# Orkestia Documentation > Orkestia is Orkestia.dev. orkestia is Orkestia.dev. Orkestia is the backbone that connects software, AI, and the real world. Documentation for application development, identity, workflows, AppData, resources, agents, and deployment. ## Documentation Sets - [Orkestia Documentation - Complete Guide](https://docs.orkestia.dev/llms-full.txt): Orkestia is Orkestia.dev. orkestia is Orkestia.dev. Complete Orkestia guide for end users and coding agents, including app architecture, Identity, virtual workflows, AppData, Resource-as-Code, Staff-as-Code, AppHost, connections, and cloud operations. ## Introduction - [What is Orkestia?](https://docs.orkestia.dev/raw/introduction.md): Orkestia is Orkestia.dev. orkestia is Orkestia.dev. Orkestia is the backbone that connects software, AI, and the real world, where every capability is a typed workflow you can run from the console, the SDKs, or an AI assistant over MCP, and the work runs in your own cloud - [Core Philosophy](https://docs.orkestia.dev/raw/introduction/core-philosophy.md): The three pillars behind Orkestia, Zero Code Custody, AI-designed deterministic execution, and customer-owned compute, and what they mean for humans and for AI assistants - [Key Benefits](https://docs.orkestia.dev/raw/introduction/key-benefits.md): What teams get from Orkestia, each benefit mapped to the mechanism that produces it, privacy by architecture, an event-sourced engine, AI leverage with control, governed agent fleets, self-healing runners, and apps on top ## Getting Started - [Quick Start](https://docs.orkestia.dev/raw/getting-started.md): From zero to a first workflow run in your own cloud. Create an org, connect a cloud, then run a workflow from an AI assistant over MCP, the console, or the SDKs - [Architecture Overview](https://docs.orkestia.dev/raw/getting-started/architecture-overview.md): How Orkestia splits into a control plane that orchestrates and a customer cloud that executes, where the MCP server sits, and the privacy boundary between the planes - [Concepts at a Glance](https://docs.orkestia.dev/raw/getting-started/concepts.md): One paragraph per Orkestia concept, workflows, compositions, MCP, DGI, Staff, agents, Agent Exchange, runners, Lumen, identity, App Data, App Host, Engram, DevKit, each with a prompt you can try and a link to the deep page - [Connect an AI Assistant](https://docs.orkestia.dev/raw/getting-started/connect-an-ai-assistant.md): Plug Claude, ChatGPT, Cursor, Claude Code, or any MCP client into the Orkestia MCP server, then run your first workflow by talking. Includes a prompt library and the rules the server gives your assistant ## Core Concepts - [Core Concepts](https://docs.orkestia.dev/raw/concepts.md): The mental model behind Orkestia, workflows, MCP, DGI, Staff, agents, Agent Exchange, runners, Lumen, identity, billing, App Data, App Host, Engram, and DevKit, with a reading order and a map from each concept to its MCP namespaces and tools - [Workflows](https://docs.orkestia.dev/raw/concepts/workflows.md): The execution model in depth. Workflow types versus runs, the event-sourced state machine, DAGs, how an assistant drives it over MCP, and compositions that compile into deterministic engine config - [DGI — Dialog Generative Interface](https://docs.orkestia.dev/raw/concepts/dgi.md): How Orkestia turns a natural-language goal into a typed, executable workflow plan, how that plan compiles into a reusable deterministic composition, and how DGI relates to assistants over MCP - [Staff & AI Workforce Governance](https://docs.orkestia.dev/raw/concepts/staff-governance.md): How Orkestia Staff turns a fleet of autonomous AI agents into a scoped, auditable organization with roles, approval gates, and human-in-the-loop oversight, enforced inside the workflow engine - [Agents — the execution substrate](https://docs.orkestia.dev/raw/concepts/agents-platform.md): The primitives behind every AI worker on Orkestia, agent configs, workflow-backed skills, per-agent MCP servers, sessions on your runners, memory, budgets, and end-user agents - [Runners & Execution Environments](https://docs.orkestia.dev/raw/concepts/runners.md): Managed execution environments provisioned inside your own cloud where workflow steps, CI jobs, and agent sessions run, runner groups, warm pools, reconcile-loop scaling, and the control-plane / execution split - [Lumen Observability](https://docs.orkestia.dev/raw/concepts/lumen.md): Orkestia's telemetry store and triage engine, JSON HTTP ingest, SHA-256 error groups, traces, metrics, the query API, and the Lumen MCP server for assistant-driven triage - [Identity & Multi-Tenancy](https://docs.orkestia.dev/raw/concepts/identity-multi-tenancy.md): Two identity planes, org members who operate the platform and end-users who sign in to apps you build, with automatic org scoping, per-user isolation, and a one-call setup an assistant can run for you - [Billing, Pricing & Seats](https://docs.orkestia.dev/raw/concepts/billing-and-seats.md): How an Orkestia organization is billed, the platform