit","/concepts/devkit","03.concepts/12.devkit","i-lucide-terminal",{"title":106,"path":107,"stem":108,"icon":109},"App Host","/concepts/app-host","03.concepts/13.app-host","i-lucide-globe",{"title":111,"path":112,"stem":113,"icon":114},"Agent Exchange","/concepts/agent-exchange","03.concepts/14.agent-exchange","i-lucide-landmark",{"title":116,"path":117,"stem":118,"children":119,"icon":121},"Guides","/guides","04.guides/1.index",[120,122,127,132,137,142,147,151],{"title":116,"path":117,"stem":118,"icon":121},"i-lucide-compass",{"title":123,"path":124,"stem":125,"icon":126},"Building with DGI","/guides/building-with-dgi","04.guides/2.building-with-dgi","i-lucide-brain-circuit",{"title":128,"path":129,"stem":130,"icon":131},"Creating & Exposing Virtual Workflows","/guides/virtual-workflows","04.guides/4.virtual-workflows","i-lucide-blocks",{"title":133,"path":134,"stem":135,"icon":136},"Runner Management & Provisioning","/guides/runner-management","04.guides/5.runner-management","i-lucide-server",{"title":138,"path":139,"stem":140,"icon":141},"Security & Compliance","/guides/security-and-compliance","04.guides/7.security-and-compliance","i-lucide-shield",{"title":143,"path":144,"stem":145,"icon":146},"Tickets & Software Delivery","/guides/tickets-and-software-delivery","04.guides/8.tickets-and-software-delivery","i-lucide-ticket",{"title":148,"path":149,"stem":150},"Orkestia for AI-driven cloud infrastructure automation","/guides/cloud-automation-alternatives","04.guides/9.cloud-automation-alternatives",{"title":152,"path":153,"stem":154,"icon":155},"Typed decisions with TypeSafe","/guides/typed-decisions-with-typesafe","04.guides/9.typed-decisions-with-typesafe","i-lucide-git-branch",{"title":157,"path":158,"stem":159,"children":160,"icon":162},"Reference","/reference","05.reference/1.index",[161,163,168,173,177,182],{"title":157,"path":158,"stem":159,"icon":162},"i-lucide-library",{"title":164,"path":165,"stem":166,"icon":167},"Workflow Types & Registry","/reference/workflow-types-registry","05.reference/2.workflow-types-registry","i-lucide-list-tree",{"title":169,"path":170,"stem":171,"icon":172},"MCP Integration","/reference/mcp-integration","05.reference/3.mcp-integration","i-lucide-plug-zap",{"title":174,"path":175,"stem":176,"icon":104},"API & Tooling","/reference/api-tooling","05.reference/4.api-tooling",{"title":178,"path":179,"stem":180,"icon":181},"Integrations Catalog","/reference/integrations-catalog","05.reference/6.integrations-catalog","i-lucide-plug",{"title":183,"path":184,"stem":185,"icon":186},"Platform Services","/reference/platform-services","05.reference/7.platform-services","i-lucide-boxes",{"title":188,"path":189,"stem":190,"children":191,"icon":193},"Advanced Topics","/advanced","06.advanced/1.index",[192,194,199,204,209],{"title":188,"path":189,"stem":190,"icon":193},"i-lucide-flask-conical",{"title":195,"path":196,"stem":197,"icon":198},"Hybrid AI + Deterministic Execution","/advanced/hybrid-execution-model","06.advanced/2.hybrid-execution-model","i-lucide-git-merge",{"title":200,"path":201,"stem":202,"icon":203},"Drift Detection & Self-Healing","/advanced/drift-detection-self-healing","06.advanced/3.drift-detection-self-healing","i-lucide-heart-pulse",{"title":205,"path":206,"stem":207,"icon":208},"Governance & Approvals","/advanced/governance-and-approvals","06.advanced/4.governance-and-approvals","i-lucide-scale",{"title":210,"path":211,"stem":212,"icon":213},"Cost & Performance Optimization","/advanced/cost-and-performance","06.advanced/5.cost-and-performance","i-lucide-zap",{"title":215,"path":216,"stem":217,"children":218,"icon":220},"Operations","/operations","07.operations/1.index",[219,221,225,230],{"title":215,"path":216,"stem":217,"icon":220},"i-lucide-settings-2",{"title":222,"path":223,"stem":224,"icon":186},"Deployment Models","/operations/deployment-models","07.operations/2.deployment-models",{"title":226,"path":227,"stem":228,"icon":229},"Monitoring & Debugging","/operations/monitoring-and-debugging","07.operations/3.monitoring-and-debugging","i-lucide-bug",{"title":231,"path":232,"stem":233,"icon":234},"Best Practices","/operations/best-practices","07.operations/4.best-practices","i-lucide-check-check",{"title":236,"path":237,"stem":238,"children":239,"icon":241},"AWS Connections","/aws-connections","08.aws-connections/1.index",[240,242,245,250,255,260],{"title":236,"path":237,"stem":238,"icon":241},"i-simple-icons-amazonaws",{"title":23,"path":243,"stem":244,"icon":29},"/aws-connections/getting-started","08.aws-connections/2.getting-started",{"title":246,"path":247,"stem":248,"icon":249},"Setup Methods","/aws-connections/setup-methods","08.aws-connections/3.setup-methods","i-lucide-wrench",{"title":251,"path":252,"stem":253,"icon":254},"Managing Connections","/aws-connections/managing-connections","08.aws-connections/4.managing-connections","i-lucide-settings",{"title":256,"path":257,"stem":258,"icon":259},"Security Best Practices","/aws-connections/security-best-practices","08.aws-connections/5.security-best-practices","i-lucide-lock",{"title":261,"path":262,"stem":263,"icon":229},"Troubleshooting","/aws-connections/troubleshooting","08.aws-connections/6.troubleshooting",{"title":265,"path":266,"stem":267,"children":268,"icon":270},"Cloud Connections","/cloud-connections","09.cloud-connections/1.index",[269,271,276,281,286,291],{"title":265,"path":266,"stem":267,"icon":270},"i-lucide-cable",{"title":272,"path":273,"stem":274,"icon":275},"Google Cloud (GCP)","/cloud-connections/gcp","09.cloud-connections/2.gcp","i-simple-icons-googlecloud",{"title":277,"path":278,"stem":279,"icon":280},"Microsoft Azure","/cloud-connections/azure","09.cloud-connections/3.azure","i-simple-icons-microsoftazure",{"title":282,"path":283,"stem":284,"icon":285},"Magalu Cloud","/cloud-connections/magalu","09.cloud-connections/4.magalu","i-lucide-cloud",{"title":287,"path":288,"stem":289,"icon":290},"Kubernetes","/cloud-connections/kubernetes","09.cloud-connections/5.kubernetes","i-simple-icons-kubernetes",{"title":292,"path":293,"stem":294,"icon":208},"TypeSafe","/cloud-connections/typesafe","09.cloud-connections/6.typesafe",{"title":296,"path":297,"stem":298,"children":299,"icon":136},"DNS Providers","/dns-providers","10.dns-providers/1.index",[300,302,305,308,311,315],{"title":301,"path":297,"stem":298,"icon":136},"DNS Provider