[{"data":1,"prerenderedAt":1786},["ShallowReactive",2],{"navigation":3,"/concepts/staff-governance":879,"/concepts/staff-governance-surround":1781},[4,22,45,115,156,187,214,235,264,295,318,361,389,418,436,470,491,534,548,571,632,670,693,757,850],{"title":5,"path":6,"stem":7,"children":8,"icon":11},"Introduction","/introduction","01.introduction/1.index",[9,12,17],{"title":10,"path":6,"stem":7,"icon":11},"What is Orkestia?","i-lucide-sparkles",{"title":13,"path":14,"stem":15,"icon":16},"Core Philosophy","/introduction/core-philosophy","01.introduction/2.core-philosophy","i-lucide-shield-check",{"title":18,"path":19,"stem":20,"icon":21},"Key Benefits","/introduction/key-benefits","01.introduction/3.key-benefits","i-lucide-trophy",{"title":23,"path":24,"stem":25,"children":26,"icon":29},"Getting Started","/getting-started","02.getting-started/1.index",[27,30,35,40],{"title":28,"path":24,"stem":25,"icon":29},"Quick Start","i-lucide-rocket",{"title":31,"path":32,"stem":33,"icon":34},"Architecture Overview","/getting-started/architecture-overview","02.getting-started/2.architecture-overview","i-lucide-layout-dashboard",{"title":36,"path":37,"stem":38,"icon":39},"Concepts at a Glance","/getting-started/concepts","02.getting-started/3.concepts","i-lucide-list",{"title":41,"path":42,"stem":43,"icon":44},"Connect an AI Assistant","/getting-started/connect-an-ai-assistant","02.getting-started/4.connect-an-ai-assistant","i-lucide-bot",{"title":46,"path":47,"stem":48,"children":49,"icon":51},"Core Concepts","/concepts","03.concepts/01.index",[50,52,57,62,67,71,76,81,86,91,96,100,105,110],{"title":46,"path":47,"stem":48,"icon":51},"i-lucide-book-open",{"title":53,"path":54,"stem":55,"icon":56},"Workflows","/concepts/workflows","03.concepts/02.workflows","i-lucide-workflow",{"title":58,"path":59,"stem":60,"icon":61},"DGI — Dialog Generative Interface","/concepts/dgi","03.concepts/03.dgi","i-lucide-brain",{"title":63,"path":64,"stem":65,"icon":66},"Staff & AI Workforce Governance","/concepts/staff-governance","03.concepts/04.staff-governance","i-lucide-users-round",{"title":68,"path":69,"stem":70,"icon":44},"Agents — the execution substrate","/concepts/agents-platform","03.concepts/05.agents-platform",{"title":72,"path":73,"stem":74,"icon":75},"Runners & Execution Environments","/concepts/runners","03.concepts/06.runners","i-lucide-server-cog",{"title":77,"path":78,"stem":79,"icon":80},"Lumen Observability","/concepts/lumen","03.concepts/07.lumen","i-lucide-activity",{"title":82,"path":83,"stem":84,"icon":85},"Identity & Multi-Tenancy","/concepts/identity-multi-tenancy","03.concepts/08.identity-multi-tenancy","i-lucide-users",{"title":87,"path":88,"stem":89,"icon":90},"Billing, Pricing & Seats","/concepts/billing-and-seats","03.concepts/09.billing-and-seats","i-lucide-credit-card",{"title":92,"path":93,"stem":94,"icon":95},"App Data","/concepts/appdata","03.concepts/10.appdata","i-lucide-database",{"title":97,"path":98,"stem":99,"icon":61},"Engram","/concepts/engram","03.concepts/11.engram",{"title":101,"path":102,"stem":103,"icon":104},"DevKit","/concepts/devkit","03.concepts/12.devkit","i-lucide-terminal",{"title":106,"path":107,"stem":108,"icon":109},"App Host","/concepts/app-host","03.concepts/13.app-host","i-lucide-globe",{"title":111,"path":112,"stem":113,"icon":114},"Agent Exchange","/concepts/agent-exchange","03.concepts/14.agent-exchange","i-lucide-landmark",{"title":116,"path":117,"stem":118,"children":119,"icon":121},"Guides","/guides","04.guides/1.index",[120,122,127,132,137,142,147,151],{"title":116,"path":117,"stem":118,"icon":121},"i-lucide-compass",{"title":123,"path":124,"stem":125,"icon":126},"Building with DGI","/guides/building-with-dgi","04.guides/2.building-with-dgi","i-lucide-brain-circuit",{"title":128,"path":129,"stem":130,"icon":131},"Creating & Exposing Virtual Workflows","/guides/virtual-workflows","04.guides/4.virtual-workflows","i-lucide-blocks",{"title":133,"path":134,"stem":135,"icon":136},"Runner Management & Provisioning","/guides/runner-management","04.guides/5.runner-management","i-lucide-server",{"title":138,"path":139,"stem":140,"icon":141},"Security & Compliance","/guides/security-and-compliance","04.guides/7.security-and-compliance","i-lucide-shield",{"title":143,"path":144,"stem":145,"icon":146},"Tickets & Software Delivery","/guides/tickets-and-software-delivery","04.guides/8.tickets-and-software-delivery","i-lucide-ticket",{"title":148,"path":149,"stem":150},"Orkestia for AI-driven cloud infrastructure automation","/guides/cloud-automation-alternatives","04.guides/9.cloud-automation-alternatives",{"title":152,"path":153,"stem":154,"icon":155},"Typed decisions with TypeSafe","/guides/typed-decisions-with-typesafe","04.guides/9.typed-decisions-with-typesafe","i-lucide-git-branch",{"title":157,"path":158,"stem":159,"children":160,"icon":162},"Reference","/reference","05.reference/1.index",[161,163,168,173,177,182],{"title":157,"path":158,"stem":159,"icon":162},"i-lucide-library",{"title":164,"path":165,"stem":166,"icon":167},"Workflow Types & Registry","/reference/workflow-types-registry","05.reference/2.workflow-types-registry","i-lucide-list-tree",{"title":169,"path":170,"stem":171,"icon":172},"MCP Integration","/reference/mcp-integration","05.reference/3.mcp-integration","i-lucide-plug-zap",{"title":174,"path":175,"stem":176,"icon":104},"API & Tooling","/reference/api-tooling","05.reference/4.api-tooling",{"title":178,"path":179,"stem":180,"icon":181},"Integrations Catalog","/reference/integrations-catalog","05.reference/6.integrations-catalog","i-lucide-plug",{"title":183,"path":184,"stem":185,"icon":186},"Platform Services","/reference/platform-services","05.reference/7.platform-services","i-lucide-boxes",{"title":188,"path":189,"stem":190,"children":191,"icon":193},"Advanced Topics","/advanced","06.advanced/1.index",[192,194,199,204,209],{"title":188,"path":189,"stem":190,"icon":193},"i-lucide-flask-conical",{"title":195,"path":196,"stem":197,"icon":198},"Hybrid AI + Deterministic