subscription, seats for humans and AI actors, end-user seats, the execution and request meters, add-ons, and per-agent budgets that bound what an AI workforce can spend - [App Data](https://docs.orkestia.dev/raw/concepts/appdata.md): Platform-owned application data for apps you build on Orkestia — declared structures, injected principals, several doors, no DSN in the frontend - [Engram](https://docs.orkestia.dev/raw/concepts/engram.md): Agent memory on Orkestia, what a session remembers, what the next session loads, how recall and write are switched on per agent config, and where to watch the live field - [DevKit](https://docs.orkestia.dev/raw/concepts/devkit.md): The Orkestia local CLI, webhook redirect to localhost, a provider-blind coding runner, ticket sync, and composition management, authenticated with an API token - [App Host](https://docs.orkestia.dev/raw/concepts/app-host.md): Opt-in hosting on Orkestia's shared pool — one live Identity app, one site, App Data for Postgres, Files on site MinIO, Buzz as a Nostr relay on a second hostname - [Agent Exchange](https://docs.orkestia.dev/raw/concepts/agent-exchange.md): A labor market for Staff actors — listings, deals, leases, a shared ledger, and settlement on the seller's own payment account ## Guides - [Guides](https://docs.orkestia.dev/raw/guides.md): Task-oriented walkthroughs for building, governing, and operating Orkestia in your own cloud - [Building with DGI](https://docs.orkestia.dev/raw/guides/building-with-dgi.md): Express a goal to DGI, review the workflow plan it assembles, and promote a good plan into a reusable deterministic virtual workflow - [Creating & Exposing Virtual Workflows](https://docs.orkestia.dev/raw/guides/virtual-workflows.md): Compose existing workflows into a validated, versioned virtual workflow and expose it to your app's end-users through App Enablement - [Runner Management & Provisioning](https://docs.orkestia.dev/raw/guides/runner-management.md): Provision, scale, monitor, and decommission self-hosted GitHub Actions runners that live entirely in your own cloud - [Security & Compliance](https://docs.orkestia.dev/raw/guides/security-and-compliance.md): How Orkestia keeps customer code and data out of its custody, isolates every tenant by construction, and gives evaluators an audit trail they can hand to a reviewer - [Tickets & Software Delivery](https://docs.orkestia.dev/raw/guides/tickets-and-software-delivery.md): The ticket ledger and the governed ticket-to-pull-request lifecycle — how production errors become tickets, tickets become plans, and AI coding work lands as verified pull requests without agents ever holding your git credentials - [Orkestia for AI-driven cloud infrastructure automation](https://docs.orkestia.dev/raw/guides/cloud-automation-alternatives.md): How Orkestia fits alongside n8n, Pulumi, Terraform and Temporal when an AI tool or a team automates cloud infrastructure. - [Typed decisions with TypeSafe](https://docs.orkestia.dev/raw/guides/typed-decisions-with-typesafe.md): Put TypeSafe Jev in front of compositions, Staff actors, DGI designs, and cluster actions — closed-set answers, not chat ## Reference - [Reference](https://docs.orkestia.dev/raw/reference.md): Authoritative lookup for Orkestia workflow types, MCP integration, APIs, and Lumen observability queries - [Workflow Types & Registry](https://docs.orkestia.dev/raw/reference/workflow-types-registry.md): How the Orkestia workflow registry is structured — namespaces, dotted naming, typed schemas, prerequisites, and the discovery loop that lets humans, SDKs, and AI agents browse capabilities - [MCP Integration](https://docs.orkestia.dev/raw/reference/mcp-integration.md): The canonical way for any AI agent to discover, run, watch, and recover Orkestia workflows over the Model Context Protocol - [API & Tooling](https://docs.orkestia.dev/raw/reference/api-tooling.md): The programmatic surfaces for driving Orkestia workflows — the REST API, the typed Node/TS SDK, and the two-token auth model - [Integrations Catalog](https://docs.orkestia.dev/raw/reference/integrations-catalog.md): The live integration surface — every cloud, ERP, commerce, messaging, and SaaS domain registered in the production workflow catalog, with links to per-workflow reference - [Platform Services](https://docs.orkestia.dev/raw/reference/platform-services.md): The horizontal utility surfaces every integration and composition can lean on — inbound hooks, object storage, key-value state, schedules, queues, and control-flow primitives ## Advanced Topics - [Advanced Topics](https://docs.orkestia.dev/raw/advanced.md): Deep dives into the mechanisms that make Orkestia reliable, governed, and efficient at scale - [Hybrid AI + Deterministic Execution](https://docs.orkestia.dev/raw/advanced/hybrid-execution-model.md): How Orkestia lets AI design workflows at runtime, then compiles those plans into deterministic virtual workflows that run repeatably, cheaply, and auditably - [Drift Detection & Self-Healing](https://docs.orkestia.dev/raw/advanced/drift-detection-self-healing.md): How