[{"data":1,"prerenderedAt":2172},["ShallowReactive",2],{"navigation":3,"/guides/security-and-compliance":879,"/guides/security-and-compliance-surround":2167},[4,22,45,115,156,187,214,235,264,295,318,361,389,418,436,470,491,534,548,571,632,670,693,757,850],{"title":5,"path":6,"stem":7,"children":8,"icon":11},"Introduction","/introduction","01.introduction/1.index",[9,12,17],{"title":10,"path":6,"stem":7,"icon":11},"What is Orkestia?","i-lucide-sparkles",{"title":13,"path":14,"stem":15,"icon":16},"Core Philosophy","/introduction/core-philosophy","01.introduction/2.core-philosophy","i-lucide-shield-check",{"title":18,"path":19,"stem":20,"icon":21},"Key Benefits","/introduction/key-benefits","01.introduction/3.key-benefits","i-lucide-trophy",{"title":23,"path":24,"stem":25,"children":26,"icon":29},"Getting Started","/getting-started","02.getting-started/1.index",[27,30,35,40],{"title":28,"path":24,"stem":25,"icon":29},"Quick Start","i-lucide-rocket",{"title":31,"path":32,"stem":33,"icon":34},"Architecture Overview","/getting-started/architecture-overview","02.getting-started/2.architecture-overview","i-lucide-layout-dashboard",{"title":36,"path":37,"stem":38,"icon":39},"Concepts at a Glance","/getting-started/concepts","02.getting-started/3.concepts","i-lucide-list",{"title":41,"path":42,"stem":43,"icon":44},"Connect an AI Assistant","/getting-started/connect-an-ai-assistant","02.getting-started/4.connect-an-ai-assistant","i-lucide-bot",{"title":46,"path":47,"stem":48,"children":49,"icon":51},"Core Concepts","/concepts","03.concepts/01.index",[50,52,57,62,67,71,76,81,86,91,96,100,105,110],{"title":46,"path":47,"stem":48,"icon":51},"i-lucide-book-open",{"title":53,"path":54,"stem":55,"icon":56},"Workflows","/concepts/workflows","03.concepts/02.workflows","i-lucide-workflow",{"title":58,"path":59,"stem":60,"icon":61},"DGI — Dialog Generative Interface","/concepts/dgi","03.concepts/03.dgi","i-lucide-brain",{"title":63,"path":64,"stem":65,"icon":66},"Staff & AI Workforce Governance","/concepts/staff-governance","03.concepts/04.staff-governance","i-lucide-users-round",{"title":68,"path":69,"stem":70,"icon":44},"Agents — the execution substrate","/concepts/agents-platform","03.concepts/05.agents-platform",{"title":72,"path":73,"stem":74,"icon":75},"Runners & Execution Environments","/concepts/runners","03.concepts/06.runners","i-lucide-server-cog",{"title":77,"path":78,"stem":79,"icon":80},"Lumen Observability","/concepts/lumen","03.concepts/07.lumen","i-lucide-activity",{"title":82,"path":83,"stem":84,"icon":85},"Identity & Multi-Tenancy","/concepts/identity-multi-tenancy","03.concepts/08.identity-multi-tenancy","i-lucide-users",{"title":87,"path":88,"stem":89,"icon":90},"Billing, Pricing & Seats","/concepts/billing-and-seats","03.concepts/09.billing-and-seats","i-lucide-credit-card",{"title":92,"path":93,"stem":94,"icon":95},"App Data","/concepts/appdata","03.concepts/10.appdata","i-lucide-database",{"title":97,"path":98,"stem":99,"icon":61},"Engram","/concepts/engram","03.concepts/11.engram",{"title":101,"path":102,"stem":103,"icon":104},"DevKit","/concepts/devkit","03.concepts/12.devkit","i-lucide-terminal",{"title":106,"path":107,"stem":108,"icon":109},"App Host","/concepts/app-host","03.concepts/13.app-host","i-lucide-globe",{"title":111,"path":112,"stem":113,"icon":114},"Agent Exchange","/concepts/agent-exchange","03.concepts/14.agent-exchange","i-lucide-landmark",{"title":116,"path":117,"stem":118,"children":119,"icon":121},"Guides","/guides","04.guides/1.index",[120,122,127,132,137,142,147,151],{"title":116,"path":117,"stem":118,"icon":121},"i-lucide-compass",{"title":123,"path":124,"stem":125,"icon":126},"Building with DGI","/guides/building-with-dgi","04.guides/2.building-with-dgi","i-lucide-brain-circuit",{"title":128,"path":129,"stem":130,"icon":131},"Creating & Exposing Virtual Workflows","/guides/virtual-workflows","04.guides/4.virtual-workflows","i-lucide-blocks",{"title":133,"path":134,"stem":135,"icon":136},"Runner Management & Provisioning","/guides/runner-management","04.guides/5.runner-management","i-lucide-server",{"title":138,"path":139,"stem":140,"icon":141},"Security & Compliance","/guides/security-and-compliance","04.guides/7.security-and-compliance","i-lucide-shield",{"title":143,"path":144,"stem":145,"icon":146},"Tickets & Software Delivery","/guides/tickets-and-software-delivery","04.guides/8.tickets-and-software-delivery","i-lucide-ticket",{"title":148,"path":149,"stem":150},"Orkestia for AI-driven cloud infrastructure automation","/guides/cloud-automation-alternatives","04.guides/9.cloud-automation-alternatives",{"title":152,"path":153,"stem":154,"icon":155},"Typed decisions with TypeSafe","/guides/typed-decisions-with-typesafe","04.guides/9.typed-decisions-with-typesafe","i-lucide-git-branch",{"title":157,"path":158,"stem":159,"children":160,"icon":162},"Reference","/reference","05.reference/1.index",[161,163,168,173,177,182],{"title":157,"path":158,"stem":159,"icon":162},"i-lucide-library",{"title":164,"path":165,"stem":166,"icon":167},"Workflow Types & Registry","/reference/workflow-types-registry","05.reference/2.workflow-types-registry","i-lucide-list-tree",{"title":169,"path":170,"stem":171,"icon":172},"MCP Integration","/reference/mcp-integration","05.reference/3.mcp-integration","i-lucide-plug-zap",{"title":174,"path":175,"stem":176,"icon":104},"API & Tooling","/reference/api-tooling","05.reference/4.api-tooling",{"title":178,"path":179,"stem":180,"icon":181},"Integrations Catalog","/reference/integrations-catalog","05.reference/6.integrations-catalog","i-lucide-plug",{"title":183,"path":184,"stem":185,"icon":186},"Platform Services","/reference/platform-services","05.reference/7.platform-services","i-lucide-boxes",{"title":188,"path":189,"stem":190,"children":191,"icon":193},"Advanced Topics","/advanced","06.advanced/1.index",[192,194,199,204,209],{"title":188,"path":189,"stem":190,"icon":193},"i-lucide-flask-conical",{"title":195,"path":196,"stem":197,"icon":198},"Hybrid AI + Deterministic Execution","/advanced/hybrid-execution-model","06.advanced/2.hybrid-execution-model","i-lucide-git-merge",{"title":200,"path":201,"stem":202,"icon":203},"Drift Detection & Self-Healing","/advanced/drift-detection-self-healing","06.advanced/3.drift-detection-self-healing","i-lucide-heart-pulse",{"title":205,"path":206,"stem":207,"icon":208},"Governance & Approvals","/advanced/governance-and-approvals","06.advanced/4.governance-and-approvals","i-lucide-scale",{"title":210,"path":211,"stem":212,"icon":213},"Cost & Performance Optimization","/advanced/cost-and-performance","06.advanced/5.cost-and-performance","i-lucide-zap",{"title":215,"path":216,"stem":217,"children":218,"icon":220},"Operations","/operations","07.operations/1.index",[219,221,225,230],{"title":215,"path":216,"stem":217,"icon":220},"i-lucide-settings-2",{"title":222,"path":223,"stem":224,"icon":186},"Deployment Models","/operations/deployment-models","07.operations/2.deployment-models",{"title":226,"path":227,"stem":228,"icon":229},"Monitoring & Debugging","/operations/monitoring-and-debugging","07.operations/3.monitoring-and-debugging","i-lucide-bug",{"title":231,"path":232,"stem":233,"icon":234},"Best Practices","/operations/best-practices","07.operations/4.best-practices","i-lucide-check-check",{"title":236,"path":237,"stem":238,"children":239,"icon":241},"AWS