Execution","/advanced/hybrid-execution-model","06.advanced/2.hybrid-execution-model","i-lucide-git-merge",{"title":200,"path":201,"stem":202,"icon":203},"Drift Detection & Self-Healing","/advanced/drift-detection-self-healing","06.advanced/3.drift-detection-self-healing","i-lucide-heart-pulse",{"title":205,"path":206,"stem":207,"icon":208},"Governance & Approvals","/advanced/governance-and-approvals","06.advanced/4.governance-and-approvals","i-lucide-scale",{"title":210,"path":211,"stem":212,"icon":213},"Cost & Performance Optimization","/advanced/cost-and-performance","06.advanced/5.cost-and-performance","i-lucide-zap",{"title":215,"path":216,"stem":217,"children":218,"icon":220},"Operations","/operations","07.operations/1.index",[219,221,225,230],{"title":215,"path":216,"stem":217,"icon":220},"i-lucide-settings-2",{"title":222,"path":223,"stem":224,"icon":186},"Deployment Models","/operations/deployment-models","07.operations/2.deployment-models",{"title":226,"path":227,"stem":228,"icon":229},"Monitoring & Debugging","/operations/monitoring-and-debugging","07.operations/3.monitoring-and-debugging","i-lucide-bug",{"title":231,"path":232,"stem":233,"icon":234},"Best Practices","/operations/best-practices","07.operations/4.best-practices","i-lucide-check-check",{"title":236,"path":237,"stem":238,"children":239,"icon":241},"AWS Connections","/aws-connections","08.aws-connections/1.index",[240,242,245,250,255,260],{"title":236,"path":237,"stem":238,"icon":241},"i-simple-icons-amazonaws",{"title":23,"path":243,"stem":244,"icon":29},"/aws-connections/getting-started","08.aws-connections/2.getting-started",{"title":246,"path":247,"stem":248,"icon":249},"Setup Methods","/aws-connections/setup-methods","08.aws-connections/3.setup-methods","i-lucide-wrench",{"title":251,"path":252,"stem":253,"icon":254},"Managing Connections","/aws-connections/managing-connections","08.aws-connections/4.managing-connections","i-lucide-settings",{"title":256,"path":257,"stem":258,"icon":259},"Security Best Practices","/aws-connections/security-best-practices","08.aws-connections/5.security-best-practices","i-lucide-lock",{"title":261,"path":262,"stem":263,"icon":229},"Troubleshooting","/aws-connections/troubleshooting","08.aws-connections/6.troubleshooting",{"title":265,"path":266,"stem":267,"children":268,"icon":270},"Cloud Connections","/cloud-connections","09.cloud-connections/1.index",[269,271,276,281,286,291],{"title":265,"path":266,"stem":267,"icon":270},"i-lucide-cable",{"title":272,"path":273,"stem":274,"icon":275},"Google Cloud (GCP)","/cloud-connections/gcp","09.cloud-connections/2.gcp","i-simple-icons-googlecloud",{"title":277,"path":278,"stem":279,"icon":280},"Microsoft Azure","/cloud-connections/azure","09.cloud-connections/3.azure","i-simple-icons-microsoftazure",{"title":282,"path":283,"stem":284,"icon":285},"Magalu Cloud","/cloud-connections/magalu","09.cloud-connections/4.magalu","i-lucide-cloud",{"title":287,"path":288,"stem":289,"icon":290},"Kubernetes","/cloud-connections/kubernetes","09.cloud-connections/5.kubernetes","i-simple-icons-kubernetes",{"title":292,"path":293,"stem":294,"icon":208},"TypeSafe","/cloud-connections/typesafe","09.cloud-connections/6.typesafe",{"title":296,"path":297,"stem":298,"children":299,"icon":136},"DNS Providers","/dns-providers","10.dns-providers/1.index",[300,302,305,308,311,315],{"title":301,"path":297,"stem":298,"icon":136},"DNS Provider Connections",{"title":23,"path":303,"stem":304,"icon":29},"/dns-providers/getting-started","10.dns-providers/2.getting-started",{"title":246,"path":306,"stem":307,"icon":249},"/dns-providers/setup-methods","10.dns-providers/3.setup-methods",{"title":251,"path":309,"stem":310,"icon":254},"/dns-providers/managing-connections","10.dns-providers/4.managing-connections",{"title":312,"path":313,"stem":314,"icon":39},"Zones and Records","/dns-providers/zones-and-records","10.dns-providers/5.zones-and-records",{"title":261,"path":316,"stem":317,"icon":229},"/dns-providers/troubleshooting","10.dns-providers/6.troubleshooting",{"title":319,"path":320,"stem":321,"children":322,"icon":29},"Cloud Deploy","/cloud-deploy","11.cloud-deploy/01.index",[323,324,327,332,336,341,345,349,354,358],{"title":319,"path":320,"stem":321,"icon":29},{"title":23,"path":325,"stem":326,"icon":29},"/cloud-deploy/getting-started","11.cloud-deploy/02.getting-started",{"title":328,"path":329,"stem":330,"icon":331},"Creating a Site","/cloud-deploy/creating-a-site","11.cloud-deploy/03.creating-a-site","i-lucide-plus-circle",{"title":333,"path":334,"stem":335,"icon":34},"Site Overview and Deployments","/cloud-deploy/site-overview","11.cloud-deploy/04.site-overview",{"title":337,"path":338,"stem":339,"icon":340},"Deployment Progress and Success","/cloud-deploy/deployment-progress","11.cloud-deploy/05.deployment-progress","i-lucide-loader",{"title":342,"path":343,"stem":344,"icon":254},"Settings","/cloud-deploy/settings","11.cloud-deploy/06.settings",{"title":346,"path":347,"stem":348,"icon":109},"Custom Domains","/cloud-deploy/custom-domains","11.cloud-deploy/07.custom-domains",{"title":350,"path":351,"stem":352,"icon":353},"Resources, Releases, and Danger Zone","/cloud-deploy/resources-releases","11.cloud-deploy/08.resources-releases","i-lucide-package",{"title":355,"path":356,"stem":357,"icon":141},"Admin Dashboard","/cloud-deploy/admin-dashboard","11.cloud-deploy/09.admin-dashboard",{"title":261,"path":359,"stem":360,"icon":229},"/cloud-deploy/troubleshooting","11.cloud-deploy/10.troubleshooting",{"title":362,"path":363,"stem":364,"children":365,"icon":368},"User Onboarding","/user-onboarding","12.user-onboarding/1.index",[366,369,372,377,382,386],{"title":367,"path":363,"stem":364,"icon":368},"User Creation and Onboarding","i-lucide-user-plus",{"title":23,"path":370,"stem":371,"icon":29},"/user-onboarding/getting-started","12.user-onboarding/2.getting-started",{"title":373,"path":374,"stem":375,"icon":376},"Creating Your