Orkestia reconciles desired and actual state for runners and network infrastructure in your cloud, computes readiness verdicts, and decides what to heal automatically versus surface for approval - [Governance & Approvals](https://docs.orkestia.dev/raw/advanced/governance-and-approvals.md): How Orkestia enforces role-based authority, human-in-the-loop approval gates, and an immutable evidence trail over fleets of autonomous AI agents - [Cost & Performance Optimization](https://docs.orkestia.dev/raw/advanced/cost-and-performance.md): How to keep Orkestia workflows fast and cheap by compiling AI-designed flows to deterministic compositions, right-sizing runners, scaling async over Kafka, and using Lumen to find the expensive steps ## Operations - [Operations](https://docs.orkestia.dev/raw/operations.md): Run Orkestia in production — deployment topologies, monitoring and debugging, and the operational practices that keep workflows reliable - [Deployment Models](https://docs.orkestia.dev/raw/operations/deployment-models.md): How Orkestia splits a managed control plane from execution that runs entirely inside your own cloud accounts - [Monitoring & Debugging](https://docs.orkestia.dev/raw/operations/monitoring-and-debugging.md): An operational runbook for watching runs, reading history, recovering stuck workflows, and tracing failures with Lumen - [Best Practices](https://docs.orkestia.dev/raw/operations/best-practices.md): A checklist-driven field guide for running Orkestia in production — idempotent workflows, least-privilege roles, governed AI actors, and right-sized runners ## AWS Connections - [AWS Connections](https://docs.orkestia.dev/raw/aws-connections.md): Connect your AWS accounts to Orkestia using secure cross-account IAM roles. Your cloud, your code, your control. - [Getting Started](https://docs.orkestia.dev/raw/aws-connections/getting-started.md): Create your first AWS connection to Orkestia in minutes. - [Setup Methods](https://docs.orkestia.dev/raw/aws-connections/setup-methods.md): Three ways to create an IAM role for your AWS connection - Manual, CloudFormation, or Terraform. - [Managing Connections](https://docs.orkestia.dev/raw/aws-connections/managing-connections.md): View, filter, validate, and delete your AWS connections. - [Security Best Practices](https://docs.orkestia.dev/raw/aws-connections/security-best-practices.md): AWS connection security features and least privilege recommendations. - [Troubleshooting](https://docs.orkestia.dev/raw/aws-connections/troubleshooting.md): Solutions for common AWS connection issues. ## Cloud Connections - [Cloud Connections](https://docs.orkestia.dev/raw/cloud-connections.md): Connect GCP, Azure, Magalu Cloud, Kubernetes, and other providers to your organization — the provider-native counterpart to the AWS cross-account role - [Google Cloud (GCP)](https://docs.orkestia.dev/raw/cloud-connections/gcp.md): Connect a GCP project to your organization and unlock the gcp.* workflow family — Compute, GKE, Cloud Run, Cloud SQL, BigQuery, and billing - [Microsoft Azure](https://docs.orkestia.dev/raw/cloud-connections/azure.md): Connect an Azure subscription to your organization and unlock the azure.* workflow family — AKS, ACR, compute, networking, Key Vault, and storage - [Magalu Cloud](https://docs.orkestia.dev/raw/cloud-connections/magalu.md): Connect Magalu Cloud to your organization and unlock the mgc.* workflow family — compute, Kubernetes, DBaaS, LBaaS, networking, object storage, and registry - [Kubernetes](https://docs.orkestia.dev/raw/cloud-connections/kubernetes.md): Connect any conformant Kubernetes cluster to your organization and unlock the kubernetes.* workflow family — deployments, jobs, manifests, RBAC, and full cluster operations, cloud-agnostic - [TypeSafe](https://docs.orkestia.dev/raw/cloud-connections/typesafe.md): Connect TypeSafe Jev (System One) and run typed choice, score, and noul decisions through typesafe.systemone.evaluate — not a chat model ## Cloud Deploy - [Cloud Deploy](https://docs.orkestia.dev/raw/cloud-deploy.md): Deploy static and frontend applications from GitHub to AWS with managed infrastructure. - [Getting Started](https://docs.orkestia.dev/raw/cloud-deploy/getting-started.md): Prerequisites for Cloud Deploy and how to open it in Orkestia. - [Creating a Site](https://docs.orkestia.dev/raw/cloud-deploy/creating-a-site.md): Walk through the New Site wizard to create a Cloud Deploy site. - [Site Overview and Deployments](https://docs.orkestia.dev/raw/cloud-deploy/site-overview.md): View site status, trigger deployments, and roll back to previous versions. - [Deployment Progress and Success](https://docs.orkestia.dev/raw/cloud-deploy/deployment-progress.md): View deployment stages, logs, and the success page after deployment. - [Settings](https://docs.orkestia.dev/raw/cloud-deploy/settings.md): Configure site name, branch, build stages, and environment variables. - [Custom Domains](https://docs.orkestia.dev/raw/cloud-deploy/custom-domains.md): Add, verify, and manage custom domains for