Connections","/aws-connections","08.aws-connections/1.index",[240,242,245,250,255,260],{"title":236,"path":237,"stem":238,"icon":241},"i-simple-icons-amazonaws",{"title":23,"path":243,"stem":244,"icon":29},"/aws-connections/getting-started","08.aws-connections/2.getting-started",{"title":246,"path":247,"stem":248,"icon":249},"Setup Methods","/aws-connections/setup-methods","08.aws-connections/3.setup-methods","i-lucide-wrench",{"title":251,"path":252,"stem":253,"icon":254},"Managing Connections","/aws-connections/managing-connections","08.aws-connections/4.managing-connections","i-lucide-settings",{"title":256,"path":257,"stem":258,"icon":259},"Security Best Practices","/aws-connections/security-best-practices","08.aws-connections/5.security-best-practices","i-lucide-lock",{"title":261,"path":262,"stem":263,"icon":229},"Troubleshooting","/aws-connections/troubleshooting","08.aws-connections/6.troubleshooting",{"title":265,"path":266,"stem":267,"children":268,"icon":270},"Cloud Connections","/cloud-connections","09.cloud-connections/1.index",[269,271,276,281,286,291],{"title":265,"path":266,"stem":267,"icon":270},"i-lucide-cable",{"title":272,"path":273,"stem":274,"icon":275},"Google Cloud (GCP)","/cloud-connections/gcp","09.cloud-connections/2.gcp","i-simple-icons-googlecloud",{"title":277,"path":278,"stem":279,"icon":280},"Microsoft Azure","/cloud-connections/azure","09.cloud-connections/3.azure","i-simple-icons-microsoftazure",{"title":282,"path":283,"stem":284,"icon":285},"Magalu Cloud","/cloud-connections/magalu","09.cloud-connections/4.magalu","i-lucide-cloud",{"title":287,"path":288,"stem":289,"icon":290},"Kubernetes","/cloud-connections/kubernetes","09.cloud-connections/5.kubernetes","i-simple-icons-kubernetes",{"title":292,"path":293,"stem":294,"icon":208},"TypeSafe","/cloud-connections/typesafe","09.cloud-connections/6.typesafe",{"title":296,"path":297,"stem":298,"children":299,"icon":136},"DNS Providers","/dns-providers","10.dns-providers/1.index",[300,302,305,308,311,315],{"title":301,"path":297,"stem":298,"icon":136},"DNS Provider Connections",{"title":23,"path":303,"stem":304,"icon":29},"/dns-providers/getting-started","10.dns-providers/2.getting-started",{"title":246,"path":306,"stem":307,"icon":249},"/dns-providers/setup-methods","10.dns-providers/3.setup-methods",{"title":251,"path":309,"stem":310,"icon":254},"/dns-providers/managing-connections","10.dns-providers/4.managing-connections",{"title":312,"path":313,"stem":314,"icon":39},"Zones and Records","/dns-providers/zones-and-records","10.dns-providers/5.zones-and-records",{"title":261,"path":316,"stem":317,"icon":229},"/dns-providers/troubleshooting","10.dns-providers/6.troubleshooting",{"title":319,"path":320,"stem":321,"children":322,"icon":29},"Cloud Deploy","/cloud-deploy","11.cloud-deploy/01.index",[323,324,327,332,336,341,345,349,354,358],{"title":319,"path":320,"stem":321,"icon":29},{"title":23,"path":325,"stem":326,"icon":29},"/cloud-deploy/getting-started","11.cloud-deploy/02.getting-started",{"title":328,"path":329,"stem":330,"icon":331},"Creating a Site","/cloud-deploy/creating-a-site","11.cloud-deploy/03.creating-a-site","i-lucide-plus-circle",{"title":333,"path":334,"stem":335,"icon":34},"Site Overview and Deployments","/cloud-deploy/site-overview","11.cloud-deploy/04.site-overview",{"title":337,"path":338,"stem":339,"icon":340},"Deployment Progress and Success","/cloud-deploy/deployment-progress","11.cloud-deploy/05.deployment-progress","i-lucide-loader",{"title":342,"path":343,"stem":344,"icon":254},"Settings","/cloud-deploy/settings","11.cloud-deploy/06.settings",{"title":346,"path":347,"stem":348,"icon":109},"Custom Domains","/cloud-deploy/custom-domains","11.cloud-deploy/07.custom-domains",{"title":350,"path":351,"stem":352,"icon":353},"Resources, Releases, and Danger Zone","/cloud-deploy/resources-releases","11.cloud-deploy/08.resources-releases","i-lucide-package",{"title":355,"path":356,"stem":357,"icon":141},"Admin Dashboard","/cloud-deploy/admin-dashboard","11.cloud-deploy/09.admin-dashboard",{"title":261,"path":359,"stem":360,"icon":229},"/cloud-deploy/troubleshooting","11.cloud-deploy/10.troubleshooting",{"title":362,"path":363,"stem":364,"children":365,"icon":368},"User Onboarding","/user-onboarding","12.user-onboarding/1.index",[366,369,372,377,382,386],{"title":367,"path":363,"stem":364,"icon":368},"User Creation and Onboarding","i-lucide-user-plus",{"title":23,"path":370,"stem":371,"icon":29},"/user-onboarding/getting-started","12.user-onboarding/2.getting-started",{"title":373,"path":374,"stem":375,"icon":376},"Creating Your Organization","/user-onboarding/onboarding","12.user-onboarding/3.onboarding","i-lucide-building-2",{"title":378,"path":379,"stem":380,"icon":381},"Invitations","/user-onboarding/invitations","12.user-onboarding/4.invitations","i-lucide-mail",{"title":383,"path":384,"stem":385,"icon":254},"Managing Your Account","/user-onboarding/managing-account","12.user-onboarding/5.managing-account",{"title":261,"path":387,"stem":388,"icon":229},"/user-onboarding/troubleshooting","12.user-onboarding/6.troubleshooting",{"title":342,"path":390,"stem":391,"children":392,"icon":394},"/settings","13.settings/1.index",[393,395,400,404,409,413],{"title":342,"path":390,"stem":391,"icon":394},"i-lucide-sliders-horizontal",{"title":396,"path":397,"stem":398,"icon":399},"General Settings","/settings/general","13.settings/2.general","i-lucide-user",{"title":401,"path":402,"stem":403,"icon":85},"Members Settings","/settings/members","13.settings/3.members",{"title":405,"path":406,"stem":407,"icon":408},"Notifications Settings","/settings/notifications","13.settings/4.notifications","i-lucide-bell",{"title":410,"path":411,"stem":412,"icon":141},"Security Settings","/settings/security","13.settings/5.security",{"title":414,"path":415,"stem":416,"icon":417},"Signing Keys","/settings/keys","13.settings/6.keys","i-lucide-key-round",{"title":419,"path":420,"stem":421,"children":422,"icon":29},"App Enablement","/app-enablement","14.app-enablement/1.index",[423,424,428,432],{"title":419,"path":420,"stem":421,"icon":29},{"title":425,"path":426,"stem":427,"icon":417},"Sign in with Orkestia","/app-enablement/sign-in-with-orkestia","14.app-enablement/2.sign-in-with-orkestia",{"title":429,"path":430,"stem":431,"icon":95},"End-user data","/app-enablement/end-user-data","14.app-enablement/3.end-user-data",{"title":433,"path":434,"stem":435,"icon":131},"Compositions — use, invoke, share","/app-enablement/compositions","14.app-enablement/4.compositions",{"title":437,"path":438,"stem":439,"children":440,"icon":80},"Lumen","/lumen","15.lumen/1.index",[441,442,447,452,457,461,465],{"title":437,"path":438,"stem":439,"icon":80},{"title":443,"path":444,"stem":445,"icon":446},"Enable Lumen","/lumen/enable","15.lumen/2.enable","i-lucide-power",{"title":448,"path":449,"stem":450,"icon":451},"Send data","/lumen/send-data","15.lumen/3.send-data","i-lucide-upload",{"title":453,"path":454,"stem":455,"icon":456},"Collector","/lumen/collector","15.lumen/4.collector","i-lucide-container",{"title":458,"path":459,"stem":460,"icon":34},"Use Lumen","/lumen/observe","15.lumen/5.observe",{"title":462,"path":463,"stem":464,"icon":44},"Lumen MCP","/lumen/mcp","15.lumen/6.mcp",{"title":466,"path":467,"stem":468,"icon":469},"Query