Pushgate.devDocs Open Pushgate.dev

Onboarding ceremonies

Follow each operation from reviewed inputs to confirmed results.

On this page

Each handoff has separate authority and completion evidence. Green status at one step does not complete the next. These diagrams describe the normal path; refusals and uncertain outcomes stop for authoritative readback.

Account and workspace

Human works with Platform.

  1. Sign in or register.
  2. Establish tenant membership.
  3. Read signed-in workspace.

Recovery: Authentication failure stops onboarding.

Account and workspace flowSign in or register; Establish tenant membership; Read signed-in workspace. Authentication failure stops onboardingSign in or register→Establish tenant membership→Read signed-in workspace↓ Refused or uncertainStop and inspect authoritative state
Account and workspace: Sign in or register → Establish tenant membership → Read signed-in workspace.
Mermaid source
flowchart LR
    R["Sign in or register"] --> E["Establish tenant membership"]
    E -->|confirmed| C["Read signed-in workspace"]
    E -->|refused or uncertain| F["Stop and inspect authoritative state"]
Account and workspace sequenceSign in or register; Establish tenant membership; Read signed-in workspace. Authentication failure stops onboardingHumanPlatformSign in or registerEstablish tenant membershipRead signed-in workspace
Account and workspace: Sign in or register → Establish tenant membership → Read signed-in workspace.
Mermaid source
sequenceDiagram
    actor A as Human
    participant S as Platform
    A->>S: Sign in or register
    S-->>A: Exact review or prerequisite status
    A->>S: Establish tenant membership
    S-->>A: Read signed-in workspace
    Note over A,S: Refused or uncertain outcomes stop for readback

GitHub installation

Human works with GitHub and platform.

  1. Choose GitHub account and repositories.
  2. Approve App access.
  3. Read complete authorized repository catalog.

Recovery: Missing or partial catalog cannot grant repository access.

GitHub installation flowChoose GitHub account and repositories; Approve App access; Read complete authorized repository catalog. Missing or partial catalog cannot grant repository accessChoose GitHub account andrepositories→Approve App access→Read complete authorizedrepository catalog↓ Refused or uncertainStop and inspect authoritative state
GitHub installation: Choose GitHub account and repositories → Approve App access → Read complete authorized repository catalog.
Mermaid source
flowchart LR
    R["Choose GitHub account and repositories"] --> E["Approve App access"]
    E -->|confirmed| C["Read complete authorized repository catalog"]
    E -->|refused or uncertain| F["Stop and inspect authoritative state"]
GitHub installation sequenceChoose GitHub account and repositories; Approve App access; Read complete authorized repository catalog. Missing or partial catalog cannot grant repository accessHumanGitHub and platformChoose GitHub account and repositoriesApprove App accessRead complete authorized repository catalog
GitHub installation: Choose GitHub account and repositories → Approve App access → Read complete authorized repository catalog.
Mermaid source
sequenceDiagram
    actor A as Human
    participant S as GitHub and platform
    A->>S: Choose GitHub account and repositories
    S-->>A: Exact review or prerequisite status
    A->>S: Approve App access
    S-->>A: Read complete authorized repository catalog
    Note over A,S: Refused or uncertain outcomes stop for readback

Connect and register repository

Human works with Pushgate and platform.

  1. Review exact repository and default protection.
  2. Connect and register immutable GitHub repository ID.
  3. Confirm enrollment_registered and delivery readiness separately.

Recovery: Registration failure cannot become successful enrollment; Check delivery performs explicit repair when registration is required.

Connect and register repository flowReview exact repository and default protection; Connect and register immutable GitHub repository ID; Confirm enrollment_registered and delivery readiness separately. Registration failure cannot become successful enrollment; Check delivery performs explicit repair when registration is requiredReview exact repository anddefault protection→Connect and registerimmutable GitHub repositoryID→Confirmenrollment_registered anddelivery readinessseparately↓ Refused or uncertainStop and inspect authoritative state
Connect and register repository: Review exact repository and default protection → Connect and register immutable GitHub repository ID → Confirm enrollment_registered and delivery readiness separately.
Mermaid source
flowchart LR
    R["Review exact repository and default protection"] --> E["Connect and register immutable GitHub repository ID"]
    E -->|confirmed| C["Confirm enrollment_registered and delivery readiness separately"]
    E -->|refused or uncertain| F["Stop and inspect authoritative state"]
Connect and register repository sequenceReview exact repository and default protection; Connect and register immutable GitHub repository ID; Confirm enrollment_registered and delivery readiness separately. Registration failure cannot become successful enrollment; Check delivery performs explicit repair when registration is requiredHumanPushgate and platformReview exact repository and default protectionConnect and register immutable GitHub repository IDConfirm enrollment_registered and delivery readinessseparately
Connect and register repository: Review exact repository and default protection → Connect and register immutable GitHub repository ID → Confirm enrollment_registered and delivery readiness separately.
Mermaid source
sequenceDiagram
    actor A as Human
    participant S as Pushgate and platform
    A->>S: Review exact repository and default protection
    S-->>A: Exact review or prerequisite status
    A->>S: Connect and register immutable GitHub repository ID
    S-->>A: Confirm enrollment_registered and delivery readiness separately
    Note over A,S: Refused or uncertain outcomes stop for readback

Agent setup link

Human and agent works with Pushgate.