Connections",{"title":23,"path":303,"stem":304,"icon":29},"/dns-providers/getting-started","10.dns-providers/2.getting-started",{"title":246,"path":306,"stem":307,"icon":249},"/dns-providers/setup-methods","10.dns-providers/3.setup-methods",{"title":251,"path":309,"stem":310,"icon":254},"/dns-providers/managing-connections","10.dns-providers/4.managing-connections",{"title":312,"path":313,"stem":314,"icon":39},"Zones and Records","/dns-providers/zones-and-records","10.dns-providers/5.zones-and-records",{"title":261,"path":316,"stem":317,"icon":229},"/dns-providers/troubleshooting","10.dns-providers/6.troubleshooting",{"title":319,"path":320,"stem":321,"children":322,"icon":29},"Cloud Deploy","/cloud-deploy","11.cloud-deploy/01.index",[323,324,327,332,336,341,345,349,354,358],{"title":319,"path":320,"stem":321,"icon":29},{"title":23,"path":325,"stem":326,"icon":29},"/cloud-deploy/getting-started","11.cloud-deploy/02.getting-started",{"title":328,"path":329,"stem":330,"icon":331},"Creating a Site","/cloud-deploy/creating-a-site","11.cloud-deploy/03.creating-a-site","i-lucide-plus-circle",{"title":333,"path":334,"stem":335,"icon":34},"Site Overview and Deployments","/cloud-deploy/site-overview","11.cloud-deploy/04.site-overview",{"title":337,"path":338,"stem":339,"icon":340},"Deployment Progress and Success","/cloud-deploy/deployment-progress","11.cloud-deploy/05.deployment-progress","i-lucide-loader",{"title":342,"path":343,"stem":344,"icon":254},"Settings","/cloud-deploy/settings","11.cloud-deploy/06.settings",{"title":346,"path":347,"stem":348,"icon":109},"Custom Domains","/cloud-deploy/custom-domains","11.cloud-deploy/07.custom-domains",{"title":350,"path":351,"stem":352,"icon":353},"Resources, Releases, and Danger Zone","/cloud-deploy/resources-releases","11.cloud-deploy/08.resources-releases","i-lucide-package",{"title":355,"path":356,"stem":357,"icon":141},"Admin Dashboard","/cloud-deploy/admin-dashboard","11.cloud-deploy/09.admin-dashboard",{"title":261,"path":359,"stem":360,"icon":229},"/cloud-deploy/troubleshooting","11.cloud-deploy/10.troubleshooting",{"title":362,"path":363,"stem":364,"children":365,"icon":368},"User Onboarding","/user-onboarding","12.user-onboarding/1.index",[366,369,372,377,382,386],{"title":367,"path":363,"stem":364,"icon":368},"User Creation and Onboarding","i-lucide-user-plus",{"title":23,"path":370,"stem":371,"icon":29},"/user-onboarding/getting-started","12.user-onboarding/2.getting-started",{"title":373,"path":374,"stem":375,"icon":376},"Creating Your Organization","/user-onboarding/onboarding","12.user-onboarding/3.onboarding","i-lucide-building-2",{"title":378,"path":379,"stem":380,"icon":381},"Invitations","/user-onboarding/invitations","12.user-onboarding/4.invitations","i-lucide-mail",{"title":383,"path":384,"stem":385,"icon":254},"Managing Your Account","/user-onboarding/managing-account","12.user-onboarding/5.managing-account",{"title":261,"path":387,"stem":388,"icon":229},"/user-onboarding/troubleshooting","12.user-onboarding/6.troubleshooting",{"title":342,"path":390,"stem":391,"children":392,"icon":394},"/settings","13.settings/1.index",[393,395,400,404,409,413],{"title":342,"path":390,"stem":391,"icon":394},"i-lucide-sliders-horizontal",{"title":396,"path":397,"stem":398,"icon":399},"General Settings","/settings/general","13.settings/2.general","i-lucide-user",{"title":401,"path":402,"stem":403,"icon":85},"Members Settings","/settings/members","13.settings/3.members",{"title":405,"path":406,"stem":407,"icon":408},"Notifications Settings","/settings/notifications","13.settings/4.notifications","i-lucide-bell",{"title":410,"path":411,"stem":412,"icon":141},"Security Settings","/settings/security","13.settings/5.security",{"title":414,"path":415,"stem":416,"icon":417},"Signing Keys","/settings/keys","13.settings/6.keys","i-lucide-key-round",{"title":419,"path":420,"stem":421,"children":422,"icon":29},"App Enablement","/app-enablement","14.app-enablement/1.index",[423,424,428,432],{"title":419,"path":420,"stem":421,"icon":29},{"title":425,"path":426,"stem":427,"icon":417},"Sign in with Orkestia","/app-enablement/sign-in-with-orkestia","14.app-enablement/2.sign-in-with-orkestia",{"title":429,"path":430,"stem":431,"icon":95},"End-user data","/app-enablement/end-user-data","14.app-enablement/3.end-user-data",{"title":433,"path":434,"stem":435,"icon":131},"Compositions — use, invoke, share","/app-enablement/compositions","14.app-enablement/4.compositions",{"title":437,"path":438,"stem":439,"children":440,"icon":80},"Lumen","/lumen","15.lumen/1.index",[441,442,447,452,457,461,465],{"title":437,"path":438,"stem":439,"icon":80},{"title":443,"path":444,"stem":445,"icon":446},"Enable Lumen","/lumen/enable","15.lumen/2.enable","i-lucide-power",{"title":448,"path":449,"stem":450,"icon":451},"Send data","/lumen/send-data","15.lumen/3.send-data","i-lucide-upload",{"title":453,"path":454,"stem":455,"icon":456},"Collector","/lumen/collector","15.lumen/4.collector","i-lucide-container",{"title":458,"path":459,"stem":460,"icon":34},"Use Lumen","/lumen/observe","15.lumen/5.observe",{"title":462,"path":463,"stem":464,"icon":44},"Lumen MCP","/lumen/mcp","15.lumen/6.mcp",{"title":466,"path":467,"stem":468,"icon":469},"Query API","/lumen/query-api","15.lumen/7.query-api","i-lucide-search",{"title":471,"path":472,"stem":473,"children":474,"icon":476},"SDKs","/sdks","16.sdks/1.index",[475,477,482,487],{"title":471,"path":472,"stem":473,"icon":476},"i-lucide-code",{"title":478,"path":479,"stem":480,"icon":481},"Workflows SDK — Node / TypeScript","/sdks/workflows-nodejs","16.sdks/2.workflows-nodejs","i-lucide-file-ts",{"title":483,"path":484,"stem":485,"icon":486},"Workflows SDK — Python","/sdks/workflows-python","16.sdks/3.workflows-python","i-simple-icons-python",{"title":488,"path":489,"stem":490,"icon":417},"Auth SDK — Sign in with Orkestia","/sdks/auth","16.sdks/4.auth",{"title":92,"path":492,"stem":493,"children":494,"icon":95},"/appdata","17.appdata/1.index",[495,496,501,506,510,515,520,525,530],{"title":92,"path":492,"stem":493,"icon":95},{"title":497,"path":498,"stem":499,"icon":500},"Declare structures","/appdata/declare","17.appdata/2.declare","i-lucide-table",{"title":502,"path":503,"stem":504,"icon":505},"Records & Data API","/appdata/data-api","17.appdata/3.data-api","i-lucide-rows-3",{"title":507,"path":508,"stem":509,"icon":376},"Ownership & workspaces","/appdata/ownership","17.appdata/4.ownership",{"title":511,"path":512,"stem":513,"icon":514},"Expose App Data to end-users","/appdata/expose","17.appdata/5.expose","i-lucide-app-window",{"title":516,"path":517,"stem":518,"icon":519},"PostgREST