Skip to main content

GitHub design-partner pilot · Continuous acceptance pending

One bounded agent action, with an exact acceptance gate.

The required run sends a real agent request through an out-of-scope denial, exactly one GitHub issue creation, independent retrieval, Authority Packet export, and offline verification. A separate response-loss case must prove there is no replacement POST. That continuous live acceptance gate has not run yet.

Request a pilot review

Scenario model, not a live acceptance artifact

One request. Two authority outcomes.

Live acceptance not run
A

Outside approved repository

Same typed action, repository outside the effective scope.

denied
Toolwork.issue.create
Decisionrepository_outside_effective_scope
Provider contactNo contact
Outcome claimdenied
Offline packet checksGranular denial checks
B

Inside approved repository

Exact repository, action, workload, run, and content constraints.

effect_confirmed
Toolwork.issue.create
AuthorityDurable reservation
Provider contactAt most one create POST
ObservationIndependent retrieval
Offline packet checksSame-operation evidence

Is this boundary useful for your agent?

The continuous live gate remains pending. Review whether this exact, founder-assisted GitHub profile fits your pilot.

Request a pilot review

Authority chain schema example

Inspect the commitment, not a green badge.

No operation was run. Values below are illustrative and support only the displayed checks.

Each displayed predecessor value matches the prior displayed event hash.No displayed mismatch result is present. Some checks remain not_run.

External anchor receipts

Separate trust domains attach to the packet commitment only when their exact artifacts are present and checked.

  • Rekor inclusionanchor_inclusion_supportednot_run
  • RFC 3161 timestamptimestamp_token_supportednot_run

What acceptance must establish

01A real workload obtains a short-lived credential bound to its run and DPoP key; it receives no GitHub credential.
02One customer-signed grant permits work.issue.create for one exact numeric repository and bounded issue content.
03An out-of-scope request is denied before reservation, credential resolution, or GitHub contact, and its denial packet verifies offline.
04An in-scope request creates exactly one GitHub issue and an independent GET confirms that same provider object.
05The same-operation Authority Packet passes its supported offline checks without calling a RANKIGI service.
06A post-acceptance response-loss run remains indeterminate until recovery and never sends a replacement create request.

Three layers, one accountable boundary

Agent layer

The agent receives work.issue.create, but never receives the GitHub App private key or installation token.

Customer gateway

The gateway validates workload and authority, reserves durably, resolves the customer-held credential, dispatches once, retrieves, and records evidence.

Human authority

An authorized approver defines the repository and action scope and supplies WebAuthn-bound approval evidence; the customer authority signer signs the governed artifacts.

Seven honest outcome states

The packet does not collapse evidence into an aggregate verified badge. It records each outcome state supported by the evidence, and preserves uncertainty and coverage gaps.

deniedThe gateway or provider explicitly refused the operation.
provider_acceptedProvider evidence records acceptance, but not the external effect.
effect_confirmedAn authoritative provider lookup records the effect.
settledPart of the public vocabulary, but this GitHub pilot cannot emit it.
reversedPart of the public vocabulary, but this GitHub pilot cannot emit it.
indeterminateDispatch or outcome cannot yet be resolved honestly.
coverage_gapRequired control or observation coverage is absent or unprovable.

Pilot review

Review what works and what remains.

We will walk through the current gateway, Control, and verifier components, then identify the infrastructure and acceptance work required for your pilot.

Implemented: dedicated customer gateway image, protected configuration and material loading, exact PostgreSQL profile checks, GitHub connector, recovery, packet assembly, and offline protocol vectors.
Pending: customer-owned GitHub App and AWS secret, real workload credential flow, and one retained continuous denial, allowed-create, recovery, and offline-verifier acceptance run.