API","/lumen/query-api","15.lumen/7.query-api","i-lucide-search",{"title":471,"path":472,"stem":473,"children":474,"icon":476},"SDKs","/sdks","16.sdks/1.index",[475,477,482,487],{"title":471,"path":472,"stem":473,"icon":476},"i-lucide-code",{"title":478,"path":479,"stem":480,"icon":481},"Workflows SDK — Node / TypeScript","/sdks/workflows-nodejs","16.sdks/2.workflows-nodejs","i-lucide-file-ts",{"title":483,"path":484,"stem":485,"icon":486},"Workflows SDK — Python","/sdks/workflows-python","16.sdks/3.workflows-python","i-simple-icons-python",{"title":488,"path":489,"stem":490,"icon":417},"Auth SDK — Sign in with Orkestia","/sdks/auth","16.sdks/4.auth",{"title":92,"path":492,"stem":493,"children":494,"icon":95},"/appdata","17.appdata/1.index",[495,496,501,506,510,515,520,525,530],{"title":92,"path":492,"stem":493,"icon":95},{"title":497,"path":498,"stem":499,"icon":500},"Declare structures","/appdata/declare","17.appdata/2.declare","i-lucide-table",{"title":502,"path":503,"stem":504,"icon":505},"Records & Data API","/appdata/data-api","17.appdata/3.data-api","i-lucide-rows-3",{"title":507,"path":508,"stem":509,"icon":376},"Ownership & workspaces","/appdata/ownership","17.appdata/4.ownership",{"title":511,"path":512,"stem":513,"icon":514},"Expose App Data to end-users","/appdata/expose","17.appdata/5.expose","i-lucide-app-window",{"title":516,"path":517,"stem":518,"icon":519},"PostgREST HTTP","/appdata/postgrest","17.appdata/6.postgrest","i-lucide-unplug",{"title":521,"path":522,"stem":523,"icon":524},"Ordered append","/appdata/append","17.appdata/7.append","i-lucide-list-ordered",{"title":526,"path":527,"stem":528,"icon":529},"Databases and instances","/appdata/instances","17.appdata/8.instances","i-lucide-hard-drive",{"title":531,"path":532,"stem":533,"icon":104},"Query console and SQL","/appdata/query","17.appdata/9.query",{"title":97,"path":535,"stem":536,"children":537,"icon":61},"/engram","18.engram/1.index",[538,539,543],{"title":97,"path":535,"stem":536,"icon":61},{"title":540,"path":541,"stem":542,"icon":155},"Write & recall","/engram/write-recall","18.engram/2.write-recall",{"title":544,"path":545,"stem":546,"icon":547},"Field & feed","/engram/agent-memory","18.engram/3.agent-memory","i-lucide-radio",{"title":101,"path":549,"stem":550,"children":551,"icon":104},"/devkit","19.devkit/1.index",[552,553,558,562,567],{"title":101,"path":549,"stem":550,"icon":104},{"title":554,"path":555,"stem":556,"icon":557},"Install DevKit","/devkit/install","19.devkit/2.install","i-lucide-download",{"title":559,"path":560,"stem":561,"icon":519},"Hook redirect","/devkit/hooks","19.devkit/3.hooks",{"title":563,"path":564,"stem":565,"icon":566},"Local coding runner","/devkit/local-runner","19.devkit/4.local-runner","i-lucide-cpu",{"title":568,"path":569,"stem":570,"icon":131},"Compositions from DevKit","/devkit/compositions","19.devkit/5.compositions",{"title":572,"path":573,"stem":574,"children":575,"icon":44},"Staff & Agents","/staff-and-agents","20.staff-and-agents/01.index",[576,577,582,586,590,594,598,602,606,611,615,620,625,629],{"title":572,"path":573,"stem":574,"icon":44},{"title":578,"path":579,"stem":580,"icon":581},"Prerequisites","/staff-and-agents/prerequisites","20.staff-and-agents/02.prerequisites","i-lucide-list-checks",{"title":583,"path":584,"stem":585,"icon":368},"Hire an actor","/staff-and-agents/hire-an-actor","20.staff-and-agents/03.hire-an-actor",{"title":587,"path":588,"stem":589,"icon":34},"Console","/staff-and-agents/console","20.staff-and-agents/04.console",{"title":591,"path":592,"stem":593,"icon":11},"Configs, skills, and MCP","/staff-and-agents/configs-skills-mcp","20.staff-and-agents/05.configs-skills-mcp",{"title":595,"path":596,"stem":597,"icon":136},"Agent runner groups","/staff-and-agents/runner-groups","20.staff-and-agents/06.runner-groups",{"title":599,"path":600,"stem":601,"icon":16},"Governance","/staff-and-agents/governance","20.staff-and-agents/07.governance",{"title":603,"path":604,"stem":605,"icon":417},"Identity and tokens","/staff-and-agents/identity","20.staff-and-agents/08.identity",{"title":607,"path":608,"stem":609,"icon":610},"Memory and cost","/staff-and-agents/memory-and-cost","20.staff-and-agents/09.memory-and-cost","i-lucide-wallet",{"title":612,"path":613,"stem":614,"icon":155},"Coding agents","/staff-and-agents/coding-agents","20.staff-and-agents/10.coding-agents",{"title":616,"path":617,"stem":618,"icon":619},"Wire a repository for coding agents","/staff-and-agents/wire-a-repository","20.staff-and-agents/11.wire-a-repository","i-lucide-link",{"title":621,"path":622,"stem":623,"icon":624},"Run a ticket end to end","/staff-and-agents/run-a-ticket","20.staff-and-agents/12.run-a-ticket","i-lucide-play",{"title":626,"path":627,"stem":628,"icon":66},"Build a product team of actors","/staff-and-agents/build-a-product-team","20.staff-and-agents/13.build-a-product-team",{"title":261,"path":630,"stem":631,"icon":249},"/staff-and-agents/troubleshooting","20.staff-and-agents/14.troubleshooting",{"title":106,"path":633,"stem":634,"children":635,"icon":109},"/app-host","21.app-host/1.index",[636,637,641,644,649,653,658,662,666],{"title":106,"path":633,"stem":634,"icon":109},{"title":638,"path":639,"stem":640,"icon":514},"Your app and site","/app-host/your-app","21.app-host/2.your-app",{"title":92,"path":642,"stem":643,"icon":95},"/app-host/app-data","21.app-host/3.app-data",{"title":645,"path":646,"stem":647,"icon":648},"Website and process","/app-host/hosting","21.app-host/4.hosting","i-lucide-cloud-upload",{"title":650,"path":651,"stem":652,"icon":547},"Buzz","/app-host/buzz","21.app-host/5.buzz",{"title":654,"path":655,"stem":656,"icon":657},"Files","/app-host/files","21.app-host/6.files","i-lucide-folder",{"title":659,"path":660,"stem":661,"icon":109},"Your own domain","/app-host/your-domain","21.app-host/7.your-domain",{"title":663,"path":664,"stem":665,"icon":229},"Troubleshooting App Host","/app-host/troubleshooting","21.app-host/8.troubleshooting",{"title":667,"path":668,"stem":669,"icon":417},"Signing keys","/app-host/signing-keys","21.app-host/9.signing-keys",{"title":111,"path":671,"stem":672,"children":673,"icon":114},"/agent-exchange","22.agent-exchange/01.index",[674,675,678,682,686,690],{"title":111,"path":671,"stem":672,"icon":114},{"title":583,"path":676,"stem":677,"icon":368},"/agent-exchange/hire","22.agent-exchange/02.hire",{"title":679,"path":680,"stem":681,"icon":208},"List an actor","/agent-exchange/list","22.agent-exchange/03.list",{"title":683,"path":684,"stem":685,"icon":104},"Invoke & leases","/agent-exchange/invoke","22.agent-exchange/04.invoke",{"title":687,"path":688,"stem":689,"icon":141},"Settlement & trust","/agent-exchange/settlement","22.agent-exchange/05.settlement",{"title":53,"path":691,"stem":692,"icon":56},"/agent-exchange/workflows","22.agent-exchange/06.workflows",{"title":694,"path":695,"stem":696,"children":697,"icon":75},"Runners","/runners","23.runners/1.index",[698,700,704,709,713,717,721,726,730,734,738,741,745,749,753],{"title":699,"path":695,"stem":696,"icon":75},"Runner groups",{"title":701,"path":702,"stem":703,"icon":275},"Cloud Run","/runners/cloud-run","23.runners/10.cloud-run",{"title":705,"path":706,"stem":707,"icon":708},"DigitalOcean App Job","/runners/do-app-job","23.runners/11.do-app-job","i-simple-icons-digitalocean",{"title":710,"path":711,"stem":712,"icon":708},"DigitalOcean Droplet","/runners/do-droplet","23.runners/12.do-droplet",{"title":714,"path":715,"stem":716,"icon":285},"Magalu