HTTP","/appdata/postgrest","17.appdata/6.postgrest","i-lucide-unplug",{"title":521,"path":522,"stem":523,"icon":524},"Ordered append","/appdata/append","17.appdata/7.append","i-lucide-list-ordered",{"title":526,"path":527,"stem":528,"icon":529},"Databases and instances","/appdata/instances","17.appdata/8.instances","i-lucide-hard-drive",{"title":531,"path":532,"stem":533,"icon":104},"Query console and SQL","/appdata/query","17.appdata/9.query",{"title":97,"path":535,"stem":536,"children":537,"icon":61},"/engram","18.engram/1.index",[538,539,543],{"title":97,"path":535,"stem":536,"icon":61},{"title":540,"path":541,"stem":542,"icon":155},"Write & recall","/engram/write-recall","18.engram/2.write-recall",{"title":544,"path":545,"stem":546,"icon":547},"Field & feed","/engram/agent-memory","18.engram/3.agent-memory","i-lucide-radio",{"title":101,"path":549,"stem":550,"children":551,"icon":104},"/devkit","19.devkit/1.index",[552,553,558,562,567],{"title":101,"path":549,"stem":550,"icon":104},{"title":554,"path":555,"stem":556,"icon":557},"Install DevKit","/devkit/install","19.devkit/2.install","i-lucide-download",{"title":559,"path":560,"stem":561,"icon":519},"Hook redirect","/devkit/hooks","19.devkit/3.hooks",{"title":563,"path":564,"stem":565,"icon":566},"Local coding runner","/devkit/local-runner","19.devkit/4.local-runner","i-lucide-cpu",{"title":568,"path":569,"stem":570,"icon":131},"Compositions from DevKit","/devkit/compositions","19.devkit/5.compositions",{"title":572,"path":573,"stem":574,"children":575,"icon":44},"Staff & Agents","/staff-and-agents","20.staff-and-agents/01.index",[576,577,582,586,590,594,598,602,606,611,615,620,625,629],{"title":572,"path":573,"stem":574,"icon":44},{"title":578,"path":579,"stem":580,"icon":581},"Prerequisites","/staff-and-agents/prerequisites","20.staff-and-agents/02.prerequisites","i-lucide-list-checks",{"title":583,"path":584,"stem":585,"icon":368},"Hire an actor","/staff-and-agents/hire-an-actor","20.staff-and-agents/03.hire-an-actor",{"title":587,"path":588,"stem":589,"icon":34},"Console","/staff-and-agents/console","20.staff-and-agents/04.console",{"title":591,"path":592,"stem":593,"icon":11},"Configs, skills, and MCP","/staff-and-agents/configs-skills-mcp","20.staff-and-agents/05.configs-skills-mcp",{"title":595,"path":596,"stem":597,"icon":136},"Agent runner groups","/staff-and-agents/runner-groups","20.staff-and-agents/06.runner-groups",{"title":599,"path":600,"stem":601,"icon":16},"Governance","/staff-and-agents/governance","20.staff-and-agents/07.governance",{"title":603,"path":604,"stem":605,"icon":417},"Identity and tokens","/staff-and-agents/identity","20.staff-and-agents/08.identity",{"title":607,"path":608,"stem":609,"icon":610},"Memory and cost","/staff-and-agents/memory-and-cost","20.staff-and-agents/09.memory-and-cost","i-lucide-wallet",{"title":612,"path":613,"stem":614,"icon":155},"Coding agents","/staff-and-agents/coding-agents","20.staff-and-agents/10.coding-agents",{"title":616,"path":617,"stem":618,"icon":619},"Wire a repository for coding agents","/staff-and-agents/wire-a-repository","20.staff-and-agents/11.wire-a-repository","i-lucide-link",{"title":621,"path":622,"stem":623,"icon":624},"Run a ticket end to end","/staff-and-agents/run-a-ticket","20.staff-and-agents/12.run-a-ticket","i-lucide-play",{"title":626,"path":627,"stem":628,"icon":66},"Build a product team of actors","/staff-and-agents/build-a-product-team","20.staff-and-agents/13.build-a-product-team",{"title":261,"path":630,"stem":631,"icon":249},"/staff-and-agents/troubleshooting","20.staff-and-agents/14.troubleshooting",{"title":106,"path":633,"stem":634,"children":635,"icon":109},"/app-host","21.app-host/1.index",[636,637,641,644,649,653,658,662,666],{"title":106,"path":633,"stem":634,"icon":109},{"title":638,"path":639,"stem":640,"icon":514},"Your app and site","/app-host/your-app","21.app-host/2.your-app",{"title":92,"path":642,"stem":643,"icon":95},"/app-host/app-data","21.app-host/3.app-data",{"title":645,"path":646,"stem":647,"icon":648},"Website and process","/app-host/hosting","21.app-host/4.hosting","i-lucide-cloud-upload",{"title":650,"path":651,"stem":652,"icon":547},"Buzz","/app-host/buzz","21.app-host/5.buzz",{"title":654,"path":655,"stem":656,"icon":657},"Files","/app-host/files","21.app-host/6.files","i-lucide-folder",{"title":659,"path":660,"stem":661,"icon":109},"Your own domain","/app-host/your-domain","21.app-host/7.your-domain",{"title":663,"path":664,"stem":665,"icon":229},"Troubleshooting App Host","/app-host/troubleshooting","21.app-host/8.troubleshooting",{"title":667,"path":668,"stem":669,"icon":417},"Signing keys","/app-host/signing-keys","21.app-host/9.signing-keys",{"title":111,"path":671,"stem":672,"children":673,"icon":114},"/agent-exchange","22.agent-exchange/01.index",[674,675,678,682,686,690],{"title":111,"path":671,"stem":672,"icon":114},{"title":583,"path":676,"stem":677,"icon":368},"/agent-exchange/hire","22.agent-exchange/02.hire",{"title":679,"path":680,"stem":681,"icon":208},"List an actor","/agent-exchange/list","22.agent-exchange/03.list",{"title":683,"path":684,"stem":685,"icon":104},"Invoke & leases","/agent-exchange/invoke","22.agent-exchange/04.invoke",{"title":687,"path":688,"stem":689,"icon":141},"Settlement & trust","/agent-exchange/settlement","22.agent-exchange/05.settlement",{"title":53,"path":691,"stem":692,"icon":56},"/agent-exchange/workflows","22.agent-exchange/06.workflows",{"title":694,"path":695,"stem":696,"children":697,"icon":75},"Runners","/runners","23.runners/1.index",[698,700,704,709,713,717,721,726,730,734,738,741,745,749,753],{"title":699,"path":695,"stem":696,"icon":75},"Runner groups",{"title":701,"path":702,"stem":703,"icon":275},"Cloud Run","/runners/cloud-run","23.runners/10.cloud-run",{"title":705,"path":706,"stem":707,"icon":708},"DigitalOcean App Job","/runners/do-app-job","23.runners/11.do-app-job","i-simple-icons-digitalocean",{"title":710,"path":711,"stem":712,"icon":708},"DigitalOcean Droplet","/runners/do-droplet","23.runners/12.do-droplet",{"title":714,"path":715,"stem":716,"icon":285},"Magalu Cloud VM","/runners/magalu-vm","23.runners/13.magalu-vm",{"title":101,"path":718,"stem":719,"icon":720},"/runners/devkit","23.runners/14.devkit","i-lucide-laptop",{"title":722,"path":723,"stem":724,"icon":725},"Purposes & integrations","/runners/purposes","23.runners/16.purposes","i-lucide-layers",{"title":727,"path":728,"stem":729,"icon":241},"Fargate","/runners/fargate","23.runners/2.fargate",{"title":731,"path":732,"stem":733,"icon":241},"EC2 