  1. Request a repository setup link.
  2. Agent consumes instructions and push credential.
  3. Inspect exact configured remote.

Recovery: A new link does not enroll an agent or repair a missing platform repository.

Agent setup link flowRequest a repository setup link; Agent consumes instructions and push credential; Inspect exact configured remote. A new link does not enroll an agent or repair a missing platform repositoryRequest a repository setuplink→Agent consumes instructionsand push credential→Inspect exact configuredremote↓ Refused or uncertainStop and inspect authoritative state
Agent setup link: Request a repository setup link → Agent consumes instructions and push credential → Inspect exact configured remote.
Mermaid source
flowchart LR
    R["Request a repository setup link"] --> E["Agent consumes instructions and push credential"]
    E -->|confirmed| C["Inspect exact configured remote"]
    E -->|refused or uncertain| F["Stop and inspect authoritative state"]
Agent setup link sequenceRequest a repository setup link; Agent consumes instructions and push credential; Inspect exact configured remote. A new link does not enroll an agent or repair a missing platform repositoryHuman and agentPushgateRequest a repository setup linkAgent consumes instructions and push credentialInspect exact configured remote
Agent setup link: Request a repository setup link → Agent consumes instructions and push credential → Inspect exact configured remote.
Mermaid source
sequenceDiagram
    actor A as Human and agent
    participant S as Pushgate
    A->>S: Request a repository setup link
    S-->>A: Exact review or prerequisite status
    A->>S: Agent consumes instructions and push credential
    S-->>A: Inspect exact configured remote
    Note over A,S: Refused or uncertain outcomes stop for readback

Enroll agent

Human and CI/lock works with Platform.

  1. Review exact repository scope, name and lifetime.
  2. Fresh bound passkey approval; seal credential to CI/lock.
  3. Redeem credential and read active agent status.

Recovery: Missing, ambiguous, revoked, expired or undelivered scope refuses; never substitute an empty or broader scope.

Enroll agent flowReview exact repository scope, name and lifetime; Fresh bound passkey approval; seal credential to CI/lock; Redeem credential and read active agent status. Missing, ambiguous, revoked, expired or undelivered scope refuses; never substitute an empty or broader scopeReview exact repositoryscope, name and lifetime→Fresh bound passkeyapproval; seal credentialto CI/lock→Redeem credential and readactive agent status↓ Refused or uncertainStop and inspect authoritative state
Enroll agent: Review exact repository scope, name and lifetime → Fresh bound passkey approval; seal credential to CI/lock → Redeem credential and read active agent status.
Mermaid source
flowchart LR
    R["Review exact repository scope, name and lifetime"] --> E["Fresh bound passkey approval; seal credential to CI/lock"]
    E -->|confirmed| C["Redeem credential and read active agent status"]
    E -->|refused or uncertain| F["Stop and inspect authoritative state"]
Enroll agent sequenceReview exact repository scope, name and lifetime; Fresh bound passkey approval; seal credential to CI/lock; Redeem credential and read active agent status. Missing, ambiguous, revoked, expired or undelivered scope refuses; never substitute an empty or broader scopeHuman and CI/lockPlatformReview exact repository scope, name and lifetimeFresh bound passkey approval; seal credential to CI/lockRedeem credential and read active agent status
Enroll agent: Review exact repository scope, name and lifetime → Fresh bound passkey approval; seal credential to CI/lock → Redeem credential and read active agent status.
Mermaid source
sequenceDiagram
    actor A as Human and CI/lock
    participant S as Platform
    A->>S: Review exact repository scope, name and lifetime
    S-->>A: Exact review or prerequisite status
    A->>S: Fresh bound passkey approval; seal credential to CI/lock
    S-->>A: Redeem credential and read active agent status
    Note over A,S: Refused or uncertain outcomes stop for readback

Create and validate policy

Human or agent works with Pushgate and platform.

  1. Choose checks and inspect generated source.
  2. Save draft generation; validate exact source digest.
  3. Read validation for that saved generation.

Recovery: Description over 512 UTF-8 bytes refuses before save; validation is not signing or enforcement.