Cloud VM","/runners/magalu-vm","23.runners/13.magalu-vm",{"title":101,"path":718,"stem":719,"icon":720},"/runners/devkit","23.runners/14.devkit","i-lucide-laptop",{"title":722,"path":723,"stem":724,"icon":725},"Purposes & integrations","/runners/purposes","23.runners/16.purposes","i-lucide-layers",{"title":727,"path":728,"stem":729,"icon":241},"Fargate","/runners/fargate","23.runners/2.fargate",{"title":731,"path":732,"stem":733,"icon":241},"EC2 Auto Scaling","/runners/ec2-auto-scaling","23.runners/3.ec2-auto-scaling",{"title":735,"path":736,"stem":737,"icon":241},"EC2 VM","/runners/ec2-vm","23.runners/4.ec2-vm",{"title":287,"path":739,"stem":740,"icon":290},"/runners/kubernetes","23.runners/5.kubernetes",{"title":742,"path":743,"stem":744,"icon":280},"Azure Container Apps","/runners/azure-container-apps","23.runners/6.azure-container-apps",{"title":746,"path":747,"stem":748,"icon":280},"Azure VMSS","/runners/azure-vmss","23.runners/7.azure-vmss",{"title":750,"path":751,"stem":752,"icon":280},"Azure VM","/runners/azure-vm","23.runners/8.azure-vm",{"title":754,"path":755,"stem":756,"icon":275},"GCE","/runners/gce","23.runners/9.gce",{"title":758,"path":759,"stem":760,"children":761,"icon":763},"Chat","/chat","24.chat/01.index",[762,764,768,773,777,782,787,791,796,800,805,810,814,819,824,828,832,836,840,845],{"title":758,"path":759,"stem":760,"icon":763},"i-lucide-messages-square",{"title":765,"path":766,"stem":767,"icon":446},"Enable and publish","/chat/enable-and-publish","24.chat/02.enable-and-publish",{"title":769,"path":770,"stem":771,"icon":772},"Theme and customization","/chat/theme-and-customization","24.chat/03.theme-and-customization","i-lucide-palette",{"title":774,"path":775,"stem":776,"icon":85},"Members and moderation","/chat/members-and-moderation","24.chat/04.members-and-moderation",{"title":778,"path":779,"stem":780,"icon":781},"Channels","/chat/channels","24.chat/05.channels","i-lucide-hash",{"title":783,"path":784,"stem":785,"icon":786},"Using the chat","/chat/using-the-chat","24.chat/06.using-the-chat","i-lucide-message-circle",{"title":788,"path":789,"stem":790,"icon":44},"Actors in chat","/chat/actors-in-chat","24.chat/07.actors-in-chat",{"title":792,"path":793,"stem":794,"icon":795},"Internal support actor","/chat/internal-support-actor","24.chat/08.internal-support-actor","i-lucide-life-buoy",{"title":797,"path":798,"stem":799,"icon":104},"API and console","/chat/api-and-console","24.chat/09.api-and-console",{"title":801,"path":802,"stem":803,"icon":804},"Limits","/chat/limits","24.chat/10.limits","i-lucide-triangle-alert",{"title":806,"path":807,"stem":808,"icon":809},"Structured chat with DGI","/chat/structured-chat","24.chat/11.structured-chat","i-lucide-layout-list",{"title":811,"path":812,"stem":813,"icon":109},"Option A: hosted chat with DGI","/chat/option-a-hosted-chat","24.chat/12.option-a-hosted-chat",{"title":815,"path":816,"stem":817,"icon":818},"Option B: embed the chat component","/chat/option-b-embed-component","24.chat/13.option-b-embed-component","i-lucide-component",{"title":820,"path":821,"stem":822,"icon":823},"Option C: custom client (wire contract)","/chat/option-c-custom-client","24.chat/14.option-c-custom-client","i-lucide-braces",{"title":825,"path":826,"stem":827,"icon":394},"Responder configuration reference","/chat/responder-reference","24.chat/15.responder-reference",{"title":829,"path":830,"stem":831,"icon":547},"Cards, live updates and proactive posts","/chat/cards-live-and-proactive","24.chat/16.cards-live-and-proactive",{"title":833,"path":834,"stem":835,"icon":16},"Structured chat security model","/chat/structured-chat-security","24.chat/17.structured-chat-security",{"title":837,"path":838,"stem":839,"icon":181},"Option D: any app or API (dgi.chat)","/chat/option-d-chat-api","24.chat/18.option-d-chat-api",{"title":841,"path":842,"stem":843,"icon":844},"Card catalog","/chat/card-catalog","24.chat/19.card-catalog","i-lucide-layout-grid",{"title":846,"path":847,"stem":848,"icon":849},"Living Surfaces","/chat/living-surfaces","24.chat/20.living-surfaces","i-lucide-sprout",{"title":851,"path":852,"stem":853,"children":854,"icon":61},"DGI","/dgi","25.dgi/1.index",[855,857,862,866,870,874],{"title":856,"path":852,"stem":853,"icon":61},"What is DGI",{"title":858,"path":859,"stem":860,"icon":861},"How DGI works","/dgi/how-it-works","25.dgi/2.how-it-works","i-lucide-cog",{"title":863,"path":864,"stem":865,"icon":844},"Interfaces","/dgi/interfaces","25.dgi/3.interfaces",{"title":867,"path":868,"stem":869,"icon":29},"Quickstart","/dgi/quickstart","25.dgi/4.quickstart",{"title":871,"path":872,"stem":873,"icon":16},"Trust and safety","/dgi/trust-and-safety","25.dgi/5.trust-and-safety",{"title":875,"path":876,"stem":877,"icon":878},"FAQ","/dgi/faq","25.dgi/6.faq","i-lucide-circle-help",{"id":880,"title":138,"body":881,"description":2160,"extension":2161,"links":2162,"meta":2163,"navigation":2164,"path":139,"seo":2165,"stem":140,"__hash__":2166},"docs/04.guides/7.security-and-compliance.md",{"type":882,"value":883,"toc":2149},"minimark",[884,888,911,951,956,977,983,1044,1064,1068,1079,1288,1291,1317,1342,1348,1352,1359,1405,1416,1422,1500,1507,1520,1524,1531,1559,1563,1568,1602,1607,1722,1726,1737,1826,1829,1862,1881,1885,1892,1968,1983,1994,1998,2001,2085,2106,2110,2145],[885,886,887],"p",{},"This guide is written for the person who has to sign off before Orkestia touches a production cloud account: the platform engineer, the security reviewer, the technical lead doing an evaluation. It explains the actual mechanisms behind Orkestia's security posture and what is available today versus on the roadmap.",[885,889,890,891,895,896,899,900,904,905,907,908,910],{},"The short version: Orkestia is built so that ",[892,893,894],"strong",{},"the secure path is the only path",". Customer ",[892,897,898],{},"cloud"," code and data stay in ",[901,902,903],"em",{},"your"," accounts. Execution of cloud workflows happens there. ",[892,906,92],{}," is the explicit exception: rows of apps that opted into the platform data plane live on Orkestia-managed Postgres, isolated by identity and ownership — not a copy of your cloud warehouse. ",[892,909,106],{}," is the explicit exception for hosting: a claimed site runs on a shared pool you do not kubeconfig. Every tenant is isolated by construction, and everything the platform did for your organization is recoverable as an org-scoped audit trail.",[912,913,914,932,938,944],"card-group",{},[915,916,919],"card",{"icon":917,"title":918},"i-lucide-cloud-off","No code/data custody (cloud)",[885,920,921,922,925,926,928,929,931],{},"Cloud workflows execute in the customer's own accounts. Orkestia stores workflow ",[892,923,924],{},"state"," and observability. ",[892,927,92],{}," stores only the app rows you declared. ",[892,930,106],{}," stores site metadata, not your git.",[915,933,935],{"icon":417,"title":934},"No static keys",[885,936,937],{},"Cross-account access uses STS-assumed roles scoped by an external ID. No long-lived access keys are stored.",[915,939,941],{"icon":16,"title":940},"Isolated by construction",[885,942,943],{},"Tenant scope is bound from the verified identity server-side. A caller cannot widen scope to read another org's rows.",[915,945,948],{"icon":946,"title":947},"i-lucide-scroll-text","Provable",[885,949,950],{},"An org-scoped, read-only audit log over the engine's