Auto Scaling","/runners/ec2-auto-scaling","23.runners/3.ec2-auto-scaling",{"title":735,"path":736,"stem":737,"icon":241},"EC2 VM","/runners/ec2-vm","23.runners/4.ec2-vm",{"title":287,"path":739,"stem":740,"icon":290},"/runners/kubernetes","23.runners/5.kubernetes",{"title":742,"path":743,"stem":744,"icon":280},"Azure Container Apps","/runners/azure-container-apps","23.runners/6.azure-container-apps",{"title":746,"path":747,"stem":748,"icon":280},"Azure VMSS","/runners/azure-vmss","23.runners/7.azure-vmss",{"title":750,"path":751,"stem":752,"icon":280},"Azure VM","/runners/azure-vm","23.runners/8.azure-vm",{"title":754,"path":755,"stem":756,"icon":275},"GCE","/runners/gce","23.runners/9.gce",{"title":758,"path":759,"stem":760,"children":761,"icon":763},"Chat","/chat","24.chat/01.index",[762,764,768,773,777,782,787,791,796,800,805,810,814,819,824,828,832,836,840,845],{"title":758,"path":759,"stem":760,"icon":763},"i-lucide-messages-square",{"title":765,"path":766,"stem":767,"icon":446},"Enable and publish","/chat/enable-and-publish","24.chat/02.enable-and-publish",{"title":769,"path":770,"stem":771,"icon":772},"Theme and customization","/chat/theme-and-customization","24.chat/03.theme-and-customization","i-lucide-palette",{"title":774,"path":775,"stem":776,"icon":85},"Members and moderation","/chat/members-and-moderation","24.chat/04.members-and-moderation",{"title":778,"path":779,"stem":780,"icon":781},"Channels","/chat/channels","24.chat/05.channels","i-lucide-hash",{"title":783,"path":784,"stem":785,"icon":786},"Using the chat","/chat/using-the-chat","24.chat/06.using-the-chat","i-lucide-message-circle",{"title":788,"path":789,"stem":790,"icon":44},"Actors in chat","/chat/actors-in-chat","24.chat/07.actors-in-chat",{"title":792,"path":793,"stem":794,"icon":795},"Internal support actor","/chat/internal-support-actor","24.chat/08.internal-support-actor","i-lucide-life-buoy",{"title":797,"path":798,"stem":799,"icon":104},"API and console","/chat/api-and-console","24.chat/09.api-and-console",{"title":801,"path":802,"stem":803,"icon":804},"Limits","/chat/limits","24.chat/10.limits","i-lucide-triangle-alert",{"title":806,"path":807,"stem":808,"icon":809},"Structured chat with DGI","/chat/structured-chat","24.chat/11.structured-chat","i-lucide-layout-list",{"title":811,"path":812,"stem":813,"icon":109},"Option A: hosted chat with DGI","/chat/option-a-hosted-chat","24.chat/12.option-a-hosted-chat",{"title":815,"path":816,"stem":817,"icon":818},"Option B: embed the chat component","/chat/option-b-embed-component","24.chat/13.option-b-embed-component","i-lucide-component",{"title":820,"path":821,"stem":822,"icon":823},"Option C: custom client (wire contract)","/chat/option-c-custom-client","24.chat/14.option-c-custom-client","i-lucide-braces",{"title":825,"path":826,"stem":827,"icon":394},"Responder configuration reference","/chat/responder-reference","24.chat/15.responder-reference",{"title":829,"path":830,"stem":831,"icon":547},"Cards, live updates and proactive posts","/chat/cards-live-and-proactive","24.chat/16.cards-live-and-proactive",{"title":833,"path":834,"stem":835,"icon":16},"Structured chat security model","/chat/structured-chat-security","24.chat/17.structured-chat-security",{"title":837,"path":838,"stem":839,"icon":181},"Option D: any app or API (dgi.chat)","/chat/option-d-chat-api","24.chat/18.option-d-chat-api",{"title":841,"path":842,"stem":843,"icon":844},"Card catalog","/chat/card-catalog","24.chat/19.card-catalog","i-lucide-layout-grid",{"title":846,"path":847,"stem":848,"icon":849},"Living Surfaces","/chat/living-surfaces","24.chat/20.living-surfaces","i-lucide-sprout",{"title":851,"path":852,"stem":853,"children":854,"icon":61},"DGI","/dgi","25.dgi/1.index",[855,857,862,866,870,874],{"title":856,"path":852,"stem":853,"icon":61},"What is DGI",{"title":858,"path":859,"stem":860,"icon":861},"How DGI works","/dgi/how-it-works","25.dgi/2.how-it-works","i-lucide-cog",{"title":863,"path":864,"stem":865,"icon":844},"Interfaces","/dgi/interfaces","25.dgi/3.interfaces",{"title":867,"path":868,"stem":869,"icon":29},"Quickstart","/dgi/quickstart","25.dgi/4.quickstart",{"title":871,"path":872,"stem":873,"icon":16},"Trust and safety","/dgi/trust-and-safety","25.dgi/5.trust-and-safety",{"title":875,"path":876,"stem":877,"icon":878},"FAQ","/dgi/faq","25.dgi/6.faq","i-lucide-circle-help",{"id":880,"title":82,"body":881,"description":2027,"extension":2028,"links":2029,"meta":2030,"navigation":2031,"path":83,"seo":2032,"stem":84,"__hash__":2033},"docs/03.concepts/08.identity-multi-tenancy.md",{"type":882,"value":883,"toc":2007},"minimark",[884,889,974,978,982,1088,1114,1118,1145,1160,1171,1209,1214,1221,1225,1244,1270,1273,1426,1437,1508,1512,1571,1574,1593,1597,1608,1619,1625,1629,1636,1640,1646,1653,1700,1703,1709,1716,1720,1758,1764,1772,1776,1785,1789,1795,1821,1825,1832,1836,1947,1951,1962,1966,2003],[885,886,888],"h2",{"id":887},"tldr","TL;DR",[890,891,892,908,923,929,958,968],"ul",{},[893,894,895,899,900,903,904,907],"li",{},[896,897,898],"strong",{},"Two identity planes."," ",[896,901,902],{},"Members"," (your team, and AI actors with agent tokens) operate the platform. ",[896,905,906],{},"End-users"," (your app's customers) sign in with \"Sign in with Orkestia\" and can only run what you expose.",[893,909,910,913,914,918,919,922],{},[896,911,912],{},"Org scoping is automatic."," Your organization is resolved server-side from your token. You never pass ",[915,916,917],"code",{},"organization_uuid"," by hand. ",[915,920,921],{},"whoami"," tells you who you are.",[893,924,925,928],{},[896,926,927],{},"End-user isolation is a three-part key:"," org, app, end-user, all derived from the verified token.",[893,930,931,934,935,938,939,942,943,948,949,951,952,957],{},[896,932,933],{},"Provisioning an identity app is one workflow call"," (",[915,936,937],{},"identity.app.provision","). An assistant can do it by following ",[915,940,941],{},"rule://orkestia-auth-setup",". New apps start in ",[896,944,945],{},[915,946,947],{},"dev"," (localhost). ",[896,950,106],{}," needs ",[896,953,954],{},[915,955,956],{},"live",".",[893,959,960,967],{},[896,961,962,963,966],{},"Signing keys (",[915,964,965],{},"identity.key.