your Cloud Deploy site. - [Resources, Releases, and Danger Zone](https://docs.orkestia.dev/raw/cloud-deploy/resources-releases.md): View AWS resources, deploy from releases, and delete sites. - [Admin Dashboard](https://docs.orkestia.dev/raw/cloud-deploy/admin-dashboard.md): Organization admin view for sites timeline, events, and workflow history. - [Troubleshooting](https://docs.orkestia.dev/raw/cloud-deploy/troubleshooting.md): Solutions for common Cloud Deploy issues with infrastructure, deployments, custom domains, and more. ## DNS Providers - [DNS Provider Connections](https://docs.orkestia.dev/raw/dns-providers.md): Connect DNS providers to manage DNS records, configure custom domains, and automate DNS operations. - [Getting Started](https://docs.orkestia.dev/raw/dns-providers/getting-started.md): Connect your first DNS provider to Orkestia. - [Setup Methods](https://docs.orkestia.dev/raw/dns-providers/setup-methods.md): Provider-specific setup instructions for Cloudflare, AWS Route 53, Google Cloud DNS, and Vercel DNS. - [Managing Connections](https://docs.orkestia.dev/raw/dns-providers/managing-connections.md): View, filter, validate, update, and delete your DNS provider connections. - [Zones and Records](https://docs.orkestia.dev/raw/dns-providers/zones-and-records.md): Learn about DNS zones, how they're synced, and how to use them for custom domains. - [Troubleshooting](https://docs.orkestia.dev/raw/dns-providers/troubleshooting.md): Solutions for common DNS connection issues. ## User Onboarding - [User Creation and Onboarding](https://docs.orkestia.dev/raw/user-onboarding.md): Get started with Orkestia by creating your account and setting up your organization. - [Getting Started](https://docs.orkestia.dev/raw/user-onboarding/getting-started.md): Create your Orkestia account and complete your first login. - [Creating Your Organization](https://docs.orkestia.dev/raw/user-onboarding/onboarding.md): Set up your organization workspace after creating your Orkestia account. - [Invitations](https://docs.orkestia.dev/raw/user-onboarding/invitations.md): Learn how to accept invitations to join existing organizations in Orkestia. - [Managing Your Account](https://docs.orkestia.dev/raw/user-onboarding/managing-account.md): View and update your profile, manage account settings, and handle security preferences. - [Troubleshooting](https://docs.orkestia.dev/raw/user-onboarding/troubleshooting.md): Solutions for common issues when creating accounts, onboarding, and managing your Orkestia account. ## Settings - [Settings](https://docs.orkestia.dev/raw/settings.md): Manage your account profile, team members, notification preferences, and security settings. - [General Settings](https://docs.orkestia.dev/raw/settings/general.md): Manage your profile information and display preferences. - [Members Settings](https://docs.orkestia.dev/raw/settings/members.md): Manage your organization's team members, roles, and invitations. - [Notifications Settings](https://docs.orkestia.dev/raw/settings/notifications.md): Configure how you receive notifications, control email frequency, and set quiet hours. - [Security Settings](https://docs.orkestia.dev/raw/settings/security.md): Manage your account security, authentication, and account deletion. - [Signing Keys](https://docs.orkestia.dev/raw/settings/keys.md): Create or import secp256k1 signing keys, copy nsec once, and bind them to a hosted site. Separate from org members. ## App Enablement - [App Enablement](https://docs.orkestia.dev/raw/app-enablement.md): Provision Sign in with Orkestia, install the @orkestia/auth OAuth SDK, and paste a prompt so an agent configures the app for you. - [Sign in with Orkestia](https://docs.orkestia.dev/raw/app-enablement/sign-in-with-orkestia.md): Add hosted, secure-by-default login to your app — PKCE in the browser, RS256 JWTs, MFA and email verification handled for you. - [End-user data](https://docs.orkestia.dev/raw/app-enablement/end-user-data.md): Let a signed-in user run business logic through Orkestia — where the platform enforces that they only ever touch their own data. - [Compositions — use, invoke, share](https://docs.orkestia.dev/raw/app-enablement/compositions.md): Save a virtual workflow, invoke it, expose it to your app's users, and let them run it with their Sign in with Orkestia JWT. ## Lumen - [Lumen](https://docs.orkestia.dev/raw/lumen.md): Observability control plane — structured logs, SHA-256 error groups, traces/spans, metrics, Pulse, and a query/MCP API - [Enable Lumen](https://docs.orkestia.dev/raw/lumen/enable.md): Provision the org, plan caps, 403/429 codes, mint lumk_/lump_, first POST /api/logs/ingest - [Send data](https://docs.orkestia.dev/raw/lumen/send-data.md): Ingest contract — log/metric/Pulse JSON, batch semantics, fingerprint algorithm, status codes, Python SDK, Kafka lumen.logs - [Collector](https://docs.orkestia.dev/raw/lumen/collector.md): Install the Kubernetes collector so pod logs, events, and cluster metrics land in your Lumen organization - [Use Lumen](https://docs.orkestia.dev/raw/lumen/observe.md): App