transition log, plus exportable evidence packs.",[952,953,955],"h2",{"id":954},"the-trust-boundary-zero-code-custody","The trust boundary: Zero Code Custody",[885,957,958,959,962,963,966,967,970,971,973,974,976],{},"The single most important architectural fact for an evaluator is ",[901,960,961],{},"where execution happens",". Orkestia is an orchestrator and an observability plane. Cloud jobs and provider resources stay in your accounts. If you ",[892,964,965],{},"opt in"," to ",[968,969,92],"a",{"href":492}," or ",[968,972,106],{"href":633},", those apps' rows, the claimed site, and (when Buzz is on) site MinIO including ",[968,975,654],{"href":655}," run on Orkestia-managed infrastructure with the same identity isolation — still not your git, still not a dump of your cloud data plane.",[978,979],"dag-diagram",{":edges":980,":nodes":981,"direction":982},"[{\"from\":\"ENG\",\"to\":\"RUN\",\"label\":\"assume-role (STS + external ID)\"},{\"from\":\"RUN\",\"to\":\"ENG\",\"label\":\"results + state transitions\"},{\"from\":\"RUN\",\"to\":\"LUM\",\"label\":\"telemetry\"},{\"from\":\"DGI\",\"to\":\"ENG\",\"label\":\"design / orchestrate\",\"dashed\":true}]","[{\"id\":\"ENG\",\"label\":\"Workflow engine\",\"sub\":\"(state + transition log)\",\"kind\":\"engine\"},{\"id\":\"LUM\",\"label\":\"Lumen\",\"sub\":\"(observability)\",\"kind\":\"data\"},{\"id\":\"DGI\",\"label\":\"DGI / Staff\",\"sub\":\"(design + governance)\",\"kind\":\"ai\"},{\"id\":\"RUN\",\"label\":\"Runners / runtime\",\"kind\":\"cloud\"},{\"id\":\"DATA\",\"label\":\"Your data + code\",\"kind\":\"data\"}]","LR",[984,985,986,999],"table",{},[987,988,989],"thead",{},[990,991,992,996],"tr",{},[993,994,995],"th",{},"Lives in Orkestia",[993,997,998],{},"Lives in your cloud",[1000,1001,1002,1011,1022,1033],"tbody",{},[990,1003,1004,1008],{},[1005,1006,1007],"td",{},"Workflow definitions & compositions",[1005,1009,1010],{},"Your application code",[990,1012,1013,1019],{},[1005,1014,1015,1016,1018],{},"Workflow ",[892,1017,924],{}," + the transition log",[1005,1020,1021],{},"Your data stores, secrets, runtimes",[990,1023,1024,1030],{},[1005,1025,1026,1027,1029],{},"Observability data (",[968,1028,437],{"href":78},")",[1005,1031,1032],{},"The actual execution of work",[990,1034,1035,1041],{},[1005,1036,1037,1038,1029],{},"Identity, org structure, governance (",[968,1039,1040],{"href":64},"Staff",[1005,1042,1043],{},"Customer-owned KBs / S3 / compute",[1045,1046,1047],"tip",{},[885,1048,1049,1050,1053,1054,1057,1058,1060,1061,1063],{},"This boundary is why the ",[968,1051,1052],{"href":196},"hybrid execution model"," matters for security, not just performance: AI designs the workflow, but the compiled deterministic ",[968,1055,1056],{"href":129},"virtual workflow"," is what actually runs — and it runs against ",[901,1059,903],{}," resources, under ",[901,1062,903],{}," roles, with the engine only recording what happened.",[952,1065,1067],{"id":1066},"cross-account-access-without-static-keys","Cross-account access without static keys",[885,1069,1070,1071,1074,1075,1078],{},"Orkestia reaches into a customer cloud account through a ",[892,1072,1073],{},"role it assumes",", not a key it stores. You create a role in your own account that trusts Orkestia's platform principal, gated by an ",[892,1076,1077],{},"external ID"," that the platform supplies. This is the standard AWS confused-deputy mitigation.",[1080,1081,1086],"pre",{"className":1082,"code":1083,"language":1084,"meta":1085,"style":1085},"language-json shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","{\n  \"Version\": \"2012-10-17\",\n  \"Statement\": [{\n    \"Effect\": \"Allow\",\n    \"Principal\": { \"AWS\": \"\u003Corkestia-platform-principal>\" },\n    \"Action\": \"sts:AssumeRole\",\n    \"Condition\": {\n      \"StringEquals\": { \"sts:ExternalId\": \"\u003Cyour-unique-external-id>\" }\n    }\n  }]\n}\n","json","",[1087,1088,1089,1098,1126,1141,1164,1199,1220,1235,1270,1276,1282],"code",{"__ignoreMap":1085},[1090,1091,1094],"span",{"class":1092,"line":1093},"line",1,[1090,1095,1097],{"class":1096},"sMK4o","{\n",[1090,1099,1101,1104,1108,1111,1114,1117,1121,1123],{"class":1092,"line":1100},2,[1090,1102,1103],{"class":1096},"  \"",[1090,1105,1107],{"class":1106},"spNyl","Version",[1090,1109,1110],{"class":1096},"\"",[1090,1112,1113],{"class":1096},":",[1090,1115,1116],{"class":1096}," \"",[1090,1118,1120],{"class":1119},"sfazB","2012-10-17",[1090,1122,1110],{"class":1096},[1090,1124,1125],{"class":1096},",\n",[1090,1127,1129,1131,1134,1136,1138],{"class":1092,"line":1128},3,[1090,1130,1103],{"class":1096},[1090,1132,1133],{"class":1106},"Statement",[1090,1135,1110],{"class":1096},[1090,1137,1113],{"class":1096},[1090,1139,1140],{"class":1096}," [{\n",[1090,1142,1144,1147,1151,1153,1155,1157,1160,1162],{"class":1092,"line":1143},4,[1090,1145,1146],{"class":1096},"    \"",[1090,1148,1150],{"class":1149},"sBMFI","Effect",[1090,1152,1110],{"class":1096},[1090,1154,1113],{"class":1096},[1090,1156,1116],{"class":1096},[1090,1158,1159],{"class":1119},"Allow",[1090,1161,1110],{"class":1096},[1090,1163,1125],{"class":1096},[1090,1165,1167,1169,1172,1174,1176,1179,1181,1185,1187,1189,1191,1194,1196],{"class":1092,"line":1166},5,[1090,1168,1146],{"class":1096},[1090,1170,1171],{"class":1149},"Principal",[1090,1173,1110],{"class":1096},[1090,1175,1113],{"class":1096},[1090,1177,1178],{"class":1096}," {",[1090,1180,1116],{"class":1096},[1090,1182,1184],{"class":1183},"sbssI","AWS",[1090,1186,1110],{"class":1096},[1090,1188,1113],{"class":1096},[1090,1190,1116],{"class":1096},[1090,1192,1193],{"class":1119},"\u003Corkestia-platform-principal>",[1090,1195,1110],{"class":1096},[1090,1197,1198],{"class":1096}," },\n",[1090,1200,1202,1204,1207,1209,1211,1213,1216,1218],{"class":1092,"line":1201},6,[1090,1203,1146],{"class":1096},[1090,1205,1206],{"class":1149},"Action",[1090,1208,1110],{"class":1096},[1090,1210,1113],{"class":1096},[1090,1212,1116],{"class":1096},[1090,1214,1215],{"class":1119},"sts:AssumeRole",[1090,1217,1110],{"class":1096},[1090,1219,1125],{"class":1096},[1090,1221,1223,1225,1228,1230,1232],{"class":1092,"line":1222},7,[1090,1224,1146],{"class":1096},[1090,1226,1227],{"class":1149},"Condition",[1090,1229,1110],{"class":1096},[1090,1231,1113],{"class":1096},[1090,1233,1234],{"class":1096}," {\n",[1090,1236,1238,1241,1244,1246,1248,1250,1252,1256,1258,1260,1262,1265,1267],{"class":1092,"line":1237},8,[1090,1239,1240],{"class":1096},"      \"",[1090,1242,1243],{"class":1183},"StringEquals",[1090,1245,1110],{"class":1096},[1090,1247,1113],{"class":1096},[1090,1249,1178],{"class":1096},[1090,1251,1116],{"class":1096},[1090,1253,1255],{"class":1254},"swJcz","sts:ExternalId",[1090,1257,1110],{"class":1096},[1090,1259,1113],{"class":1096},[1090,1261,1116],{"class":1096},[1090,1263,1264],{"class":1119},"\u003Cyour-unique-external-id>",[1090,1266,1110],{"class":1096},[1090,1268,1269],{"class":1096}," }\n",[1090,1271,1273],{"class":1092,"line":1272},9,[1090,1274,1275],{"class":1096},"    }\n",[1090,1277,1279],{"class":1092,"line":1278},10,[1090,1280,1281],{"class":1096},"  }]\n",[1090,1283,1285],{"class":1092,"line":1284},11,[1090,1286,1287],{"class":1096},"}\n",[885,1289,1290],{},"What this buys an evaluator:",[1292,1293,1294,1305,1311],"ul",{},[1295,1296,1297,1300,1301,1304],"li",{},[892,1298,1299],{},"No long-lived secrets in Orkestia's store."," Access