Organization","/user-onboarding/onboarding","12.user-onboarding/3.onboarding","i-lucide-building-2",{"title":378,"path":379,"stem":380,"icon":381},"Invitations","/user-onboarding/invitations","12.user-onboarding/4.invitations","i-lucide-mail",{"title":383,"path":384,"stem":385,"icon":254},"Managing Your Account","/user-onboarding/managing-account","12.user-onboarding/5.managing-account",{"title":261,"path":387,"stem":388,"icon":229},"/user-onboarding/troubleshooting","12.user-onboarding/6.troubleshooting",{"title":342,"path":390,"stem":391,"children":392,"icon":394},"/settings","13.settings/1.index",[393,395,400,404,409,413],{"title":342,"path":390,"stem":391,"icon":394},"i-lucide-sliders-horizontal",{"title":396,"path":397,"stem":398,"icon":399},"General Settings","/settings/general","13.settings/2.general","i-lucide-user",{"title":401,"path":402,"stem":403,"icon":85},"Members Settings","/settings/members","13.settings/3.members",{"title":405,"path":406,"stem":407,"icon":408},"Notifications Settings","/settings/notifications","13.settings/4.notifications","i-lucide-bell",{"title":410,"path":411,"stem":412,"icon":141},"Security Settings","/settings/security","13.settings/5.security",{"title":414,"path":415,"stem":416,"icon":417},"Signing Keys","/settings/keys","13.settings/6.keys","i-lucide-key-round",{"title":419,"path":420,"stem":421,"children":422,"icon":29},"App Enablement","/app-enablement","14.app-enablement/1.index",[423,424,428,432],{"title":419,"path":420,"stem":421,"icon":29},{"title":425,"path":426,"stem":427,"icon":417},"Sign in with Orkestia","/app-enablement/sign-in-with-orkestia","14.app-enablement/2.sign-in-with-orkestia",{"title":429,"path":430,"stem":431,"icon":95},"End-user data","/app-enablement/end-user-data","14.app-enablement/3.end-user-data",{"title":433,"path":434,"stem":435,"icon":131},"Compositions — use, invoke, share","/app-enablement/compositions","14.app-enablement/4.compositions",{"title":437,"path":438,"stem":439,"children":440,"icon":80},"Lumen","/lumen","15.lumen/1.index",[441,442,447,452,457,461,465],{"title":437,"path":438,"stem":439,"icon":80},{"title":443,"path":444,"stem":445,"icon":446},"Enable Lumen","/lumen/enable","15.lumen/2.enable","i-lucide-power",{"title":448,"path":449,"stem":450,"icon":451},"Send data","/lumen/send-data","15.lumen/3.send-data","i-lucide-upload",{"title":453,"path":454,"stem":455,"icon":456},"Collector","/lumen/collector","15.lumen/4.collector","i-lucide-container",{"title":458,"path":459,"stem":460,"icon":34},"Use Lumen","/lumen/observe","15.lumen/5.observe",{"title":462,"path":463,"stem":464,"icon":44},"Lumen MCP","/lumen/mcp","15.lumen/6.mcp",{"title":466,"path":467,"stem":468,"icon":469},"Query API","/lumen/query-api","15.lumen/7.query-api","i-lucide-search",{"title":471,"path":472,"stem":473,"children":474,"icon":476},"SDKs","/sdks","16.sdks/1.index",[475,477,482,487],{"title":471,"path":472,"stem":473,"icon":476},"i-lucide-code",{"title":478,"path":479,"stem":480,"icon":481},"Workflows SDK — Node / TypeScript","/sdks/workflows-nodejs","16.sdks/2.workflows-nodejs","i-lucide-file-ts",{"title":483,"path":484,"stem":485,"icon":486},"Workflows SDK — Python","/sdks/workflows-python","16.sdks/3.workflows-python","i-simple-icons-python",{"title":488,"path":489,"stem":490,"icon":417},"Auth SDK — Sign in with Orkestia","/sdks/auth","16.sdks/4.auth",{"title":92,"path":492,"stem":493,"children":494,"icon":95},"/appdata","17.appdata/1.index",[495,496,501,506,510,515,520,525,530],{"title":92,"path":492,"stem":493,"icon":95},{"title":497,"path":498,"stem":499,"icon":500},"Declare structures","/appdata/declare","17.appdata/2.declare","i-lucide-table",{"title":502,"path":503,"stem":504,"icon":505},"Records & Data API","/appdata/data-api","17.appdata/3.data-api","i-lucide-rows-3",{"title":507,"path":508,"stem":509,"icon":376},"Ownership & workspaces","/appdata/ownership","17.appdata/4.ownership",{"title":511,"path":512,"stem":513,"icon":514},"Expose App Data to end-users","/appdata/expose","17.appdata/5.expose","i-lucide-app-window",{"title":516,"path":517,"stem":518,"icon":519},"PostgREST HTTP","/appdata/postgrest","17.appdata/6.postgrest","i-lucide-unplug",{"title":521,"path":522,"stem":523,"icon":524},"Ordered append","/appdata/append","17.appdata/7.append","i-lucide-list-ordered",{"title":526,"path":527,"stem":528,"icon":529},"Databases and instances","/appdata/instances","17.appdata/8.instances","i-lucide-hard-drive",{"title":531,"path":532,"stem":533,"icon":104},"Query console and SQL","/appdata/query","17.appdata/9.query",{"title":97,"path":535,"stem":536,"children":537,"icon":61},"/engram","18.engram/1.index",[538,539,543],{"title":97,"path":535,"stem":536,"icon":61},{"title":540,"path":541,"stem":542,"icon":155},"Write & recall","/engram/write-recall","18.engram/2.write-recall",{"title":544,"path":545,"stem":546,"icon":547},"Field & feed","/engram/agent-memory","18.engram/3.agent-memory","i-lucide-radio",{"title":101,"path":549,"stem":550,"children":551,"icon":104},"/devkit","19.devkit/1.index",[552,553,558,562,567],{"title":101,"path":549,"stem":550,"icon":104},{"title":554,"path":555,"stem":556,"icon":557},"Install DevKit","/devkit/install","19.devkit/2.install","i-lucide-download",{"title":559,"path":560,"stem":561,"icon":519},"Hook redirect","/devkit/hooks","19.devkit/3.hooks",{"title":563,"path":564,"stem":565,"icon":566},"Local coding runner","/devkit/local-runner","19.devkit/4.local-runner","i-lucide-cpu",{"title":568,"path":569,"stem":570,"icon":131},"Compositions from DevKit","/devkit/compositions","19.devkit/5.compositions",{"title":572,"path":573,"stem":574,"children":575,"icon":44},"Staff & Agents","/staff-and-agents","20.staff-and-agents/01.index",[576,577,582,586,590,594,598,602,606,611,615,620,625,629],{"title":572,"path":573,"stem":574,"icon":44},{"title":578,"path":579,"stem":580,"icon":581},"Prerequisites","/staff-and-agents/prerequisites","20.staff-and-agents/02.prerequisites","i-lucide-list-checks",{"title":583,"path":584,"stem":585,"icon":368},"Hire an actor","/staff-and-agents/hire-an-actor","20.staff-and-agents/03.hire-an-actor",{"title":587,"path":588,"stem":589,"icon":34},"Console","/staff-and-agents/console","20.staff-and-agents/04.console",{"title":591,"path":592,"stem":593,"icon":11},"Configs, skills, and