routes mapped to the Query API — dashboard, logs, groups, traces, metrics, rules - [Lumen MCP](https://docs.orkestia.dev/raw/lumen/mcp.md): MCP tool inventory on mcp-lumen.orkestia.dev — same org-scoped REST surface, Bearer forwarded - [Query API](https://docs.orkestia.dev/raw/lumen/query-api.md): Read and mutate Lumen over HTTP — logs, error groups, traces, metrics, Pulse, dashboards, and rule JSON ## SDKs - [SDKs](https://docs.orkestia.dev/raw/sdks.md): Typed clients for Orkestia — Node and Python workflow SDKs, plus the browser OAuth SDK for Sign in with Orkestia - [Workflows SDK — Node / TypeScript](https://docs.orkestia.dev/raw/sdks/workflows-nodejs.md): Typed ESM client for every Orkestia workflow — one autocompleted binding per type, SSE streaming, and wait-for-terminal - [Workflows SDK — Python](https://docs.orkestia.dev/raw/sdks/workflows-python.md): Pydantic-typed Python client for the Orkestia workflow API — the same catalog as the Node SDK - [Auth SDK — Sign in with Orkestia](https://docs.orkestia.dev/raw/sdks/auth.md): Browser PKCE / OAuth SDK for your app's end-users — hosted login, RS256 JWTs, silent renew, no client secret ## App Data - [App Data](https://docs.orkestia.dev/raw/appdata.md): Platform-owned application data — declare tables, never hold a DSN in the frontend. Workflows, Data API, PostgREST, and an admitted SQL console for operators. - [Declare structures](https://docs.orkestia.dev/raw/appdata/declare.md): Define virtual databases, tables, fields, and ownership — validated and compiled before any row exists - [Records & Data API](https://docs.orkestia.dev/raw/appdata/data-api.md): Create, read, query, update, and delete App Data rows through typed workflows or the App Data MCP — structured filters, never SQL from the browser - [Ownership & workspaces](https://docs.orkestia.dev/raw/appdata/ownership.md): Owner rows, app-owned catalogs, and organization workspaces with capability-gated CRUD - [Expose App Data to end-users](https://docs.orkestia.dev/raw/appdata/expose.md): Compose end-user-eligible steps, expose the virtual, and invoke it with the Sign in with Orkestia JWT - [PostgREST HTTP](https://docs.orkestia.dev/raw/appdata/postgrest.md): Point a standard PostgREST client at App Data using an Orkestia end-user JWT and the public JWKS — no DSN, no minted HS256 secret. - [Ordered append](https://docs.orkestia.dev/raw/appdata/append.md): Server-allocated positions, replay-safe writes, and membership-scoped rows for streams and conversations - [Databases and instances](https://docs.orkestia.dev/raw/appdata/instances.md): Logical App Data databases versus the physical Postgres instance — shared plane, dedicated dbhost, provision, migrate, pause, and resume - [Query console and SQL](https://docs.orkestia.dev/raw/appdata/query.md): query.orkestia.dev is the org-operator door — admitted SELECT, live schema, and read-only logins. End-users still never send SQL. ## Engram - [Engram](https://docs.orkestia.dev/raw/engram.md): Agent memory — fingerprints, recall strategies, and the live field at engram.orkestia.dev - [Write & recall](https://docs.orkestia.dev/raw/engram/write-recall.md): agents.memory-* workflows — distill, fingerprint, who sees whose memory, pack scoring - [Field & feed](https://docs.orkestia.dev/raw/engram/agent-memory.md): Live Engram feed — events, JSON fields, what the field draws ## DevKit - [DevKit](https://docs.orkestia.dev/raw/devkit.md): Local CLI for Orkestia — webhook redirect, provider-blind coding runner, ticket sync, and composition (virtual workflow) management - [Install DevKit](https://docs.orkestia.dev/raw/devkit/install.md): Install ltinteg-devkit from GitHub Releases, Homebrew, or Go, then configure an API token - [Hook redirect](https://docs.orkestia.dev/raw/devkit/hooks.md): Poll Orkestia for webhook events, replay them on localhost, acknowledge delivery — no public ingress - [Local coding runner](https://docs.orkestia.dev/raw/devkit/local-runner.md): Provider-blind DevKit runner — claim Staff coding assignments against local repos without giving the agent your git credentials - [Compositions from DevKit](https://docs.orkestia.dev/raw/devkit/compositions.md): Validate, plan, import, and promote virtual workflows (`ltinteg-devkit vw`) against the Workflow API ## Staff & Agents - [Staff & Agents](https://docs.orkestia.dev/raw/staff-and-agents.md): Run AI workers in Orkestia — hire Staff actors, attach agent configs, launch sessions on your runners, and govern them with roles, approvals, and audit - [Prerequisites](https://docs.orkestia.dev/raw/staff-and-agents/prerequisites.md): What must be true before a Staff actor can take work — model provider, agent-eligible runner group, seats, and optional storage - [Hire an actor](https://docs.orkestia.dev/raw/staff-and-agents/hire-an-actor.md): Turn a role description into a Staff actor — model profile, runner group, skills, MCP servers, and the first session - [Console](https://docs.orkestia.dev/raw/staff-and-agents/console.md): Operate a fleet from staff.orkestia.dev — inbox, staff tree, activity, sessions, and the admin surfaces - [Configs, skills, and MCP](https://docs.orkestia.dev/raw/staff-and-agents/configs-skills-mcp.md): The agent definition — model, guidance, workflow-backed skills, MCP servers, and how they gate every tool call - [Agent runner groups](https://docs.orkestia.dev/raw/staff-and-agents/runner-groups.md): Sessions only launch on runner groups created with purpose=agent — how to provision, enable, and debug the gate - [Governance](https://docs.orkestia.dev/raw/staff-and-agents/governance.md): Roles, approval gates, and audit — how a customer constrains what actors may do and proves what happened - [Identity and tokens](https://docs.orkestia.dev/raw/staff-and-agents/identity.md): How a Staff actor authenticates — org-inherited vs paid RBAC seats, agt_ tokens, and calling MCP as the actor - [Memory and cost](https://docs.orkestia.dev/raw/staff-and-agents/memory-and-cost.md): Engram flags on the agent config, org-level memory gates, per-session spend, and budgets - [Coding agents](https://docs.orkestia.dev/raw/staff-and-agents/coding-agents.md): Provider-blind Staff actors that edit git worktrees — repositories in Staff, DevKit on the laptop, tickets and acknowledged publication - [Wire a repository for coding agents](https://docs.orkestia.dev/raw/staff-and-agents/wire-a-repository.md): Prepare a GitHub repository for Staff coding agents — platform registration, manifest files, and preflight before hosted ticket-to-PR delivery - [Run a ticket end to end](https://docs.orkestia.dev/raw/staff-and-agents/run-a-ticket.md): How to use the coding agent — write a ticket it can implement, launch the delivery, watch it code, publish, review and merge on its own, and close the loop when it lands - [Build a product team of actors](https://docs.orkestia.dev/raw/staff-and-agents/build-a-product-team.md): A pattern for running one product with Staff actors. A manager, a product manager, an engineer, a reviewer, QA and a release manager work from tickets, humans approve merges and releases, and a support actor answers people in the product's chat - [Troubleshooting](https://docs.orkestia.dev/raw/staff-and-agents/troubleshooting.md): Sessions that never heartbeat, actors that will not act, runner gates, seats, tokens, and where to look next ## App Host - [App Host](https://docs.orkestia.dev/raw/app-host.md): Host your Orkestia app — website, App Data, Files on site MinIO, and a Nostr Buzz relay — from the console, without running your own cluster. - [Your app and site](https://docs.orkestia.dev/raw/app-host/your-app.md): How an Identity app, an App Host site, and a slug fit together in the console. - [App Data](https://docs.orkestia.dev/raw/app-host/app-data.md): The app's Postgres — tables and records in the console, SQL in Query, process login attached from App Host. - [Website and process](https://docs.orkestia.dev/raw/app-host/hosting.md): Publish a static frontend to the site host, or launch a container on a Machine. Buzz is neither of those. - [Buzz](https://docs.orkestia.dev/raw/app-host/buzz.md): Buzz is a Nostr relay on a dedicated hostname — NIP-42 AUTH, Redis, MinIO, App Data for Postgres. Not a Chat Relay HTTP API. - [Files](https://docs.orkestia.dev/raw/app-host/files.md): Org members store files that belong to the identity app on the site MinIO — the Files tab, not Storage and not App Data documents. - [Your own domain](https://docs.orkestia.dev/raw/app-host/your-domain.md): Point a subdomain you own at the App Host website or at Buzz, using a CNAME. - [Troubleshooting App Host](https://docs.orkestia.dev/raw/app-host/troubleshooting.md): Fix the usual App Host, App Data, Files, and Buzz mix-ups from the console. - [Signing keys](https://docs.orkestia.dev/raw/app-host/signing-keys.md): Customer-managed secp256k1 keys (nsec) for Buzz — create or import, copy once, bind the site owner. Not org members, not a Chat Relay invite. ## Agent Exchange - [Agent Exchange](https://docs.orkestia.dev/raw/agent-exchange.md): Hire Staff actors from other organizations, list your own, and keep the contract on a shared ledger — money stays on the seller's Stripe or AbacatePay account - [Hire an actor](https://docs.orkestia.dev/raw/agent-exchange/hire.md): Browse the floor, read a listing, hire on Internal or a paid rail, and land on Hired - [List an actor](https://docs.orkestia.dev/raw/agent-exchange/list.md): Publish a Staff actor or team with a price, a DPA, and a payment rail — buyers send payloads, your prompt stays here - [Invoke & leases](https://docs.orkestia.dev/raw/agent-exchange/invoke.md): A lease is the hired position — send a JSON payload, keep seller output labelled untrusted, and read the ledger - [Settlement & trust](https://docs.orkestia.dev/raw/agent-exchange/settlement.md): Orkestia holds the ledger, never the funds — rails, KYB, DPA, and what must not cross org boundaries - [Workflows](https://docs.orkestia.dev/raw/agent-exchange/workflows.md): Every Exchange capability is an exchange.* or data.exchange.