is a short-lived STS session, scoped by the role's own permission policy — which ",[901,1302,1303],{},"you"," author and can tighten or revoke at any time.",[1295,1306,1307,1310],{},[892,1308,1309],{},"Revocation is one-sided and instant."," Delete the trust relationship in your account and Orkestia can no longer assume the role. There is no credential to rotate or leak.",[1295,1312,1313,1316],{},[892,1314,1315],{},"Least privilege is yours to set."," The blast radius of any Orkestia workflow is the union of the role policies you granted — nothing more.",[1318,1319,1320],"note",{},[885,1321,1322,1323,1326,1327,1330,1331,1334,1335,1341],{},"When you set up a connection, the workflow engine tells you exactly which principal to trust and which external ID to bind. The MCP ",[1087,1324,1325],{},"get_workflow_prerequisites"," flow returns this setup guide with the platform identity already filled in. See ",[968,1328,1329],{"href":237},"AWS connections"," and ",[968,1332,1333],{"href":266},"Cloud connections"," for the connection setup, and the per-connection prerequisites in the ",[968,1336,1340],{"href":1337,"rel":1338},"https://reference.orkestia.dev",[1339],"nofollow","reference catalog",".",[885,1343,1344,1345,1341],{},"For DNS-driven flows (custom domains, app enablement) the same delegated-credential principle applies via provider connections — see ",[968,1346,1347],{"href":297},"DNS providers",[952,1349,1351],{"id":1350},"identity-authentication","Identity & authentication",[885,1353,1354,1355,1358],{},"Orkestia has ",[892,1356,1357],{},"two distinct identity models",", and it's worth keeping them separate when reasoning about security.",[984,1360,1361,1374],{},[987,1362,1363],{},[990,1364,1365,1368,1371],{},[993,1366,1367],{},"Model",[993,1369,1370],{},"Who it authenticates",[993,1372,1373],{},"Mechanism",[1000,1375,1376,1389],{},[990,1377,1378,1383,1386],{},[1005,1379,1380],{},[892,1381,1382],{},"Member identity",[1005,1384,1385],{},"Your team operating the platform",[1005,1387,1388],{},"AWS Cognito — PKCE, RS256 JWTs, MFA support, social sign-in, managed sessions",[990,1390,1391,1396,1402],{},[1005,1392,1393],{},[892,1394,1395],{},"End-user identity",[1005,1397,1398,1399,1401],{},"The users of apps ",[901,1400,1303],{}," build",[1005,1403,1404],{},"\"Sign in with Orkestia\" — hosted PKCE / RS256 / MFA, immutable server-side principal injection",[885,1406,1407,1408,1411,1412,1415],{},"Member-account controls (authentication provider, password management, active sessions, account deletion) live under ",[968,1409,1410],{"href":390},"Settings → Security",". Authentication is handled by ",[892,1413,1414],{},"AWS Cognito",", so password storage, strength rules, recovery, and MFA are never implemented in application code.",[885,1417,1418,1419,1421],{},"For the apps you expose to end-users via ",[968,1420,419],{"href":420},", the security guarantees are enforced end to end:",[984,1423,1424,1434],{},[987,1425,1426],{},[990,1427,1428,1431],{},[993,1429,1430],{},"Guarantee",[993,1432,1433],{},"How it's enforced",[1000,1435,1436,1446,1456,1466,1476,1490],{},[990,1437,1438,1443],{},[1005,1439,1440],{},[892,1441,1442],{},"Secure-by-default login",[1005,1444,1445],{},"Hosted \"Sign in with Orkestia\" — PKCE, RS256-signed JWTs, MFA, email verification, none of it in your code",[990,1447,1448,1453],{},[1005,1449,1450],{},[892,1451,1452],{},"No credentials in your app",[1005,1454,1455],{},"Your frontend never holds a DB or API secret; Orkestia runs the workflow server-side",[990,1457,1458,1463],{},[1005,1459,1460],{},[892,1461,1462],{},"Immutable identity",[1005,1464,1465],{},"The end-user principal is injected server-side from the verified token — a caller cannot set or override who they are",[990,1467,1468,1473],{},[1005,1469,1470],{},[892,1471,1472],{},"Forced tenant isolation",[1005,1474,1475],{},"Scoped data steps bind the tenant filter from the caller's identity; a user can never widen scope to read another's rows",[990,1477,1478,1483],{},[1005,1479,1480],{},[892,1481,1482],{},"App Data isolation",[1005,1484,1485,1486,1489],{},"Catalog keyed by ",[1087,1487,1488],{},"(org, identity app)",". Owner / app / workspace modes. PostgREST 401/403 fail closed. Operator SQL is admitted SELECT only.",[990,1491,1492,1497],{},[1005,1493,1494],{},[892,1495,1496],{},"Least-exposure invocation",[1005,1498,1499],{},"End-user tokens can start only the virtual workflows you explicitly expose — never raw platform workflows",[885,1501,1502,1503,1506],{},"See ",[968,1504,1505],{"href":83},"Identity & multi-tenancy"," for the full model.",[1508,1509,1510],"warning",{},[885,1511,1512,1513,1515,1516,1519],{},"\"Sign in with Orkestia\" (end-user identity) is in active beta. Treat exact token lifetimes, MFA enrolment flows, and rate-limit defaults as subject to change, and confirm current values in ",[968,1514,342],{"href":390}," and the ",[968,1517,1340],{"href":1337,"rel":1518},[1339]," rather than hard-coding them.",[952,1521,1523],{"id":1522},"tenant-isolation-by-construction","Tenant isolation by construction",[885,1525,1526,1527,1530],{},"Multi-tenant breaches almost always come from a ",[901,1528,1529],{},"missing"," filter, not a wrong one. Orkestia's design removes the opportunity to forget.",[1292,1532,1533,1543,1549],{},[1295,1534,1535,1538,1539,1542],{},[892,1536,1537],{},"Org scope is resolved server-side from the token."," When you call the workflow MCP, your ",[1087,1540,1541],{},"organization_uuid"," is resolved from your authenticated identity — you do not pass it, and you cannot override it. Runs are scoped to your org automatically.",[1295,1544,1545,1548],{},[892,1546,1547],{},"Scoped data steps bind the tenant filter from identity."," A query workflow cannot express \"read another org's rows\"; the filter is derived, not supplied.",[1295,1550,1551,1554,1555,1558],{},[892,1552,1553],{},"The audit surface is org-scoped by construction."," Cross-org reads are ",[901,1556,1557],{},"not expressible"," in the audit query API — a query can only ever return your organization's runs.",[952,1560,1562],{"id":1561},"agent-exchange-two-orgs-one-ledger","Agent Exchange: two orgs, one ledger",[885,1564,1565,1567],{},[968,1566,111],{"href":671}," is the sanctioned cross-org channel for hiring Staff actors. It does not punch a hole in tenant isolation.",[1292,1569,1570,1584,1590,1596],{},[1295,1571,1572,1575,1576,1579,1580,1583],{},[892,1573,1574],{},"Mutations take the party from claims."," ",[1087,1577,1578],{},"buyer_organization_uuid"," / ",[1087,1581,1582],{},"seller_organization_uuid"," on hire or publish are ignored. You cannot hire \"as\" another org by stuffing a UUID.",[1295,1585,1586,1589],{},[892,1587,1588],{},"Dispatch is a grant, not a shared token."," An active lease is proven, then the seller-side run is pinned to the seller org under a named system principal.",[1295,1591,1592,1595],{},[892,1593,1594],{},"Orkestia never holds the funds."," Settlement rides the seller's Stripe / AbacatePay / Mercado Pago account. The platform stores contract evidence.",[1295,1597,1598,1601],{},[892,1599,1600],{},"Seller invoke output is untrusted data."," Do not treat it as instructions or render it as a prompt. Payloads stay under the listing DPA.",[885,1603,1604,1605,1341],{},"Operator path: ",[968,1606,687],{"href":688},[1080,1608,1612],{"className":1609,"code":1610,"language":1611,"meta":1085,"style":1085},"language-ts shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","// Conceptual: the caller never supplies the tenant filter.