MCP","/staff-and-agents/configs-skills-mcp","20.staff-and-agents/05.configs-skills-mcp",{"title":595,"path":596,"stem":597,"icon":136},"Agent runner groups","/staff-and-agents/runner-groups","20.staff-and-agents/06.runner-groups",{"title":599,"path":600,"stem":601,"icon":16},"Governance","/staff-and-agents/governance","20.staff-and-agents/07.governance",{"title":603,"path":604,"stem":605,"icon":417},"Identity and tokens","/staff-and-agents/identity","20.staff-and-agents/08.identity",{"title":607,"path":608,"stem":609,"icon":610},"Memory and cost","/staff-and-agents/memory-and-cost","20.staff-and-agents/09.memory-and-cost","i-lucide-wallet",{"title":612,"path":613,"stem":614,"icon":155},"Coding agents","/staff-and-agents/coding-agents","20.staff-and-agents/10.coding-agents",{"title":616,"path":617,"stem":618,"icon":619},"Wire a repository for coding agents","/staff-and-agents/wire-a-repository","20.staff-and-agents/11.wire-a-repository","i-lucide-link",{"title":621,"path":622,"stem":623,"icon":624},"Run a ticket end to end","/staff-and-agents/run-a-ticket","20.staff-and-agents/12.run-a-ticket","i-lucide-play",{"title":626,"path":627,"stem":628,"icon":66},"Build a product team of actors","/staff-and-agents/build-a-product-team","20.staff-and-agents/13.build-a-product-team",{"title":261,"path":630,"stem":631,"icon":249},"/staff-and-agents/troubleshooting","20.staff-and-agents/14.troubleshooting",{"title":106,"path":633,"stem":634,"children":635,"icon":109},"/app-host","21.app-host/1.index",[636,637,641,644,649,653,658,662,666],{"title":106,"path":633,"stem":634,"icon":109},{"title":638,"path":639,"stem":640,"icon":514},"Your app and site","/app-host/your-app","21.app-host/2.your-app",{"title":92,"path":642,"stem":643,"icon":95},"/app-host/app-data","21.app-host/3.app-data",{"title":645,"path":646,"stem":647,"icon":648},"Website and process","/app-host/hosting","21.app-host/4.hosting","i-lucide-cloud-upload",{"title":650,"path":651,"stem":652,"icon":547},"Buzz","/app-host/buzz","21.app-host/5.buzz",{"title":654,"path":655,"stem":656,"icon":657},"Files","/app-host/files","21.app-host/6.files","i-lucide-folder",{"title":659,"path":660,"stem":661,"icon":109},"Your own domain","/app-host/your-domain","21.app-host/7.your-domain",{"title":663,"path":664,"stem":665,"icon":229},"Troubleshooting App Host","/app-host/troubleshooting","21.app-host/8.troubleshooting",{"title":667,"path":668,"stem":669,"icon":417},"Signing keys","/app-host/signing-keys","21.app-host/9.signing-keys",{"title":111,"path":671,"stem":672,"children":673,"icon":114},"/agent-exchange","22.agent-exchange/01.index",[674,675,678,682,686,690],{"title":111,"path":671,"stem":672,"icon":114},{"title":583,"path":676,"stem":677,"icon":368},"/agent-exchange/hire","22.agent-exchange/02.hire",{"title":679,"path":680,"stem":681,"icon":208},"List an actor","/agent-exchange/list","22.agent-exchange/03.list",{"title":683,"path":684,"stem":685,"icon":104},"Invoke & leases","/agent-exchange/invoke","22.agent-exchange/04.invoke",{"title":687,"path":688,"stem":689,"icon":141},"Settlement & trust","/agent-exchange/settlement","22.agent-exchange/05.settlement",{"title":53,"path":691,"stem":692,"icon":56},"/agent-exchange/workflows","22.agent-exchange/06.workflows",{"title":694,"path":695,"stem":696,"children":697,"icon":75},"Runners","/runners","23.runners/1.index",[698,700,704,709,713,717,721,726,730,734,738,741,745,749,753],{"title":699,"path":695,"stem":696,"icon":75},"Runner groups",{"title":701,"path":702,"stem":703,"icon":275},"Cloud Run","/runners/cloud-run","23.runners/10.cloud-run",{"title":705,"path":706,"stem":707,"icon":708},"DigitalOcean App Job","/runners/do-app-job","23.runners/11.do-app-job","i-simple-icons-digitalocean",{"title":710,"path":711,"stem":712,"icon":708},"DigitalOcean Droplet","/runners/do-droplet","23.runners/12.do-droplet",{"title":714,"path":715,"stem":716,"icon":285},"Magalu Cloud VM","/runners/magalu-vm","23.runners/13.magalu-vm",{"title":101,"path":718,"stem":719,"icon":720},"/runners/devkit","23.runners/14.devkit","i-lucide-laptop",{"title":722,"path":723,"stem":724,"icon":725},"Purposes & integrations","/runners/purposes","23.runners/16.purposes","i-lucide-layers",{"title":727,"path":728,"stem":729,"icon":241},"Fargate","/runners/fargate","23.runners/2.fargate",{"title":731,"path":732,"stem":733,"icon":241},"EC2 Auto Scaling","/runners/ec2-auto-scaling","23.runners/3.ec2-auto-scaling",{"title":735,"path":736,"stem":737,"icon":241},"EC2 VM","/runners/ec2-vm","23.runners/4.ec2-vm",{"title":287,"path":739,"stem":740,"icon":290},"/runners/kubernetes","23.runners/5.kubernetes",{"title":742,"path":743,"stem":744,"icon":280},"Azure Container Apps","/runners/azure-container-apps","23.runners/6.azure-container-apps",{"title":746,"path":747,"stem":748,"icon":280},"Azure VMSS","/runners/azure-vmss","23.runners/7.azure-vmss",{"title":750,"path":751,"stem":752,"icon":280},"Azure VM","/runners/azure-vm","23.runners/8.azure-vm",{"title":754,"path":755,"stem":756,"icon":275},"GCE","/runners/gce","23.runners/9.gce",{"title":758,"path":759,"stem":760,"children":761,"icon":763},"Chat","/chat","24.chat/01.index",[762,764,768,773,777,782,787,791,796,800,805,810,814,819,824,828,832,836,840,845],{"title":758,"path":759,"stem":760,"icon":763},"i-lucide-messages-square",{"title":765,"path":766,"stem":767,"icon":446},"Enable and publish","/chat/enable-and-publish","24.chat/02.enable-and-publish",{"title":769,"path":770,"stem":771,"icon":772},"Theme and customization","/chat/theme-and-customization","24.chat/03.theme-and-customization","i-lucide-palette",{"title":774,"path":775,"stem":776,"icon":85},"Members and moderation","/chat/members-and-moderation","24.chat/04.members-and-moderation",{"title":778,"path":779,"stem":780,"icon":781},"Channels","/chat/channels","24.chat/05.channels","i-lucide-hash",{"title":783,"path":784,"stem":785,"icon":786},"Using the