*",") are not members."," nsec is for Buzz owner AUTH. Invite teammates in Settings → Members.",[893,969,970,973],{},[896,971,972],{},"Seats are a hard login cap"," with forgiving semantics: over-cap users can register but not log in until a new pack lands.",[975,976,977],"p",{},"Keeping the two planes apart is the key to understanding who can see what. They authenticate differently, are scoped differently, and are billed differently. Everything else in the platform hangs off an organization.",[885,979,981],{"id":980},"the-two-identity-planes","The two identity planes",[983,984,985,998],"table",{},[986,987,988],"thead",{},[989,990,991,994,996],"tr",{},[992,993],"th",{},[992,995,902],{},[992,997,906],{},[999,1000,1001,1015,1028,1041,1054,1075],"tbody",{},[989,1002,1003,1009,1012],{},[1004,1005,1006],"td",{},[896,1007,1008],{},"Who",[1004,1010,1011],{},"Your team, plus AI actors",[1004,1013,1014],{},"Your application's users",[989,1016,1017,1022,1025],{},[1004,1018,1019],{},[896,1020,1021],{},"Sign in via",[1004,1023,1024],{},"Org login (hosted) or an API / agent token",[1004,1026,1027],{},"\"Sign in with Orkestia\" (OIDC + PKCE)",[989,1029,1030,1035,1038],{},[1004,1031,1032],{},[896,1033,1034],{},"Operate",[1004,1036,1037],{},"The platform: console, API, SDKs, MCP",[1004,1039,1040],{},"Only the app you built",[989,1042,1043,1048,1051],{},[1004,1044,1045],{},[896,1046,1047],{},"Scope",[1004,1049,1050],{},"The whole organization",[1004,1052,1053],{},"Their own data within your app",[989,1055,1056,1061,1068],{},[1004,1057,1058],{},[896,1059,1060],{},"Token",[1004,1062,1063,1064,1067],{},"Org JWT, API token, or ",[915,1065,1066],{},"agt_"," agent token",[1004,1069,1070,1071,1074],{},"End-user JWT (",[915,1072,1073],{},"user_type: end_user",", RS256)",[989,1076,1077,1082,1085],{},[1004,1078,1079],{},[896,1080,1081],{},"Provisioned by",[1004,1083,1084],{},"Org onboarding, invite, or Staff hire",[1004,1086,1087],{},"Self-registration into your app",[1089,1090,1091,1103],"card-group",{},[1092,1093,1095],"card",{"icon":376,"title":1094},"Organization plane",[975,1096,1097,1098,1102],{},"Members act ",[1099,1100,1101],"em",{},"across"," the org. Connections, runs, compositions, and resources belong to the organization and are isolated from every other org.",[1092,1104,1107],{"icon":1105,"title":1106},"i-lucide-user-check","End-user plane",[975,1108,1109,1110,1113],{},"Your app's users act only ",[1099,1111,1112],{},"within"," your app. Orkestia pins their identity to each run so they can never reach another user's data or any org-level resource.",[885,1115,1117],{"id":1116},"organizations-and-members","Organizations and members",[975,1119,1120,1121,1124,1125,1127,1128,1132,1133,1136,1137,1140,1141,1144],{},"An ",[896,1122,1123],{},"organization"," is your workspace, the unit everything is scoped to. ",[896,1126,902],{}," are the people and AI actors who operate it. Members manage ",[1129,1130,1131],"a",{"href":237},"connections",", run and author ",[1129,1134,1135],{"href":54},"workflows",", build ",[1129,1138,1139],{"href":129},"compositions",", govern ",[1129,1142,1143],{"href":64},"Staff",", and configure the org.",[975,1146,1147,1148,1151,1152,1155,1156,1159],{},"The decisive property is that ",[896,1149,1150],{},"org scoping is automatic",". Your organization is resolved server-side from your credentials and applied to every run. You do ",[896,1153,1154],{},"not"," pass an org id into ",[915,1157,1158],{},"initial_data"," unless a schema explicitly declares one, and then it must match your authenticated org. This one rule is what isolates one customer's resources, data, and runs from another's.",[1161,1162,1169],"pre",{"className":1163,"code":1165,"filename":1166,"language":1167,"meta":1168},[1164],"language-text","whoami()\n→ { \"user_id\": \"…\", \"organization_uuid\": \"b7f343…\", \"username\": \"you@example.com\", \"token_type\": \"access\" }\n\nstart_workflow(\"aws.s3.create_bucket\", { \"bucket\": \"reports\", \"connection_uuid\": \"1f2a…\" })\n→ Orkestia stamps organization_uuid = b7f343… onto the run. Passing it by hand is rejected as an unknown field.\n","as an assistant sees it","text","",[915,1170,1165],{"__ignoreMap":1168},[1172,1173,1174],"note",{},[975,1175,1176,1177,1180,1181,1184,1185,1187,1188,1191,1192,1191,1195,1198,1199,1202,1203,1206,1207,957],{},"Members can be ",[896,1178,1179],{},"users"," (humans) or ",[896,1182,1183],{},"keys"," (AI agents and service principals). Both are first-class actors and both occupy a seat. On an agent token, ",[915,1186,921],{}," additionally returns ",[915,1189,1190],{},"agent_uuid",", ",[915,1193,1194],{},"staff_actor_uuid",[915,1196,1197],{},"permission_mode",", and ",[915,1200,1201],{},"seat_mode",". See ",[1129,1204,1205],{"href":64},"Staff governance"," and ",[1129,1208,87],{"href":88},[1210,1211,1213],"h3",{"id":1212},"one-person-many-organizations","One person, many organizations",[975,1215,1216,1217,1220],{},"Membership is many-to-many. The same user can belong to several organizations with one ",[896,1218,1219],{},"active organization"," at a time. Every credentialed surface (console, API, SDKs, MCP) acts as your active org. Switching re-scopes everything: connections, runs, catalogs, Staff, billing. The scoping rule is unchanged: whichever org is active is resolved server-side and stamped onto every run.",[885,1222,1224],{"id":1223},"end-users-sign-in-with-orkestia","End-users: \"Sign in with Orkestia\"",[975,1226,1227,1228,1231,1232,1235,1236,1239,1240,1243],{},"When you build an app ",[1099,1229,1230],{},"on"," Orkestia, its users are ",[896,1233,1234],{},"end-users",", not members. They authenticate through ",[896,1237,1238],{},"\"Sign in with Orkestia\"",": hosted login at ",[915,1241,1242],{},"login.orkestia.dev"," that your app embeds. None of the dangerous parts live in your code:",[890,1245,1246,1252,1258],{},[893,1247,1248,1251],{},[896,1249,1250],{},"OIDC + PKCE"," authorization-code flow. The token never rides in a redirect URL.",[893,1253,1254,1257],{},[896,1255,1256],{},"RS256 JWTs"," signed by Orkestia's rotating key, verifiable against a published JWKS.",[893,1259,1260,1191,1263,1198,1266,1269],{},[896,1261,1262],{},"MFA (TOTP)",[896,1264,1265],{},"email verification",[896,1267,1268],{},"password reset"," built in.",[975,1271,1272],{},"A decoded end-user token carries an explicit type marker so it can never be confused with a member token:",[1161,1274,1278],{"className":1275,"code":1276,"language":1277,"meta":1168,"style":1168},"language-json shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","{\n  \"iss\": \"login.orkestia.dev\",\n  \"user_type\": \"end_user\",\n  \"sub\": \"\u003Cend_user_uuid>\",\n  \"org\": \"\u003Corganization_uuid>\",\n  \"app\": \"\u003Cclient_uuid>\",\n  \"kid\": \"prod-1\"\n}\n","json",[915,1279,1280,1289,1316,1337,1358,1379,1400,1420],{"__ignoreMap":1168},[1281,1282,1285],"span",{"class":1283,"line":1284},"line",1,[1281,1286,1288],{"class":1287},"sMK4o","{\n",[1281,1290,1292,1295,1299,1302,1305,1308,1311,1313],{"class":1283,"line":1291},2,[1281,1293,1294],{"class":1287},"  \"",[1281,1296,1298],{"class":1297},"spNyl","iss",[1281,1300,1301],{"class":1287},"\"",[1281,1303,1304],{"class":1287},":",[1281,1306,1307],{"class":1287}," \"",[1281,1309,1242],{"class":1310},"sfazB",[1281,1312,1301],{"class":1287},[1281,1314,1315],{"class":1287},",\n",[1281,1317,1319,1321,1324,1326,1328,1330,1333,1335],{"class":1283,"line":1318},3,[1281,1320,1294],{"class":1287},[1281,1322,1323],{"class":1297},"user_type",[1281,1325,1301],{"class":1287},[1281,1327,1304],{"class":1287},[1281,1329,1307],{"class":1287},[1281,1331,1332],{"class":1310},"end_user",[1281,1334,1301],{"class":1287},[1281,1336,1315],{"class":1287},[1281,1338,1340,1342,1345,1347,1349,1351,1354,1356],{"class":1283,"line":1339},4,[1281,1341,1294],{"class":1287},[1281,1343,1344],{"class":1297},"sub",[1281,1346,1301],{"class":1287},[1281,1348,1304],{"class":1287},[1281,1350,1307],{"class":1287},[1281,1352,1353],{"class":1310},"\u003Cend_user_uuid>",[1281,1355,1301],{"class":1287},[1281,1357,1315],{"class":1287},[1281,1359,1361,1363,1366,1368,1370,1372,1375,1377],{"class":1283,"line":1360},5,[1281,1362,1294],{"class":1287},[1281,1364,1365],{"class":1297},"org",[1281,1367,1301],{"class":1287},[1281,1369,1304],{"class":1287},[1281,1371,1307],{"class":1287},[1281,1373,1374],{"class":1310},"\u003Corganization_uuid>",[1281,1376,1301],{"class":1287},[1281,1378,1315],{"class":1287},[1281,1380,1382,1384,1387,1389,1391,1393,1396,1398],{"class":1283,"line":1381},6,[1281,1383,1294],{"class":1287},[1281,1385,1386],{"class":1297},"app",[1281,1388,1301],{"class":1287},[1281,1390,1304],{"class":1287},[1281,1392,1307],{"class":1287},[1281,1394,1395],{"class":1310},"\u003Cclient_uuid>",[1281,1397,1301],{"class":1287},[1281,1399,1315],{"class":1287},[1281,1401,1403,1405,1408,1410,1412,1414,1417],{"class":1283,"line":1402},7,[1281,1404,1294],{"class":1287},[1281,1406,1407],{"class":1297},"kid",[1281,1409,1301],{"class":1287},[1281,1411,1304],{"class":1287},[1281,1413,1307],{"class":1287},[1281,1415,1416],{"class":1310},"prod-1",[1281,1418,1419],{"class":1287},"\"\n",[1281,1421,1423],{"class":1283,"line":1422},8,[1281,1424,1425],{"class":1287},"}\n",[975,1427,1428,1429,1432,1433,1436],{},"When a signed-in user invokes one of your exposed workflows or compositions, Orkestia ",[896,1430,1431],{},"injects the user's identity immutably"," and enforces that the run only touches ",[1099,1434,1435],{},"that user's"," data.",[1161,1438,1442],{"className":1439,"code":1440,"language":1441,"meta":1168,"style":1168},"language-mermaid shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","sequenceDiagram\n    participant U as End-user\n    participant App as Your frontend\n    participant O as Sign in with Orkestia\n    participant E as Workflow engine\n    U->>App: open app\n    App->>O: authorize (OIDC + PKCE)\n    O->>U: login / MFA / verify\n    O-->>App: end-user JWT (user_type=end_user)\n    App->>E: invoke exposed workflow + JWT\n    Note over E: org + app + end_user pinned from the token\n    E-->>App: result scoped to this user only\n","mermaid",[915,1443,1444,1449,1454,1459,1464,1469,1474,1479,1484,1490,1496,1502],{"__ignoreMap":1168},[1281,1445,1446],{"class":1283,"line":1284},[1281,1447,1448],{},"sequenceDiagram\n",[1281,1450,1451],{"class":1283,"line":1291},[1281,1452,1453],{},"    participant U as End-user\n",[1281,1455,1456],{"class":1283,"line":1318},[1281,1457,1458],{},"    participant App as Your frontend\n",[1281,1460,1461],{"class":1283,"line":1339},[1281,1462,1463],{},"    participant O as Sign in with Orkestia\n",[1281,1465,1466],{"class":1283,"line":1360},[1281,1467,1468],{},"    participant E as Workflow engine\n",[1281,1470,1471],{"class":1283,"line":1381},[1281,1472,1473],{},"    U->>App: open app\n",[1281,1475,1476],{"class":1283,"line":1402},[1281,1477,1478],{},"    App->>O: authorize (OIDC + PKCE)\n",[1281,1480,1481],{"class":1283,"line":1422},[1281,1482,1483],{},"    O->>U: login / MFA / verify\n",[1281,1485,1487],{"class":1283,"line":1486},9,[1281,1488,1489],{},"    O-->>App: end-user JWT (user_type=end_user)\n",[1281,1491,1493],{"class":1283,"line":1492},10,[1281,1494,1495],{},"    App->>E: invoke exposed workflow + JWT\n",[1281,1497,1499],{"class":1283,"line":1498},11,[1281,1500,1501],{},"    Note over E: org + app + end_user pinned from the token\n",[1281,1503,1505],{"class":1283,"line":1504},12,[1281,1506,1507],{},"    E-->>App: result scoped to this user only\n",[885,1509,1511],{"id":1510},"the-isolation-tuple-org-app-end-user","The isolation tuple: org, app, end-user",[983,1513,1514,1527],{},[986,1515,1516],{},[989,1517,1518,1521,1524],{},[992,1519,1520],{},"Dimension",[992,1522,1523],{},"Where it comes from",[992,1525,1526],{},"What it isolates",[999,1528,1529,1541,1557],{},[989,1530,1531,1535,1538],{},[1004,1532,1533],{},[896,1534,1365],{},[1004,1536,1537],{},"The app's registration",[1004,1539,1540],{},"One customer from another",[989,1542,1543,1547,1554],{},[1004,1544,1545],{},[896,1546,1386],{},[1004,1548,1549,1550,1553],{},"The ",[915,1551,1552],{},"client_uuid"," of the identity app",[1004,1555,1556],{},"One of your apps from another",[989,1558,1559,1563,1568],{},[1004,1560,1561],{},[896,1562,1332],{},[1004,1564,1549,1565,1567],{},[915,1566,1344],{}," claim, injected immutably",[1004,1569,1570],{},"One of your users from another",[975,1572,1573],{},"The engine derives all three from the verified token, not from inputs your frontend supplies, so a user cannot widen their own scope by editing a request.",[1575,1576,1577],"warning",{},[975,1578,1579,1582,1583,1585,1586,1589,1590,957],{},[896,1580,1581],{},"Orkestia paves the data layer; it does not police a database it does not run."," For workflows whose side effects run inside Orkestia-managed runners, connections, and ",[1129,1584,92],{"href":492},", the platform enforces the scope end to end. When a workflow reads or writes rows in ",[1099,1587,1588],{},"your own"," store, Orkestia guarantees the verified identity reaching it and ships row-policy templates, but the final row-level isolation is enforced by