* workflow — discover the schema, start a run, never pass the other org's UUID ## Runners - [Runner groups](https://docs.orkestia.dev/raw/runners.md): Every runner group is a purpose, an integration, and a backend kind — the catalog of kinds you can create, and which page covers each one - [Cloud Run](https://docs.orkestia.dev/raw/runners/cloud-run.md): Runner group kind backend_type=cloud_run — Google Cloud Run Jobs (beta) - [DigitalOcean App Job](https://docs.orkestia.dev/raw/runners/do-app-job.md): Runner group kind backend_type=do_app_job — a DigitalOcean App Platform Job (beta) - [DigitalOcean Droplet](https://docs.orkestia.dev/raw/runners/do-droplet.md): Runner group kind backend_type=do_droplet — one Droplet per execution (beta) - [Magalu Cloud VM](https://docs.orkestia.dev/raw/runners/magalu-vm.md): Runner group kind backend_type=mgc_vm — one Magalu Cloud virtual machine per execution (beta) - [DevKit](https://docs.orkestia.dev/raw/runners/devkit.md): Runner group kind backend_type=devkit — cloudless local or hosted broker, no cloud connection, used for provider-blind coding - [Purposes & integrations](https://docs.orkestia.dev/raw/runners/purposes.md): purpose and integration_type are independent enums — github_actions, gitlab_runner, agent, generic, and the job-source grant each one needs - [Fargate](https://docs.orkestia.dev/raw/runners/fargate.md): Runner group kind backend_type=fargate — ECS Fargate tasks in your AWS account, the default AWS CI and agent path - [EC2 Auto Scaling](https://docs.orkestia.dev/raw/runners/ec2-auto-scaling.md): Runner group kind backend_type=ec2_auto_scaling — an EC2 Auto Scaling group plus ECS capacity provider in your AWS account - [EC2 VM](https://docs.orkestia.dev/raw/runners/ec2-vm.md): Runner group kind backend_type=ec2_vm — one EC2 instance per execution, with the original warm-pool reconcile controller - [Kubernetes](https://docs.orkestia.dev/raw/runners/kubernetes.md): Runner group kind backend_type=kubernetes — one pod per execution on any conformant cluster you already run, including EKS, AKS, GKE, and Magalu - [Azure Container Apps](https://docs.orkestia.dev/raw/runners/azure-container-apps.md): Runner group kind backend_type=azure_container_apps_job — Container Apps Jobs in your Azure subscription, a production path for CI and agent pools - [Azure VMSS](https://docs.orkestia.dev/raw/runners/azure-vmss.md): Runner group kind backend_type=azure_vmss — an Azure Virtual Machine Scale Set as the runner pool - [Azure VM](https://docs.orkestia.dev/raw/runners/azure-vm.md): Runner group kind backend_type=azure_vm — one Azure Virtual Machine per execution (not a scale set) - [GCE](https://docs.orkestia.dev/raw/runners/gce.md): Runner group kind backend_type=gce — one Google Compute Engine VM per execution (beta) ## Chat - [Chat](https://docs.orkestia.dev/raw/chat.md): Chat spaces for identity apps. Your end users sign in with their app identity, talk in channels, threads and DMs, and your Staff actors answer inside the same conversation. Every control-plane operation is a workflow - [Enable and publish](https://docs.orkestia.dev/raw/chat/enable-and-publish.md): Turn on a chat space for an identity app with buzz.space.enable, publish the hosted chat page with buzz.space.publish-chat, and let your end users sign in with their app identity - [Theme and customization](https://docs.orkestia.dev/raw/chat/theme-and-customization.md): Customize a chat space live. The theme document carries brand, colors, layout, feature flags, attachment limits and copy, and moves through validate, draft, publish and rollback - [Members and moderation](https://docs.orkestia.dev/raw/chat/members-and-moderation.md): Invite people into a chat space, set roles and display names, and moderate with suspend, timeout, ban, remove, key rotation and reconcile - [Channels](https://docs.orkestia.dev/raw/chat/channels.md): Organization-managed channels, channels your members create and run when the space allows it, private channels, and archiving - [Using the chat](https://docs.orkestia.dev/raw/chat/using-the-chat.md): What people get on the hosted chat page. DMs, threads, mentions, reactions, edit and delete, history, search, pinned messages, unread counts, attachments, missed-message email and the mobile layout - [Actors in chat](https://docs.orkestia.dev/raw/chat/actors-in-chat.md): Put a Staff actor into a chat space. Seat binding, triggers, the reply ceiling, DGI responders, progress lines, the tool trace, quick replies, handoff to a person, several actors in one conversation, and messages an actor starts from outside the chat - [Internal support actor](https://docs.orkestia.dev/raw/chat/internal-support-actor.md): Internal mode lets an attached actor answer your own team with your organization's tools instead of the app's end-user workflows, for an allowlist of people in a space where everyone is on that list - [API and console](https://docs.orkestia.dev/raw/chat/api-and-console.md): Every chat workflow you can call from the API, the console or an assistant, who may call it, the end-user