chat","/chat/using-the-chat","24.chat/06.using-the-chat","i-lucide-message-circle",{"title":788,"path":789,"stem":790,"icon":44},"Actors in chat","/chat/actors-in-chat","24.chat/07.actors-in-chat",{"title":792,"path":793,"stem":794,"icon":795},"Internal support actor","/chat/internal-support-actor","24.chat/08.internal-support-actor","i-lucide-life-buoy",{"title":797,"path":798,"stem":799,"icon":104},"API and console","/chat/api-and-console","24.chat/09.api-and-console",{"title":801,"path":802,"stem":803,"icon":804},"Limits","/chat/limits","24.chat/10.limits","i-lucide-triangle-alert",{"title":806,"path":807,"stem":808,"icon":809},"Structured chat with DGI","/chat/structured-chat","24.chat/11.structured-chat","i-lucide-layout-list",{"title":811,"path":812,"stem":813,"icon":109},"Option A: hosted chat with DGI","/chat/option-a-hosted-chat","24.chat/12.option-a-hosted-chat",{"title":815,"path":816,"stem":817,"icon":818},"Option B: embed the chat component","/chat/option-b-embed-component","24.chat/13.option-b-embed-component","i-lucide-component",{"title":820,"path":821,"stem":822,"icon":823},"Option C: custom client (wire contract)","/chat/option-c-custom-client","24.chat/14.option-c-custom-client","i-lucide-braces",{"title":825,"path":826,"stem":827,"icon":394},"Responder configuration reference","/chat/responder-reference","24.chat/15.responder-reference",{"title":829,"path":830,"stem":831,"icon":547},"Cards, live updates and proactive posts","/chat/cards-live-and-proactive","24.chat/16.cards-live-and-proactive",{"title":833,"path":834,"stem":835,"icon":16},"Structured chat security model","/chat/structured-chat-security","24.chat/17.structured-chat-security",{"title":837,"path":838,"stem":839,"icon":181},"Option D: any app or API (dgi.chat)","/chat/option-d-chat-api","24.chat/18.option-d-chat-api",{"title":841,"path":842,"stem":843,"icon":844},"Card catalog","/chat/card-catalog","24.chat/19.card-catalog","i-lucide-layout-grid",{"title":846,"path":847,"stem":848,"icon":849},"Living Surfaces","/chat/living-surfaces","24.chat/20.living-surfaces","i-lucide-sprout",{"title":851,"path":852,"stem":853,"children":854,"icon":61},"DGI","/dgi","25.dgi/1.index",[855,857,862,866,870,874],{"title":856,"path":852,"stem":853,"icon":61},"What is DGI",{"title":858,"path":859,"stem":860,"icon":861},"How DGI works","/dgi/how-it-works","25.dgi/2.how-it-works","i-lucide-cog",{"title":863,"path":864,"stem":865,"icon":844},"Interfaces","/dgi/interfaces","25.dgi/3.interfaces",{"title":867,"path":868,"stem":869,"icon":29},"Quickstart","/dgi/quickstart","25.dgi/4.quickstart",{"title":871,"path":872,"stem":873,"icon":16},"Trust and safety","/dgi/trust-and-safety","25.dgi/5.trust-and-safety",{"title":875,"path":876,"stem":877,"icon":878},"FAQ","/dgi/faq","25.dgi/6.faq","i-lucide-circle-help",{"id":880,"title":63,"body":881,"description":1774,"extension":1775,"links":1776,"meta":1777,"navigation":1778,"path":64,"seo":1779,"stem":65,"__hash__":1780},"docs/03.concepts/04.staff-governance.md",{"type":882,"value":883,"toc":1761},"minimark",[884,889,954,966,986,990,1001,1066,1080,1084,1103,1108,1137,1165,1169,1180,1267,1270,1285,1303,1307,1326,1418,1425,1429,1437,1531,1546,1550,1560,1617,1620,1624,1633,1637,1704,1708,1739,1743,1757],[885,886,888],"h2",{"id":887},"tldr","TL;DR",[890,891,892,900,911,917,927],"ul",{},[893,894,895,899],"li",{},[896,897,898],"strong",{},"A fleet of agents is an organization."," Staff gives it an org chart (units, actors), role-based permissions, approval gates, and an immutable audit trail.",[893,901,902,905,906,910],{},[896,903,904],{},"Authorization lives in the engine, not the UI."," Workflows declare ",[907,908,909],"code",{},"Capability"," metadata. The engine's guard checks it before the first step runs, no matter which door the call came through: console, SDK, or an assistant over MCP.",[893,912,913,916],{},[896,914,915],{},"Approvals make \"AI proposes\" vs \"AI acts\" explicit."," Sensitive workflows park in a pending-approval state and surface in an operator inbox.",[893,918,919,922,923,926],{},[896,920,921],{},"Everything is auditable."," Every actor action is a workflow run. The ",[907,924,925],{},"audit.*"," family queries the transition log.",[893,928,929,932,933,940,941,943,944,948,949,953],{},[896,930,931],{},"Operate it at"," ",[934,935,939],"a",{"href":936,"rel":937},"https://staff.orkestia.dev",[938],"nofollow","staff.orkestia.dev",". Model here, operator path in ",[934,942,572],{"href":573},". Selling or hiring an actor ",[945,946,947],"em",{},"across organizations"," is ",[896,950,951],{},[934,952,111],{"href":671}," — a different console and a different \"hire\".",[955,956,957,958,961,962,965],"p",{},"A single AI agent is a tool. A fleet of agents that can read connections, launch sessions on your runners, and start workflows in your cloud is an ",[945,959,960],{},"organization",". Organizations need structure, permissions, and oversight. ",[896,963,964],{},"Staff"," is that layer.",[967,968,969],"note",{},[955,970,971,972,975,976,979,980,979,983,985],{},"Staff is in ",[896,973,974],{},"beta",". The substrate (",[907,977,978],{},"agents.*",", ",[907,981,982],{},"staff.*",[907,984,925],{}," workflow families) is live and RBAC is enforced in the engine. Some operator-console surfaces are still being normalized.",[885,987,989],{"id":988},"why-governance-for-autonomous-ai","Why governance for autonomous AI",[955,991,992,993,996,997,1000],{},"The point of an AI workforce is that it acts without a human in the loop for every step. That is also the danger. An agent connected over ",[934,994,995],{"href":42},"MCP"," that can ",[934,998,999],{"href":54},"start workflows"," in your accounts has real reach, and the failure surface compounds with every agent you add.",[1002,1003,1004,1020],"table",{},[1005,1006,1007],"thead",{},[1008,1009,1010,1014,1017],"tr",{},[1011,1012,1013],"th",{},"Problem",[1011,1015,1016],{},"Without governance",[1011,1018,1019],{},"With Staff",[1021,1022,1023,1037,1050],"tbody",{},[1008,1024,1025,1031,1034],{},[1026,1027,1028],"td",{},[896,1029,1030],{},"Authority