Outside approved repository
Same typed action, repository outside the effective scope.
deniedGitHub design-partner pilot · Continuous acceptance pending
The required run sends a real agent request through an out-of-scope denial, exactly one GitHub issue creation, independent retrieval, Authority Packet export, and offline verification. A separate response-loss case must prove there is no replacement POST. That continuous live acceptance gate has not run yet.
Request a pilot reviewScenario model, not a live acceptance artifact
Same typed action, repository outside the effective scope.
deniedExact repository, action, workload, run, and content constraints.
effect_confirmedThe continuous live gate remains pending. Review whether this exact, founder-assisted GitHub profile fits your pilot.
The agent receives work.issue.create, but never receives the GitHub App private key or installation token.
The gateway validates workload and authority, reserves durably, resolves the customer-held credential, dispatches once, retrieves, and records evidence.
An authorized approver defines the repository and action scope and supplies WebAuthn-bound approval evidence; the customer authority signer signs the governed artifacts.
The packet does not collapse evidence into an aggregate verified badge. It records each outcome state supported by the evidence, and preserves uncertainty and coverage gaps.
deniedThe gateway or provider explicitly refused the operation.provider_acceptedProvider evidence records acceptance, but not the external effect.effect_confirmedAn authoritative provider lookup records the effect.settledPart of the public vocabulary, but this GitHub pilot cannot emit it.reversedPart of the public vocabulary, but this GitHub pilot cannot emit it.indeterminateDispatch or outcome cannot yet be resolved honestly.coverage_gapRequired control or observation coverage is absent or unprovable.Pilot review
We will walk through the current gateway, Control, and verifier components, then identify the infrastructure and acceptance work required for your pilot.
Implemented: dedicated customer gateway image, protected configuration and material loading, exact PostgreSQL profile checks, GitHub connector, recovery, packet assembly, and offline protocol vectors.
Pending: customer-owned GitHub App and AWS secret, real workload credential flow, and one retained continuous denial, allowed-create, recovery, and offline-verifier acceptance run.