the policies you apply. See ",[1129,1591,1592],{"href":139},"Security & compliance",[885,1594,1596],{"id":1595},"seats-and-the-hard-login-cap","Seats and the hard login cap",[975,1598,1599,1600,1603,1604,1607],{},"End-user capacity is sold in ",[896,1601,1602],{},"seat packs",". The cap is a ",[896,1605,1606],{},"hard login cap",", not a soft throttle:",[890,1609,1610,1613],{},[893,1611,1612],{},"Below the limit, end-users register and log in normally.",[893,1614,1615,1618],{},[896,1616,1617],{},"Beyond the limit, end-users can still be created, but they cannot log in."," The org owner is notified until another pack is purchased.",[1620,1621,1622],"tip",{},[975,1623,1624],{},"Signups are never silently dropped, and you cannot accidentally run an unbounded, unbilled population. New seats unlock already-registered users immediately.",[885,1626,1628],{"id":1627},"exposing-workflows-to-end-users-app-enablement","Exposing workflows to end-users: App Enablement",[975,1630,1631,1632,1635],{},"End-users do not get the full catalog. A member must ",[896,1633,1634],{},"explicitly expose"," a workflow or composition to an app before any end-user can invoke it.",[1210,1637,1639],{"id":1638},"one-call-to-provision-and-an-assistant-can-run-it","One call to provision, and an assistant can run it",[975,1641,1642,1643,1645],{},"Provisioning an identity app is a single workflow. The MCP server publishes the recipe as ",[915,1644,941],{},", so an assistant can wire it unattended:",[1161,1647,1651],{"className":1648,"code":1649,"filename":1650,"language":1167,"meta":1168},[1164],"whoami()\nstart_workflow(\"identity.app.provision\", {\n  \"name\": \"My App\",\n  \"redirect_uris\": [\"http://localhost:5173/callback\", \"https://myapp.com/callback\"]\n})\n→ { client_key, client_uuid, redirect_uris,\n    integration: { issuer, discovery_url, authorize_url, code_exchange_url, jwks_url, flow, sdk } }\n","assistant transcript",[915,1652,1649],{"__ignoreMap":1168},[975,1654,1655,1656,1659,1660,1663,1664,1667,1668,934,1675,1191,1678,1681,1682,1685,1686,1689,1690,1693,1694,1697,1698,957],{},"That returns everything needed to wire auth: ",[915,1657,1658],{},"client_key"," is the public PKCE client id (safe in browser source), the origins are accepted immediately, and ",[915,1661,1662],{},"integration"," carries the endpoints. Add more redirect URIs later with ",[915,1665,1666],{},"identity.app.configure-client",". Wire the client side with ",[896,1669,1670],{},[1129,1671,1672],{"href":489},[915,1673,1674],{},"@orkestia/auth",[915,1676,1677],{},"signIn",[915,1679,1680],{},"handleCallback",", silent ",[915,1683,1684],{},"renew","), then pass ",[915,1687,1688],{},"session.token"," to the ",[1129,1691,1692],{"href":479},"Node"," or ",[1129,1695,1696],{"href":484},"Python"," workflow SDK. App rows live in ",[1129,1699,92],{"href":492},[975,1701,1702],{},"To let end-users run business logic scoped to themselves, expose a composition:",[1161,1704,1707],{"className":1705,"code":1706,"language":1167,"meta":1168},[1164],"start_workflow(\"identity.app.expose-virtual-workflow\", {\n  \"identity_app_uuid\": \"\u003Cfrom provision>\",\n  \"composition_uuid\": \"\u003Ca composition you authored>\", \"version\": 1\n})\n",[915,1708,1706],{"__ignoreMap":1168},[975,1710,1711,1712,1715],{},"The app then POSTs to ",[915,1713,1714],{},"/api/workflows"," with the end-user JWT as a Bearer token. End-users may start only the virtual workflows you exposed, nothing else.",[1210,1717,1719],{"id":1718},"exposure-is-a-descriptor-not-a-boolean","Exposure is a descriptor, not a boolean",[975,1721,1722,1725,1726,1729,1730,1733,1734,1737,1738,934,1741,1191,1744,1191,1747,1191,1750,1753,1754,1757],{},[915,1723,1724],{},"end_user_eligible"," is a ",[896,1727,1728],{},"capability descriptor"," authored alongside the workflow. It declares which inputs are ",[896,1731,1732],{},"bindable"," by the app versus ",[896,1735,1736],{},"sensitive",", the workflow's ",[896,1739,1740],{},"side-effect class",[915,1742,1743],{},"read",[915,1745,1746],{},"write-own",[915,1748,1749],{},"external-send",[915,1751,1752],{},"irreversible","), and what must be bound before exposure is legal. The app fills a policy ",[1099,1755,1756],{},"within that envelope",", and the engine enforces both at invocation time.",[1759,1760],"dag-diagram",{":edges":1761,":nodes":1762,"direction":1763},"[{\"from\":\"author\",\"to\":\"member\"},{\"from\":\"member\",\"to\":\"app_policy\"},{\"from\":\"app_policy\",\"to\":\"end_user\"},{\"from\":\"end_user\",\"to\":\"engine\"},{\"from\":\"engine\",\"to\":\"run\",\"label\":\"allowed\"},{\"from\":\"engine\",\"to\":\"rejected\",\"label\":\"violation\"}]","[{\"id\":\"author\",\"label\":\"Workflow author\",\"sub\":\"declares descriptor\",\"kind\":\"start\"},{\"id\":\"member\",\"label\":\"Member exposes\",\"sub\":\"to an app\"},{\"id\":\"app_policy\",\"label\":\"App sets policy\",\"sub\":\"within envelope\"},{\"id\":\"end_user\",\"label\":\"End-user invokes\",\"kind\":\"start\"},{\"id\":\"engine\",\"label\":\"Engine enforces\",\"sub\":\"descriptor + policy + tuple\",\"kind\":\"engine\"},{\"id\":\"run\",\"label\":\"Run scoped to user\",\"kind\":\"terminal\"},{\"id\":\"rejected\",\"label\":\"Rejected\",\"kind\":\"failed\"}]","LR",[1765,1766,1767],"callout",{"icon":29,"to":420},[975,1768,1769,1770,957],{},"Full walkthrough: provisioning, \"Sign in with Orkestia\", and exposing per-user data, in ",[896,1771,419],{},[1210,1773,1775],{"id":1774},"chat-for-your-end-users","Chat for your end-users",[975,1777,1778,1779,1782,1783,957],{},"An identity app can also get a ",[896,1780,1781],{},"chat space",". End-users open it by signing in with the same app identity, the seat cap applies as it does at login, and a Staff actor bound to an end-user seat in the app can answer inside the conversation. The chat's end-user actions are entry points exposed on the app, like any other exposed composition. See ",[1129,1784,758],{"href":759},[885,1786,1788],{"id":1787},"everything-is-org-scoped","Everything is org-scoped",[975,1790,1791,1792,1794],{},"The same ",[915,1793,917],{}," that gates a member's run also partitions:",[1089,1796,1797,1803,1809,1815],{},[1092,1798,1800],{"icon":285,"title":1799,"to":73},"Connections & runners",[975,1801,1802],{},"Cloud accounts, runners, and credentials belong to the org and are never visible cross-tenant.",[1092,1804,1806],{"icon":56,"title":1805,"to":54},"Workflows & state",[975,1807,1808],{},"Runs, event-sourced state, and compositions are stored and queried per org.",[1092,1810,1812],{"icon":80,"title":1811,"to":78},"Observability",[975,1813,1814],{},"Lumen telemetry, audit logs, and drift signals are partitioned by org.",[1092,1816,1818],{"icon":85,"title":1817,"to":420},"Identity apps & end-users",[975,1819,1820],{},"Every identity app, end-user, and seat pack nests under one org.",[885,1822,1824],{"id":1823},"ask-your-ai-assistant","Ask your AI assistant",[1161,1826,1830],{"className":1827,"code":1828,"filename":1829,"language":1167,"meta":1168},[1164],"Call whoami and explain what kind of principal I am, which org I'm scoped to, and whether I'm on a user, API, or agent token.