Constellations · drawn policy
orrery/publish-gate@0.1.0
Publication-authority seam: prior artifact envelope → publish-profile write-authority → optional witness → release seal (no deploy)
What to pass
prior-artifact → write-authority-check → human-witness → artifact-seal
What you get
Dispositions: released, denied, awaiting_witness, inconclusive
gate (must verify)
repair loop (bounded)
fan-in
Composite receipt
constellation: orrery/publish-gate@0.1.0policy_digest: sha256:9558c98065ca4e6b5fd73c7e83f6a0e759b7a94f516cb579f8b535cbefd3c3c9 chain: 1. prior-artifact Envelope ✓ authorized edit prior 2. write-authority-check Envelope ✓ publish profile grant 3. human-witness optional awaiting_witness if required release: sha256:publish-gate… signed orrery-publish-gate-1
Why this isn't CI YAML
Same graph from any harness. Stars can live in different namespaces. Edges require verified Envelopes — not green checkmarks in one repo.