sprawl",[1026,1032,1033],{},"Every agent can do everything",[1026,1035,1036],{},"Role bindings scope each actor; the engine denies anything not granted",[1008,1038,1039,1044,1047],{},[1026,1040,1041],{},[896,1042,1043],{},"Unsupervised side effects",[1026,1045,1046],{},"An agent mutates production because nothing stopped it",[1026,1048,1049],{},"Approval gates on sensitive capabilities",[1008,1051,1052,1057,1060],{},[1026,1053,1054],{},[896,1055,1056],{},"No accountability",[1026,1058,1059],{},"Something happened; nobody can prove who or when",[1026,1061,1062,1063,1065],{},"Every action is a run in the transition log; ",[907,1064,925],{}," makes it queryable",[1067,1068,1069],"tip",{},[955,1070,1071,1072,1075,1076,1079],{},"Staff is built on Zero Code Custody. Agents execute in ",[945,1073,1074],{},"your"," cloud through ",[934,1077,1078],{"href":73},"runners",". Governance is enforced at the orchestration layer, so guardrails hold regardless of where execution physically runs.",[885,1081,1083],{"id":1082},"the-model-actors-in-an-org-structure","The model: actors in an org structure",[955,1085,1086,1087,979,1090,979,1093,1096,1097,1099,1100,1102],{},"Staff borrows the vocabulary of a real organization. The core entities are ",[907,1088,1089],{},"OrgUnit",[907,1091,1092],{},"Actor",[907,1094,1095],{},"RoleBinding",", and ",[907,1098,909],{},", managed through ",[907,1101,982],{}," workflows.",[1104,1105],"dag-diagram",{":edges":1106,":nodes":1107},"[{\"from\":\"Org\",\"to\":\"U1\"},{\"from\":\"Org\",\"to\":\"U2\"},{\"from\":\"U1\",\"to\":\"A1\"},{\"from\":\"U1\",\"to\":\"A2\"},{\"from\":\"U2\",\"to\":\"A3\"},{\"from\":\"A1\",\"to\":\"R1\",\"label\":\"RoleBinding\",\"dashed\":true},{\"from\":\"A3\",\"to\":\"R2\",\"label\":\"RoleBinding\",\"dashed\":true},{\"from\":\"R1\",\"to\":\"C1\",\"label\":\"grants\",\"dashed\":true},{\"from\":\"R2\",\"to\":\"C2\",\"label\":\"grants\",\"dashed\":true}]","[{\"id\":\"Org\",\"label\":\"Organization\",\"kind\":\"start\"},{\"id\":\"U1\",\"label\":\"OrgUnit: Finance\"},{\"id\":\"U2\",\"label\":\"OrgUnit: Platform\"},{\"id\":\"A1\",\"label\":\"Actor: invoice-agent\",\"kind\":\"ai\"},{\"id\":\"A2\",\"label\":\"Actor: reconciliation-agent\",\"kind\":\"ai\"},{\"id\":\"A3\",\"label\":\"Actor: deploy-agent\",\"kind\":\"ai\"},{\"id\":\"R1\",\"label\":\"Role: finance-operator\"},{\"id\":\"R2\",\"label\":\"Role: infra-operator\"},{\"id\":\"C1\",\"label\":\"Capabilities: bling.*, data.*\"},{\"id\":\"C2\",\"label\":\"Capabilities: kubernetes.*, deploy.*\"}]",[890,1109,1110,1116,1121,1126,1132],{},[893,1111,1112,1115],{},[896,1113,1114],{},"Organization",": the tenant boundary. An actor never sees or acts on another org's state.",[893,1117,1118,1120],{},[896,1119,1089],{},": a team or department. A navigable tree and a natural scope for permissions.",[893,1122,1123,1125],{},[896,1124,1092],{},": an AI worker with a lifecycle (hire, update, pause, resume, archive, invoke) and its own inbox, outbox, and journal.",[893,1127,1128,1131],{},[896,1129,1130],{},"Role and RoleBinding",": a role is a named bundle of capabilities. Binding it to an actor or unit grants them. Effective permissions are the union of bindings.",[893,1133,1134,1136],{},[896,1135,909],{},": the unit of authority. Workflows declare it; RBAC checks it at run time.",[955,1138,1139,1140,1143,1144,1147,1148,1151,1152,979,1155,979,1158,1096,1161,1164],{},"Each actor authenticates to the platform with its own ",[896,1141,1142],{},"agent token"," (",[907,1145,1146],{},"agt_…","). Over MCP, ",[907,1149,1150],{},"whoami"," on an agent token returns ",[907,1153,1154],{},"agent_uuid",[907,1156,1157],{},"staff_actor_uuid",[907,1159,1160],{},"permission_mode",[907,1162,1163],{},"seat_mode",", so the server knows exactly which actor is calling.",[885,1166,1168],{"id":1167},"roles-capabilities-and-enforcement","Roles, capabilities, and enforcement",[955,1170,1171,1172,1175,1176,1179],{},"Staff's central design choice: ",[896,1173,1174],{},"authorization is in the engine",". When any caller tries to start a workflow, the engine checks the caller's effective roles against the workflow's required capability ",[945,1177,1178],{},"before the first step runs",". A denied attempt never executes and is itself recorded.",[1181,1182,1187],"pre",{"className":1183,"code":1184,"language":1185,"meta":1186,"style":1186},"language-json shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","{\n  \"workflow_type\": \"finance.invoice.cancel\",\n  \"capability\": \"finance.invoice.cancel\",\n  \"requires_approval\": true\n}\n","json","",[907,1188,1189,1198,1226,1246,1261],{"__ignoreMap":1186},[1190,1191,1194],"span",{"class":1192,"line":1193},"line",1,[1190,1195,1197],{"class":1196},"sMK4o","{\n",[1190,1199,1201,1204,1208,1211,1214,1217,1221,1223],{"class":1192,"line":1200},2,[1190,1202,1203],{"class":1196},"  \"",[1190,1205,1207],{"class":1206},"spNyl","workflow_type",[1190,1209,1210],{"class":1196},"\"",[1190,1212,1213],{"class":1196},":",[1190,1215,1216],{"class":1196}," \"",[1190,1218,1220],{"class":1219},"sfazB","finance.invoice.cancel",[1190,1222,1210],{"class":1196},[1190,1224,1225],{"class":1196},",\n",[1190,1227,1229,1231,1234,1236,1238,1240,1242,1244],{"class":1192,"line":1228},3,[1190,1230,1203],{"class":1196},[1190,1232,1233],{"class":1206},"capability",[1190,1235,1210],{"class":1196},[1190,1237,1213],{"class":1196},[1190,1239,1216],{"class":1196},[1190,1241,1220],{"class":1219},[1190,1243,1210],{"class":1196},[1190,1245,1225],{"class":1196},[1190,1247,1249,1251,1254,1256,1258],{"class":1192,"line":1248},4,[1190,1250,1203],{"class":1196},[1190,1252,1253],{"class":1206},"requires_approval",[1190,1255,1210],{"class":1196},[1190,1257,1213],{"class":1196},[1190,1259,1260],{"class":1196}," true\n",[1190,1262,1264],{"class":1192,"line":1263},5,[1190,1265,1266],{"class":1196},"}\n",[955,1268,1269],{},"Two consequences:",[1271,1272,1273,1279],"ol",{},[893,1274,1275,1278],{},[896,1276,1277],{},"No back door."," Console, REST, SDK, or an assistant over MCP all funnel through the same engine and the same guard.",[893,1280,1281,1284],{},[896,1282,1283],{},"What an agent may do is data, not code."," Granting or revoking authority is a role-binding change, visible in audit, not a redeploy.",[1286,1287,1288],"warning",{},[955,1289,1290,1291,1294,1295,1298,1299,1302],{},"Scope roles tightly. Bind each actor only to the capability prefixes its job needs (a finance actor gets ",[907,1292,1293],{},"finance.