Orrery.

Constellations · drawn policy

orrery/authorized-content-patch@0.1.0

Governed content edit path: readiness → write-authority → patch-capture → sealed composite (never applies patches)

What to pass

manifest-bind → manifest-preflight → structure-audit → link-check-bounded → write-authority-check → patch-capture → artifact-seal

  • before* array · [{path, content, format?}]; may be empty
  • after* array · [{path, content, format?}] assessed for readiness
  • authority* object · policy, allowed_paths, grant_digest, optional witness
  • policy string · orrery/docs-only@v1 or orrery/max-100-files@v1
  • max_link_count integer · 1..50; default 20

What you get

  • disposition string
  • stages object
  • envelope signed-envelope

Dispositions: authorized, denied, needs-work, inconclusive

gate (must verify) repair loop (bounded) fan-in

Composite receipt

constellation: orrery/authorized-content-patch@0.1.0policy_digest: sha256:0291d0d36a523d7cddcaac374cdbfd16f1e750a1b07685d44532a707ae409008
chain:
  1. manifest-bind     Envelope ✓  after inventory
  2. manifest-preflight     Envelope ✓  named policy
  3. structure-audit     Envelope ✓  markdown findings
  4. link-check-bounded     Envelope ✓  bounded HTTPS
  5. write-authority-check     Envelope ✓  explicit grant
  6. patch-capture     Envelope ✓  before/after digest
release: sha256:authorized-content-patch…  signed orrery-authorized-content-patch-1

Why this isn't CI YAML

Same graph from any harness. Stars can live in different namespaces. Edges require verified Envelopes — not green checkmarks in one repo.