Create and validate policy flowChoose checks and inspect generated source; Save draft generation; validate exact source digest; Read validation for that saved generation. Description over 512 UTF-8 bytes refuses before save; validation is not signing or enforcementChoose checks and inspectgenerated source→Save draft generation;validate exact sourcedigest→Read validation for thatsaved generation↓ Refused or uncertainStop and inspect authoritative state
Create and validate policy: Choose checks and inspect generated source → Save draft generation; validate exact source digest → Read validation for that saved generation.
Mermaid source
flowchart LR
    R["Choose checks and inspect generated source"] --> E["Save draft generation; validate exact source digest"]
    E -->|confirmed| C["Read validation for that saved generation"]
    E -->|refused or uncertain| F["Stop and inspect authoritative state"]
Create and validate policy sequenceChoose checks and inspect generated source; Save draft generation; validate exact source digest; Read validation for that saved generation. Description over 512 UTF-8 bytes refuses before save; validation is not signing or enforcementHuman or agentPushgate and platformChoose checks and inspect generated sourceSave draft generation; validate exact source digestRead validation for that saved generation
Create and validate policy: Choose checks and inspect generated source → Save draft generation; validate exact source digest → Read validation for that saved generation.
Mermaid source
sequenceDiagram
    actor A as Human or agent
    participant S as Pushgate and platform
    A->>S: Choose checks and inspect generated source
    S-->>A: Exact review or prerequisite status
    A->>S: Save draft generation; validate exact source digest
    S-->>A: Read validation for that saved generation
    Note over A,S: Refused or uncertain outcomes stop for readback

Review, sign and publish

Human works with Platform via Pushgate.

  1. Open review for saved validated revision.
  2. Review prepared bytes; fresh passkey signs and publishes.
  3. Read signed result and exact immutable release tuple.

Recovery: Preparation refusal identifies cause; unknown opening outcome requires readback, never blind retry.

Review, sign and publish flowOpen review for saved validated revision; Review prepared bytes; fresh passkey signs and publishes; Read signed result and exact immutable release tuple. Preparation refusal identifies cause; unknown opening outcome requires readback, never blind retryOpen review for savedvalidated revision→Review prepared bytes;fresh passkey signs andpublishes→Read signed result andexact immutable releasetuple↓ Refused or uncertainStop and inspect authoritative state
Review, sign and publish: Open review for saved validated revision → Review prepared bytes; fresh passkey signs and publishes → Read signed result and exact immutable release tuple.
Mermaid source
flowchart LR
    R["Open review for saved validated revision"] --> E["Review prepared bytes; fresh passkey signs and publishes"]
    E -->|confirmed| C["Read signed result and exact immutable release tuple"]
    E -->|refused or uncertain| F["Stop and inspect authoritative state"]
Review, sign and publish sequenceOpen review for saved validated revision; Review prepared bytes; fresh passkey signs and publishes; Read signed result and exact immutable release tuple. Preparation refusal identifies cause; unknown opening outcome requires readback, never blind retryHumanPlatform via PushgateOpen review for saved validated revisionReview prepared bytes; fresh passkey signs and publishesRead signed result and exact immutable release tuple
Review, sign and publish: Open review for saved validated revision → Review prepared bytes; fresh passkey signs and publishes → Read signed result and exact immutable release tuple.
Mermaid source
sequenceDiagram
    actor A as Human
    participant S as Platform via Pushgate
    A->>S: Open review for saved validated revision
    S-->>A: Exact review or prerequisite status
    A->>S: Review prepared bytes; fresh passkey signs and publishes
    S-->>A: Read signed result and exact immutable release tuple
    Note over A,S: Refused or uncertain outcomes stop for readback

Assign policy

Human owner or admin works with Pushgate and platform.

  1. Review exact repository, before/after tuple, mode and reason.
  2. Fresh bound approval; consume once under generation fence.
  3. Read assignment and new repository generation.

Recovery: Stale generation or uncertain response requires authoritative readback; publication alone never assigns.