*"," and ",[907,1296,1297],{},"data.*",", never ",[907,1300,1301],{},"kubernetes.*","). Broad bindings undermine the model.",[885,1304,1306],{"id":1305},"human-in-the-loop-approval-gates","Human-in-the-loop approval gates",[955,1308,1309,1310,1313,1314,1317,1318,1321,1322,1325],{},"RBAC decides ",[945,1311,1312],{},"whether"," an actor may attempt a capability. Approval gates decide ",[945,1315,1316],{},"whether a specific attempt proceeds",". A sensitive workflow parks in a ",[896,1319,1320],{},"pending-approval"," state and surfaces in the operator ",[896,1323,1324],{},"inbox",". A human reviews the proposed action and its inputs, then approves or rejects.",[1181,1327,1331],{"className":1328,"code":1329,"language":1330,"meta":1186,"style":1186},"language-mermaid shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","sequenceDiagram\n  participant Agent\n  participant Engine as Workflow engine\n  participant Inbox as Operator inbox\n  participant Human\n  Agent->>Engine: start_workflow(finance.invoice.cancel)\n  Engine->>Engine: RBAC: capability granted?\n  Engine->>Inbox: requires_approval → pending\n  Inbox->>Human: item needing attention\n  Human-->>Engine: approve / reject\n  alt approved\n    Engine->>Engine: execute effectful steps\n  else rejected\n    Engine->>Engine: terminate (no side effect)\n  end\n","mermaid",[907,1332,1333,1338,1343,1348,1353,1358,1364,1370,1376,1382,1388,1394,1400,1406,1412],{"__ignoreMap":1186},[1190,1334,1335],{"class":1192,"line":1193},[1190,1336,1337],{},"sequenceDiagram\n",[1190,1339,1340],{"class":1192,"line":1200},[1190,1341,1342],{},"  participant Agent\n",[1190,1344,1345],{"class":1192,"line":1228},[1190,1346,1347],{},"  participant Engine as Workflow engine\n",[1190,1349,1350],{"class":1192,"line":1248},[1190,1351,1352],{},"  participant Inbox as Operator inbox\n",[1190,1354,1355],{"class":1192,"line":1263},[1190,1356,1357],{},"  participant Human\n",[1190,1359,1361],{"class":1192,"line":1360},6,[1190,1362,1363],{},"  Agent->>Engine: start_workflow(finance.invoice.cancel)\n",[1190,1365,1367],{"class":1192,"line":1366},7,[1190,1368,1369],{},"  Engine->>Engine: RBAC: capability granted?\n",[1190,1371,1373],{"class":1192,"line":1372},8,[1190,1374,1375],{},"  Engine->>Inbox: requires_approval → pending\n",[1190,1377,1379],{"class":1192,"line":1378},9,[1190,1380,1381],{},"  Inbox->>Human: item needing attention\n",[1190,1383,1385],{"class":1192,"line":1384},10,[1190,1386,1387],{},"  Human-->>Engine: approve / reject\n",[1190,1389,1391],{"class":1192,"line":1390},11,[1190,1392,1393],{},"  alt approved\n",[1190,1395,1397],{"class":1192,"line":1396},12,[1190,1398,1399],{},"    Engine->>Engine: execute effectful steps\n",[1190,1401,1403],{"class":1192,"line":1402},13,[1190,1404,1405],{},"  else rejected\n",[1190,1407,1409],{"class":1192,"line":1408},14,[1190,1410,1411],{},"    Engine->>Engine: terminate (no side effect)\n",[1190,1413,1415],{"class":1192,"line":1414},15,[1190,1416,1417],{},"  end\n",[955,1419,1420,1421,1424],{},"This is the mechanism behind graduated autonomy: start a new agent with approvals on everything, then relax gates as you gain confidence. The same discipline shows up at the MCP level, where the server tells assistants that creates and mutations should be confirmed with the user first. Configuration: ",[934,1422,1423],{"href":206},"Governance & approvals",".",[885,1426,1428],{"id":1427},"the-staff-console","The Staff console",[955,1430,1431,1432,1434,1435,1424],{},"The console at ",[907,1433,939],{}," is the operator-first surface. Day to day: ",[934,1436,572],{"href":573},[1002,1438,1439,1449],{},[1005,1440,1441],{},[1008,1442,1443,1446],{},[1011,1444,1445],{},"Surface",[1011,1447,1448],{},"What it is for",[1021,1450,1451,1461,1471,1481,1491,1501,1511,1521],{},[1008,1452,1453,1458],{},[1026,1454,1455],{},[896,1456,1457],{},"Inbox",[1026,1459,1460],{},"Approval requests and items needing a human decision",[1008,1462,1463,1468],{},[1026,1464,1465],{},[896,1466,1467],{},"Activity",[1026,1469,1470],{},"Live, org-scoped stream of what the fleet is doing",[1008,1472,1473,1478],{},[1026,1474,1475],{},[896,1476,1477],{},"Staff tree",[1026,1479,1480],{},"Navigate org, unit, actor",[1008,1482,1483,1488],{},[1026,1484,1485],{},[896,1486,1487],{},"Actor detail",[1026,1489,1490],{},"State, inbox, outbox, journal; hire, pause, resume, archive, invoke",[1008,1492,1493,1498],{},[1026,1494,1495],{},[896,1496,1497],{},"Roles & bindings",[1026,1499,1500],{},"Effective roles; grant and revoke capability bindings",[1008,1502,1503,1508],{},[1026,1504,1505],{},[896,1506,1507],{},"Agent operations",[1026,1509,1510],{},"Sessions, configs, skills, MCP servers, runner groups",[1008,1512,1513,1518],{},[1026,1514,1515],{},[896,1516,1517],{},"Cost & pricing",[1026,1519,1520],{},"Spend analytics, model pricing, budgets",[1008,1522,1523,1528],{},[1026,1524,1525],{},[896,1526,1527],{},"Audit",[1026,1529,1530],{},"Run history and exportable evidence",[955,1532,1533,1534,1143,1537,979,1539,1541,1542,1545],{},"The console does not mutate state directly. Operator actions ",[896,1535,1536],{},"start named workflows",[907,1538,982],{},[907,1540,978],{},", read-only ",[907,1543,1544],{},"data.agents.*","), so every operator action is itself a governed, recorded run.",[885,1547,1549],{"id":1548},"accountability-everything-is-auditable","Accountability: everything is auditable",[955,1551,1552,1553,1556,1557,1559],{},"Because every Staff and agent action is a workflow run, the engine's ",[896,1554,1555],{},"transition log"," is already a complete record. The ",[907,1558,925],{}," family exposes it as a typed, read-only, org-scoped query surface.",[1002,1561,1562,1571],{},[1005,1563,1564],{},[1008,1565,1566,1568],{},[1011,1567,909],{},[1011,1569,1570],{},"What it answers",[1021,1572,1573,1583,1591,1601,1609],{},[1008,1574,1575,1580],{},[1026,1576,1577],{},[907,1578,1579],{},"audit.workflow-run.query",[1026,1581,1582],{},"\"What ran for my org?