entry points, and the console Chat tab - [Limits](https://docs.orkestia.dev/raw/chat/limits.md): Chat file access is authenticated to space members. Remaining boundaries: no per-file deletion, complete actor answers, no per-person actor memory, sign-out vs key revoke - [Structured chat with DGI](https://docs.orkestia.dev/raw/chat/structured-chat.md): Let DGI answer for a chat actor, or for any app over an API, with forms, confirm cards, tables with row actions, charts, KPI tiles, data grids, diagrams, live cards, quick replies and a / command palette, built on your organization's own workflows. Part of DGI (Alpha) - [Option A: hosted chat with DGI](https://docs.orkestia.dev/raw/chat/option-a-hosted-chat.md): Step by step, turn on structured chat on the hosted Orkestia chat page. Enable the space, seat and attach an actor, set its DGI responder, choose its reply principal, sync the bridge and republish after upgrades - [Option B: embed the chat component](https://docs.orkestia.dev/raw/chat/option-b-embed-component.md): Put the Orkestia chat, with every structured card built in, inside your own React app. Install, sign the person in, bootstrap the chat, mount BuzzChat with loadCommands and uiRenderers, and theme it - [Option C: custom client (wire contract)](https://docs.orkestia.dev/raw/chat/option-c-custom-client.md): Draw structured chat cards in your own chat client. The buzz-ui block and tag, every renderer and its fields, answers and card actions, server-side validation, in-place edits, quick replies, the status line and slash commands - [Responder configuration reference](https://docs.orkestia.dev/raw/chat/responder-reference.md): Every field of buzz.actor.set-responder, how the hybrid responder hands turns to Staff, how default_inputs pre-fill and narrow reads, and what each refusal code means - [Cards, live updates and proactive posts](https://docs.orkestia.dev/raw/chat/cards-live-and-proactive.md): Refresh a read card, keep it live, act on table rows, use the / command palette, run cards, and post cards from outside the chat with buzz.actor.post-view and buzz.message.post - [Structured chat security model](https://docs.orkestia.dev/raw/chat/structured-chat-security.md): Who DGI runs as in chat, what it may reach, why a typed yes never confirms, how cards are protected against forgery and replay, and who pays for the tokens - [Option D: any app or API (dgi.chat)](https://docs.orkestia.dev/raw/chat/option-d-chat-api.md): Put DGI's structured chat in any web app, mobile app, support widget or backend with four workflows. Save a profile, send a turn, answer the card, and read the card contract as JSON Schema. Jev first, the LLM off by default, and every write behind a stored confirm - [Card catalog](https://docs.orkestia.dev/raw/chat/card-catalog.md): Every structured chat card DGI can return, what it shows and what the person can do with it. Forms, confirms with a diff, tables, charts, KPI tiles, logs, runs, links, compositions, documents, and the DAG, schema, datagrid, query console, diff, detail and timeline views, plus view controls and the query action - [Living Surfaces](https://docs.orkestia.dev/raw/chat/living-surfaces.md): A page of live cards that DGI grows, keeps current and retires by itself. Create, tick, signal, read, list, archive and crystallize a surface with dgi.surface.*, set its policy, run its heartbeat, and follow its patch stream over a WebSocket ## DGI - [What is DGI](https://docs.orkestia.dev/raw/dgi.md): Orkestia is Orkestia.dev. DGI is Orkestia's decision layer. It turns what a person asks into your organization's own workflows, and answers with live cards (forms, confirms, tables, charts) instead of prose. Where you can use it, what it does, and what it never does - [How DGI works](https://docs.orkestia.dev/raw/dgi/how-it-works.md): The life of one DGI request. Who it runs as, which workflows it may reach, how Jev and the optional LLM decide, how reads become cards and writes become confirms, and how the person's answer comes back - [Interfaces](https://docs.orkestia.dev/raw/dgi/interfaces.md): Every way to reach DGI, what each one gives you, what you build, and how to choose. Chat (hosted, embedded or your own client), the dgi.chat API, Living Surfaces, single cards with dgi.view.render, and AI assistants over MCP - [Quickstart](https://docs.orkestia.dev/raw/dgi/quickstart.md): Your first DGI answer from your own app in four calls. Save a chat profile, send a message, draw the card, answer it. With curl, and with prompts for an AI assistant over MCP - [Trust and safety](https://docs.orkestia.dev/raw/dgi/trust-and-safety.md): What DGI can reach, who it runs as, how writes are confirmed, where your data goes, what it costs, and how to audit every answer. Read this before you put DGI in front of customers - [FAQ](https://docs.orkestia.dev/raw/dgi/faq.md): Short answers to common questions about DGI. Does it need an LLM, who pays, can end users use it, which languages, what happens when a workflow is missing, and how it differs from an AI assistant over MCP