\n// It is bound from the verified principal, server-side.\nconst run = await start_workflow(\"audit.workflow-run.query\", {\n  workflow_type_prefixes: [\"kubernetes.\", \"deploy.k8s.\"],\n  state: \"terminal\",\n  // organization_uuid is injected from the token — not a parameter you set\n});\n","ts",[1087,1613,1614,1620,1625,1660,1691,1707,1712],{"__ignoreMap":1085},[1090,1615,1616],{"class":1092,"line":1093},[1090,1617,1619],{"class":1618},"sHwdD","// Conceptual: the caller never supplies the tenant filter.\n",[1090,1621,1622],{"class":1092,"line":1100},[1090,1623,1624],{"class":1618},"// It is bound from the verified principal, server-side.\n",[1090,1626,1627,1630,1634,1637,1641,1645,1648,1650,1653,1655,1658],{"class":1092,"line":1128},[1090,1628,1629],{"class":1106},"const",[1090,1631,1633],{"class":1632},"sTEyZ"," run ",[1090,1635,1636],{"class":1096},"=",[1090,1638,1640],{"class":1639},"s7zQu"," await",[1090,1642,1644],{"class":1643},"s2Zo4"," start_workflow",[1090,1646,1647],{"class":1632},"(",[1090,1649,1110],{"class":1096},[1090,1651,1652],{"class":1119},"audit.workflow-run.query",[1090,1654,1110],{"class":1096},[1090,1656,1657],{"class":1096},",",[1090,1659,1234],{"class":1096},[1090,1661,1662,1665,1667,1670,1672,1675,1677,1679,1681,1684,1686,1689],{"class":1092,"line":1143},[1090,1663,1664],{"class":1254},"  workflow_type_prefixes",[1090,1666,1113],{"class":1096},[1090,1668,1669],{"class":1632}," [",[1090,1671,1110],{"class":1096},[1090,1673,1674],{"class":1119},"kubernetes.",[1090,1676,1110],{"class":1096},[1090,1678,1657],{"class":1096},[1090,1680,1116],{"class":1096},[1090,1682,1683],{"class":1119},"deploy.k8s.",[1090,1685,1110],{"class":1096},[1090,1687,1688],{"class":1632},"]",[1090,1690,1125],{"class":1096},[1090,1692,1693,1696,1698,1700,1703,1705],{"class":1092,"line":1166},[1090,1694,1695],{"class":1254},"  state",[1090,1697,1113],{"class":1096},[1090,1699,1116],{"class":1096},[1090,1701,1702],{"class":1119},"terminal",[1090,1704,1110],{"class":1096},[1090,1706,1125],{"class":1096},[1090,1708,1709],{"class":1092,"line":1201},[1090,1710,1711],{"class":1618},"  // organization_uuid is injected from the token — not a parameter you set\n",[1090,1713,1714,1717,1719],{"class":1092,"line":1222},[1090,1715,1716],{"class":1096},"}",[1090,1718,1029],{"class":1632},[1090,1720,1721],{"class":1096},";\n",[952,1723,1725],{"id":1724},"the-audit-log-evidence-packs","The audit log & evidence packs",[885,1727,1728,1729,1732,1733,1736],{},"Every action on Orkestia is a workflow, and every workflow records every state transition. The audit log (the ",[1087,1730,1731],{},"audit.*"," workflow library) is the typed, ",[892,1734,1735],{},"read-only"," query surface over that transition log — so you can answer \"what ran for my organization, and what happened?\" without writing raw SQL or risking a mutation.",[984,1738,1739,1752],{},[987,1740,1741],{},[990,1742,1743,1746,1749],{},[993,1744,1745],{},"Capability",[993,1747,1748],{},"Workflow",[993,1750,1751],{},"What it answers",[1000,1753,1754,1768,1783,1798,1813],{},[990,1755,1756,1761,1765],{},[1005,1757,1758],{},[892,1759,1760],{},"Run query",[1005,1762,1763],{},[1087,1764,1652],{},[1005,1766,1767],{},"Paginated list of runs — filter by type prefix, state, terminal status, actor, time range",[990,1769,1770,1775,1780],{},[1005,1771,1772],{},[892,1773,1774],{},"Run history",[1005,1776,1777],{},[1087,1778,1779],{},"audit.workflow-run.get-history",[1005,1781,1782],{},"Full transition log for one run (after verifying it belongs to your org)",[990,1784,1785,1790,1795],{},[1005,1786,1787],{},[892,1788,1789],{},"Run aggregate",[1005,1791,1792],{},[1087,1793,1794],{},"audit.workflow-run.aggregate",[1005,1796,1797],{},"Per-type counts and last-started-at over a time range",[990,1799,1800,1805,1810],{},[1005,1801,1802],{},[892,1803,1804],{},"Health scan",[1005,1806,1807],{},[1087,1808,1809],{},"audit.workflow-health.scan",[1005,1811,1812],{},"Surfaces stuck / unhealthy runs",[990,1814,1815,1820,1823],{},[1005,1816,1817],{},[892,1818,1819],{},"Evidence pack",[1005,1821,1822],{},"composed from the queries above",[1005,1824,1825],{},"Bundle query + history + aggregate over a scoped window into a portable evidence artifact",[885,1827,1828],{},"Why this matters for compliance:",[1292,1830,1831,1837,1850,1856],{},[1295,1832,1833,1836],{},[892,1834,1835],{},"One source of truth."," The data already lives in the engine — the audit log exposes it safely instead of copying it into a parallel store that can drift.",[1295,1838,1839,1842,1843,1846,1847,1849],{},[892,1840,1841],{},"Read-only and side-effect-free."," Every audit workflow is a ",[1087,1844,1845],{},"DataWorkflow"," or read-only ",[1087,1848,1748],{},"; auditing cannot mutate state.",[1295,1851,1852,1855],{},[892,1853,1854],{},"Evidence packs."," Compose the queries above over a time range or workflow group into a portable artifact you can hand directly to an auditor — answering \"prove what the platform did for us\" without a screen-scrape.",[1295,1857,1858,1861],{},[892,1859,1860],{},"Prefix-composed grouping."," Ask for \"all kubernetes workflows\" or \"all billing workflows\" by passing the prefixes you care about, with no hard-coded filters.",[1045,1863,1864],{},[885,1865,1866,1867,1870,1871,1873,1874,1877,1878,1341],{},"The audit log is the ",[901,1868,1869],{},"historical"," record; ",[968,1872,437],{"href":78}," is the ",[901,1875,1876],{},"live"," runtime view (logs, traces, metrics). Pair them: the audit trail tells you what ran, Lumen tells you how it behaved. See ",[968,1879,1880],{"href":459},"Observability with Lumen",[952,1882,1884],{"id":1883},"failguard-reliability-guardrails","FailGuard — reliability guardrails",[885,1886,1887,1888,1891],{},"FailGuard is the automated error-fix guardrail for production. Connect a GitHub repository and a Sentry project; when production throws an error, FailGuard deduplicates it by fingerprint, indexes the relevant code, and runs the ",[1087,1889,1890],{},"failguard.error-fix"," workflow that explores, designs, generates, reviews, evaluates — and, within the controls you set, opens a pull request.",[984,1893,1894,1904],{},[987,1895,1896],{},[990,1897,1898,1901],{},[993,1899,1900],{},"Aspect",[993,1902,1903],{},"Behavior",[1000,1905,1906,1916,1928,1938,1958],{},[990,1907,1908,1913],{},[1005,1909,1910],{},[892,1911,1912],{},"Trigger",[1005,1914,1915],{},"A Sentry webhook; events are matched to a project, deduplicated by fingerprint, and screened against your rules",[990,1917,1918,1923],{},[1005,1919,1920],{},[892,1921,1922],{},"Repair",[1005,1924,1925,1927],{},[1087,1926,1890],{}," transitions through explore → design → generate → review → evaluate → create-PR / reject",[990,1929,1930,1935],{},[1005,1931,1932],{},[892,1933,1934],{},"Controls",[1005,1936,1937],{},"Auto-fix toggle, mandatory-review requirement, confidence threshold, daily / hourly attempt limits, excluded paths and error types",[990,1939,1940,1945],{},[1005,1941,1942],{},[892,1943,1944],{},"Indexing ownership",[1005,1946,1947,1950,1951,1954,1955,1957],{},[1087,1948,1949],{},"our_side"," uses platform-managed Bedrock resources; ",[1087,1952,1953],{},"their_side"," keeps the KB/S3 in ",[901,1956,903],{}," AWS account via a