\" Paginated; filter by type prefix, state, status, actor, time range",[1008,1584,1585,1588],{},[1026,1586,1587],{},"Run history",[1026,1589,1590],{},"\"What exactly happened in this run?\" The full transition log",[1008,1592,1593,1598],{},[1026,1594,1595],{},[907,1596,1597],{},"audit.workflow-run.aggregate",[1026,1599,1600],{},"\"How much of each type ran, and when last?\"",[1008,1602,1603,1606],{},[1026,1604,1605],{},"Health scan",[1026,1607,1608],{},"\"Is anything stuck or unhealthy?\"",[1008,1610,1611,1614],{},[1026,1612,1613],{},"Evidence pack",[1026,1615,1616],{},"A bundled, exportable artifact composed from the queries above",[955,1618,1619],{},"Denied RBAC attempts and approval decisions land in the same log. Over-reach and human sign-off are part of the evidence trail, not separate systems.",[885,1621,1623],{"id":1622},"ask-your-ai-assistant","Ask your AI assistant",[1181,1625,1631],{"className":1626,"code":1628,"filename":1629,"language":1630,"meta":1186},[1627],"language-text","List the Staff actors in my organization with their unit and role bindings. Flag any actor bound to kubernetes.* or deploy.* capabilities.\n\nShow me what is waiting in the operator inbox and summarise each pending approval.\n\nRun audit.workflow-run.query for the \"finance.\" prefix over the last 7 days and group the results by actor.\n\nHire a new actor called \"release-notes-writer\" in the Platform unit with a read-only role. Show me the plan before you start anything.\n","prompts","text",[907,1632,1628],{"__ignoreMap":1186},[885,1634,1636],{"id":1635},"for-ai-agents","For AI agents",[1002,1638,1639,1649],{},[1005,1640,1641],{},[1008,1642,1643,1646],{},[1011,1644,1645],{},"Rule",[1011,1647,1648],{},"Detail",[1021,1650,1651,1665,1673,1681,1693],{},[1008,1652,1653,1656],{},[1026,1654,1655],{},"Know who you are",[1026,1657,1658,1151,1660,1294,1662,1664],{},[907,1659,1150],{},[907,1661,1157],{},[907,1663,1160],{},". Act within that identity.",[1008,1666,1667,1670],{},[1026,1668,1669],{},"Expect denials",[1026,1671,1672],{},"A start rejected by RBAC is final. Report it; do not look for another door.",[1008,1674,1675,1678],{},[1026,1676,1677],{},"Expect gates",[1026,1679,1680],{},"A run parked pending approval is not a failure. Report the pending state and stop.",[1008,1682,1683,1686],{},[1026,1684,1685],{},"Reads are safe",[1026,1687,1688,1294,1690,1692],{},[907,1689,1544],{},[907,1691,925],{}," are read-only and safe to start.",[1008,1694,1695,1698],{},[1026,1696,1697],{},"Evidence",[1026,1699,1700,1701,1703],{},"Use ",[907,1702,1579],{}," to see what actually ran, including virtual and scheduled runs.",[885,1705,1707],{"id":1706},"how-staff-fits-the-rest-of-orkestia","How Staff fits the rest of Orkestia",[1709,1710,1711,1718,1723,1728,1733],"card-group",{},[1712,1713,1715],"card",{"icon":44,"title":1714,"to":69},"Agents substrate",[955,1716,1717],{},"Configs, skills, MCP servers, memory, budgets, sessions behind each actor.",[1712,1719,1720],{"icon":114,"title":111,"to":112},[955,1721,1722],{},"List those actors, or hire one another org published. Ledger, not funds.",[1712,1724,1725],{"icon":56,"title":53,"to":54},[955,1726,1727],{},"Actors act by starting governed runs, the unit RBAC and approvals are enforced on.",[1712,1729,1730],{"icon":136,"title":694,"to":73},[955,1731,1732],{},"Agent sessions launch onto runner capacity in your own cloud.",[1712,1734,1736],{"icon":417,"title":1735,"to":83},"Identity & multi-tenancy",[955,1737,1738],{},"Org boundaries that scope every actor, role, and audit query.",[885,1740,1742],{"id":1741},"next-steps","Next steps",[1709,1744,1745,1751],{},[1712,1746,1748],{"icon":34,"title":1747,"to":573},"Manage the fleet",[955,1749,1750],{},"Hire, invoke, runner groups, tokens, troubleshooting.",[1712,1752,1754],{"icon":16,"title":1753,"to":206},"Configure approvals",[955,1755,1756],{},"Wire human-in-the-loop gates and graduate autonomy.",[1758,1759,1760],"style",{},"html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html pre.shiki code .sMK4o, html code.shiki .sMK4o{--shiki-light:#39ADB5;--shiki-default:#89DDFF;--shiki-dark:#89DDFF}html pre.shiki code .spNyl, html code.shiki .spNyl{--shiki-light:#9C3EDA;--shiki-default:#C792EA;--shiki-dark:#C792EA}html pre.shiki code .sfazB, html code.shiki .sfazB{--shiki-light:#91B859;--shiki-default:#C3E88D;--shiki-dark:#C3E88D}",{"title":1186,"searchDepth":1193,"depth":1200,"links":1762},[1763,1764,1765,1766,1767,1768,1769,1770,1771,1772,1773],{"id":887,"depth":1200,"text":888},{"id":988,"depth":1200,"text":989},{"id":1082,"depth":1200,"text":1083},{"id":1167,"depth":1200,"text":1168},{"id":1305,"depth":1200,"text":1306},{"id":1427,"depth":1200,"text":1428},{"id":1548,"depth":1200,"text":1549},{"id":1622,"depth":1200,"text":1623},{"id":1635,"depth":1200,"text":1636},{"id":1706,"depth":1200,"text":1707},{"id":1741,"depth":1200,"text":1742},"How Orkestia Staff turns a fleet of autonomous AI agents into a scoped, auditable organization with roles, approval gates, and human-in-the-loop oversight, enforced inside the workflow engine","md",null,{},{"icon":66},{"title":63,"description":1774},"SAmJxzdzyyUhv3zDn-t60PBrMAcUA6zBEBaNMg9CbY8",[1782,1784],{"title":58,"path":59,"stem":60,"description":1783,"icon":61,"children":-1},"How Orkestia turns a natural-language goal into a typed, executable workflow plan, how that plan compiles into a reusable deterministic composition, and how DGI relates to assistants over MCP",{"title":68,"path":69,"stem":70,"description":1785,"icon":44,"children":-1},"The primitives behind every AI worker on Orkestia, agent configs, workflow-backed skills, per-agent MCP servers, sessions on your runners, memory, budgets, and end-user agents",1790354043698]