\n\nList my organization's members and pending invitations.\n\nFollow rule://orkestia-auth-setup to provision an identity app called \"Demo\" with redirect URI http://localhost:5173/callback. Return the client_key and integration endpoints.\n\nExpose composition \u003Ccomposition_uuid> version 1 to identity app \u003Cidentity_app_uuid>. Confirm the side-effect class before you do it.\n","prompts",[915,1831,1828],{"__ignoreMap":1168},[885,1833,1835],{"id":1834},"for-ai-agents","For AI agents",[983,1837,1838,1848],{},[986,1839,1840],{},[989,1841,1842,1845],{},[992,1843,1844],{},"Rule",[992,1846,1847],{},"Detail",[999,1849,1850,1863,1877,1894,1911,1919,1929,1937],{},[989,1851,1852,1857],{},[1004,1853,1854,1856],{},[915,1855,921],{}," first",[1004,1858,1859,1860,957],{},"Identity and org come from the token. See ",[915,1861,1862],{},"rule://authenticated-context",[989,1864,1865,1868],{},[1004,1866,1867],{},"Never pass the org",[1004,1869,1870,1871,1873,1874,1876],{},"Do not add ",[915,1872,917],{}," to ",[915,1875,1158],{}," unless the schema declares it. Cross-org access is not supported.",[989,1878,1879,1882],{},[1004,1880,1881],{},"End-user setup is a recipe",[1004,1883,1884,1885,1887,1888,1890,1891,957],{},"Follow ",[915,1886,941],{},": ",[915,1889,937],{},", then optionally ",[915,1892,1893],{},"identity.app.expose-virtual-workflow",[989,1895,1896,1899],{},[1004,1897,1898],{},"Live vs dev",[1004,1900,1901,1902,948,1904,1907,1908,1910],{},"New apps are ",[915,1903,947],{},[915,1905,1906],{},"identity.app.set-mode"," → ",[915,1909,956],{}," is one-way. App Host claim/publish require live.",[989,1912,1913,1916],{},[1004,1914,1915],{},"One AgentConfig per app",[1004,1917,1918],{},"A second agent product is a second Identity app.",[989,1920,1921,1926],{},[1004,1922,1923,1925],{},[915,1924,1658],{}," is public",[1004,1927,1928],{},"It is a PKCE client id, safe in browser source. There is no client secret to protect.",[989,1930,1931,1934],{},[1004,1932,1933],{},"Members vs end-users",[1004,1935,1936],{},"Org members are the customer's team. End-users are the app's customers. Do not conflate them.",[989,1938,1939,1942],{},[1004,1940,1941],{},"Signing keys are not members",[1004,1943,1944,1946],{},[915,1945,965],{}," (nsec) is for Buzz owner AUTH. Invite people in Settings → Members.",[885,1948,1950],{"id":1949},"status-and-current-limitations","Status and current limitations",[1172,1952,1953],{},[975,1954,1955,1956,957],{},"\"Sign in with Orkestia\" is live in beta and proven end to end. In flight: federation (Google, GitHub) runtime, production email delivery, per-route rate limiting, and a Lumen dashboard for auth events. Exact endpoints and seat-pack sizes may change; see ",[1129,1957,1961],{"href":1958,"rel":1959},"https://reference.orkestia.dev",[1960],"nofollow","reference.orkestia.dev",[885,1963,1965],{"id":1964},"next","Next",[1089,1967,1968,1974,1979,1984,1990,1997],{},[1092,1969,1971],{"icon":29,"title":1970,"to":420},"Add auth & per-user data to your app",[975,1972,1973],{},"Provision an identity app and expose scoped workflows.",[1092,1975,1976],{"icon":95,"title":92,"to":492},[975,1977,1978],{},"Where those users' rows live.",[1092,1980,1981],{"icon":109,"title":106,"to":633},[975,1982,1983],{},"Claim a live site. Signing keys are not members.",[1092,1985,1987],{"icon":368,"title":1986,"to":24},"Get your team onboarded",[975,1988,1989],{},"Stand up an org and invite members.",[1092,1991,1994],{"icon":1992,"title":1993,"to":129},"i-lucide-shapes","Build compositions to expose",[975,1995,1996],{},"The logic your end-users will run.",[1092,1998,2000],{"icon":44,"title":1999,"to":42},"Connect an AI assistant",[975,2001,2002],{},"Let an assistant provision and expose for you.",[2004,2005,2006],"style",{},"html pre.shiki code .sMK4o, html code.shiki .sMK4o{--shiki-light:#39ADB5;--shiki-default:#89DDFF;--shiki-dark:#89DDFF}html pre.shiki code .spNyl, html code.shiki .spNyl{--shiki-light:#9C3EDA;--shiki-default:#C792EA;--shiki-dark:#C792EA}html pre.shiki code .sfazB, html code.shiki .sfazB{--shiki-light:#91B859;--shiki-default:#C3E88D;--shiki-dark:#C3E88D}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":1168,"searchDepth":1284,"depth":1291,"links":2008},[2009,2010,2011,2014,2015,2016,2017,2022,2023,2024,2025,2026],{"id":887,"depth":1291,"text":888},{"id":980,"depth":1291,"text":981},{"id":1116,"depth":1291,"text":1117,"children":2012},[2013],{"id":1212,"depth":1318,"text":1213},{"id":1223,"depth":1291,"text":1224},{"id":1510,"depth":1291,"text":1511},{"id":1595,"depth":1291,"text":1596},{"id":1627,"depth":1291,"text":1628,"children":2018},[2019,2020,2021],{"id":1638,"depth":1318,"text":1639},{"id":1718,"depth":1318,"text":1719},{"id":1774,"depth":1318,"text":1775},{"id":1787,"depth":1291,"text":1788},{"id":1823,"depth":1291,"text":1824},{"id":1834,"depth":1291,"text":1835},{"id":1949,"depth":1291,"text":1950},{"id":1964,"depth":1291,"text":1965},"Two identity planes, org members who operate the platform and end-users who sign in to apps you build, with automatic org scoping, per-user isolation, and a one-call setup an assistant can run for you","md",null,{},{"icon":85},{"title":82,"description":2027},"zxN65OpzfdcDN5hKUkn3lVjCZQwnYX5tq7jBFN9-b-Y",[2035,2037],{"title":77,"path":78,"stem":79,"description":2036,"icon":80,"children":-1},"Orkestia's telemetry store and triage engine, JSON HTTP ingest, SHA-256 error groups, traces, metrics, the query API, and the Lumen MCP server for assistant-driven triage",{"title":87,"path":88,"stem":89,"description":2038,"icon":90,"children":-1},"How an Orkestia organization is billed, the platform subscription, seats for humans and AI actors, end-user seats, the execution and request meters, add-ons, and per-agent budgets that bound what an AI workforce can spend",1790354044276]