connection",[990,1959,1960,1965],{},[1005,1961,1962],{},[892,1963,1964],{},"Auditability",[1005,1966,1967],{},"Every attempt stores its full workflow history, agent outputs, file-change proposals, confidence metrics, and PR URL",[885,1969,1970,1971,1974,1975,1978,1979,1982],{},"Two security-relevant properties: a generated fix is a ",[892,1972,1973],{},"proposal, not a merge"," — it lands as a reviewed PR, and the review requirement / confidence threshold are guardrails you control; and because every repair attempt is a workflow run, it is visible to the ",[892,1976,1977],{},"audit log"," above. Repair history ",[901,1980,1981],{},"is"," workflow-run history.",[1318,1984,1985],{},[885,1986,1987,1988,1990,1991,1993],{},"With ",[1087,1989,1953],{}," indexing, FailGuard's code index and storage live in your own AWS account under a connection you grant — consistent with the no-custody boundary. ",[1087,1992,1949],{}," uses platform-managed Bedrock resources; choose per your data-residency requirements.",[952,1995,1997],{"id":1996},"mapping-to-common-compliance-concerns","Mapping to common compliance concerns",[885,1999,2000],{},"The table below maps typical reviewer questions to the mechanism that answers them. It is a map of capabilities, not a certification claim.",[984,2002,2003,2013],{},[987,2004,2005],{},[990,2006,2007,2010],{},[993,2008,2009],{},"Reviewer concern",[993,2011,2012],{},"Orkestia mechanism",[1000,2014,2015,2026,2034,2045,2053,2061,2069,2077],{},[990,2016,2017,2020],{},[1005,2018,2019],{},"\"Where does our code/data live?\"",[1005,2021,2022,2023,2025],{},"In ",[901,2024,903],{}," cloud accounts. Orkestia holds workflow state + observability data only",[990,2027,2028,2031],{},[1005,2029,2030],{},"\"How do you access our account?\"",[1005,2032,2033],{},"STS-assumed role gated by external ID; no stored static keys; revocable one-sided",[990,2035,2036,2039],{},[1005,2037,2038],{},"\"How is access scoped?\"",[1005,2040,2041,2042,2044],{},"Role permission policies ",[901,2043,1303],{}," author; least privilege is yours to set",[990,2046,2047,2050],{},[1005,2048,2049],{},"\"Can one tenant see another's data?\"",[1005,2051,2052],{},"No — org scope is bound from the verified token server-side and is not overridable",[990,2054,2055,2058],{},[1005,2056,2057],{},"\"How do you authenticate users?\"",[1005,2059,2060],{},"AWS Cognito (members); hosted PKCE/RS256/MFA \"Sign in with Orkestia\" (end-users)",[990,2062,2063,2066],{},[1005,2064,2065],{},"\"Can you prove what happened?\"",[1005,2067,2068],{},"Org-scoped, read-only audit log + exportable evidence packs",[990,2070,2071,2074],{},[1005,2072,2073],{},"\"What about secrets in our app?\"",[1005,2075,2076],{},"None — the frontend holds no DB/API secret; execution is server-side",[990,2078,2079,2082],{},[1005,2080,2081],{},"\"How do you handle prod failures?\"",[1005,2083,2084],{},"FailGuard: deduplicated, indexed, reviewed PR proposals — every attempt auditable",[1318,2086,2087],{},[885,2088,2089,2090,2093,2094,2097,2098,2101,2102,2105],{},"The guarantees above — no-custody execution, assume-role access, tenant isolation, the audit log, and FailGuard — are live today. The ",[1087,2091,2092],{},"security.*"," library today carries ",[892,2095,2096],{},"org-level workflow policy"," controls (",[1087,2099,2100],{},"security.org-workflow-policy.*","). A couple of related capabilities are on the roadmap: engine-native security-",[901,2103,2104],{},"assessment"," workflows (authorized posture collection, safe checks, findings triage), and formal compliance attestations (e.g. SOC 2 / ISO). Orkestia provides the evidence-generation primitives today; confirm current status with the team.",[952,2107,2109],{"id":2108},"where-to-go-next","Where to go next",[912,2111,2112,2117,2122,2128,2134,2139],{},[915,2113,2114],{"icon":85,"title":1505,"to":83},[885,2115,2116],{},"The two identity models and how tenant scope is bound from the token.",[915,2118,2119],{"icon":80,"title":1880,"to":459},[885,2120,2121],{},"The live runtime view that pairs with the audit trail.",[915,2123,2125],{"icon":136,"title":2124,"to":223},"Deployment models",[885,2126,2127],{},"Where the control plane and runners sit, and what crosses the boundary.",[915,2129,2131],{"icon":566,"title":2130,"to":196},"Hybrid execution model",[885,2132,2133],{},"Why AI-designed, deterministic-compiled workflows keep the trust boundary clean.",[915,2135,2136],{"icon":285,"title":1329,"to":237},[885,2137,2138],{},"Set up the assume-role + external-ID trust into your account.",[915,2140,2142],{"icon":51,"title":2141,"to":1337},"Reference catalog",[885,2143,2144],{},"Audit, evidence-pack, and FailGuard APIs in full detail.",[2146,2147,2148],"style",{},"html pre.shiki code .sMK4o, html code.shiki .sMK4o{--shiki-light:#39ADB5;--shiki-default:#89DDFF;--shiki-dark:#89DDFF}html pre.shiki code .spNyl, html code.shiki .spNyl{--shiki-light:#9C3EDA;--shiki-default:#C792EA;--shiki-dark:#C792EA}html pre.shiki code .sfazB, html code.shiki .sfazB{--shiki-light:#91B859;--shiki-default:#C3E88D;--shiki-dark:#C3E88D}html pre.shiki code .sBMFI, html code.shiki .sBMFI{--shiki-light:#E2931D;--shiki-default:#FFCB6B;--shiki-dark:#FFCB6B}html pre.shiki code .sbssI, html code.shiki .sbssI{--shiki-light:#F76D47;--shiki-default:#F78C6C;--shiki-dark:#F78C6C}html pre.shiki code .swJcz, html code.shiki .swJcz{--shiki-light:#E53935;--shiki-default:#F07178;--shiki-dark:#F07178}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html pre.shiki code .sHwdD, html code.shiki .sHwdD{--shiki-light:#90A4AE;--shiki-light-font-style:italic;--shiki-default:#546E7A;--shiki-default-font-style:italic;--shiki-dark:#676E95;--shiki-dark-font-style:italic}html pre.shiki code .sTEyZ, html code.shiki .sTEyZ{--shiki-light:#90A4AE;--shiki-default:#EEFFFF;--shiki-dark:#BABED8}html pre.shiki code .s7zQu, html code.shiki .s7zQu{--shiki-light:#39ADB5;--shiki-light-font-style:italic;--shiki-default:#89DDFF;--shiki-default-font-style:italic;--shiki-dark:#89DDFF;--shiki-dark-font-style:italic}html pre.shiki code .s2Zo4, html code.shiki .s2Zo4{--shiki-light:#6182B8;--shiki-default:#82AAFF;--shiki-dark:#82AAFF}",{"title":1085,"searchDepth":1093,"depth":1100,"links":2150},[2151,2152,2153,2154,2155,2156,2157,2158,2159],{"id":954,"depth":1100,"text":955},{"id":1066,"depth":1100,"text":1067},{"id":1350,"depth":1100,"text":1351},{"id":1522,"depth":1100,"text":1523},{"id":1561,"depth":1100,"text":1562},{"id":1724,"depth":1100,"text":1725},{"id":1883,"depth":1100,"text":1884},{"id":1996,"depth":1100,"text":1997},{"id":2108,"depth":1100,"text":2109},"How Orkestia keeps customer code and data out of its custody, isolates every tenant by construction, and gives evaluators an audit trail they can hand to a reviewer","md",null,{},{"icon":141},{"title":138,"description":2160},"pqiVMRA2gFl7mzGwxRHUZx9GY1FN_FVR2HR6j0JEmgo",[2168,2170],{"title":133,"path":134,"stem":135,"description":2169,"icon":136,"children":-1},"Provision, scale, monitor, and decommission self-hosted GitHub Actions runners that live entirely in your own cloud",{"title":143,"path":144,"stem":145,"description":2171,"icon":146,"children":-1},"The ticket ledger and the governed ticket-to-pull-request lifecycle — how production errors become tickets, tickets become plans, and AI coding work lands as verified pull requests without agents ever holding your git credentials",1790354042099]