Assign policy flowReview exact repository, before/after tuple, mode and reason; Fresh bound approval; consume once under generation fence; Read assignment and new repository generation. Stale generation or uncertain response requires authoritative readback; publication alone never assignsReview exact repository,before/after tuple, modeand reason→Fresh bound approval;consume once undergeneration fence→Read assignment and newrepository generation↓ Refused or uncertainStop and inspect authoritative state
Assign policy: Review exact repository, before/after tuple, mode and reason → Fresh bound approval; consume once under generation fence → Read assignment and new repository generation.
Mermaid source
flowchart LR
    R["Review exact repository, before/after tuple, mode and reason"] --> E["Fresh bound approval; consume once under generation fence"]
    E -->|confirmed| C["Read assignment and new repository generation"]
    E -->|refused or uncertain| F["Stop and inspect authoritative state"]
Assign policy sequenceReview exact repository, before/after tuple, mode and reason; Fresh bound approval; consume once under generation fence; Read assignment and new repository generation. Stale generation or uncertain response requires authoritative readback; publication alone never assignsHuman owner or adminPushgate and platformReview exact repository, before/after tuple, mode andreasonFresh bound approval; consume once under generation fenceRead assignment and new repository generation
Assign policy: Review exact repository, before/after tuple, mode and reason → Fresh bound approval; consume once under generation fence → Read assignment and new repository generation.
Mermaid source
sequenceDiagram
    actor A as Human owner or admin
    participant S as Pushgate and platform
    A->>S: Review exact repository, before/after tuple, mode and reason
    S-->>A: Exact review or prerequisite status
    A->>S: Fresh bound approval; consume once under generation fence
    S-->>A: Read assignment and new repository generation
    Note over A,S: Refused or uncertain outcomes stop for readback

Produce policy evidence

Enrolled agent works with CI/lock and platform.

  1. Inspect exact commit, required step and command.
  2. Run command through CI/lock; sign and upload as agent.
  3. Check stored evidence and commit bindings.

Recovery: Failed command or unavailable upload cannot be reported as passing evidence; no human-session fallback.

Produce policy evidence flowInspect exact commit, required step and command; Run command through CI/lock; sign and upload as agent; Check stored evidence and commit bindings. Failed command or unavailable upload cannot be reported as passing evidence; no human-session fallbackInspect exact commit,required step and command→Run command throughCI/lock; sign and upload asagent→Check stored evidence andcommit bindings↓ Refused or uncertainStop and inspect authoritative state
Produce policy evidence: Inspect exact commit, required step and command → Run command through CI/lock; sign and upload as agent → Check stored evidence and commit bindings.
Mermaid source
flowchart LR
    R["Inspect exact commit, required step and command"] --> E["Run command through CI/lock; sign and upload as agent"]
    E -->|confirmed| C["Check stored evidence and commit bindings"]
    E -->|refused or uncertain| F["Stop and inspect authoritative state"]
Produce policy evidence sequenceInspect exact commit, required step and command; Run command through CI/lock; sign and upload as agent; Check stored evidence and commit bindings. Failed command or unavailable upload cannot be reported as passing evidence; no human-session fallbackEnrolled agentCI/lock and platformInspect exact commit, required step and commandRun command through CI/lock; sign and upload as agentCheck stored evidence and commit bindings
Produce policy evidence: Inspect exact commit, required step and command → Run command through CI/lock; sign and upload as agent → Check stored evidence and commit bindings.
Mermaid source
sequenceDiagram
    actor A as Enrolled agent
    participant S as CI/lock and platform
    A->>S: Inspect exact commit, required step and command
    S-->>A: Exact review or prerequisite status
    A->>S: Run command through CI/lock; sign and upload as agent
    S-->>A: Check stored evidence and commit bindings
    Note over A,S: Refused or uncertain outcomes stop for readback

Evaluate and push

Enrolled agent works with Pushgate and platform.

  1. Submit signed Git push for exact refs and commit.
  2. Verify identity and evidence; evaluate immutable policy; store VSA.
  3. Read refusal or admission with exact commit.

Recovery: Denial leaves upstream unchanged; missing decision provenance is unavailable in every mode.

Evaluate and push flowSubmit signed Git push for exact refs and commit; Verify identity and evidence; evaluate immutable policy; store VSA; Read refusal or admission with exact commit. Denial leaves upstream unchanged; missing decision provenance is unavailable in every modeSubmit signed Git push forexact refs and commit→Verify identity andevidence; evaluateimmutable policy; store VSA→Read refusal or admissionwith exact commit↓ Refused or uncertainStop and inspect authoritative state
Evaluate and push: Submit signed Git push for exact refs and commit → Verify identity and evidence; evaluate immutable policy; store VSA → Read refusal or admission with exact commit.
Mermaid source
flowchart LR
    R["Submit signed Git push for exact refs and commit"] --> E["Verify identity and evidence; evaluate immutable policy; store VSA"]
    E -->|confirmed| C["Read refusal or admission with exact commit"]
    E -->|refused or uncertain| F["Stop and inspect authoritative state"]
Evaluate and push sequenceSubmit signed Git push for exact refs and commit; Verify identity and evidence; evaluate immutable policy; store VSA; Read refusal or admission with exact commit. Denial leaves upstream unchanged; missing decision provenance is unavailable in every modeEnrolled agentPushgate and platformSubmit signed Git push for exact refs and commitVerify identity and evidence; evaluate immutable policy;store VSARead refusal or admission with exact commit
Evaluate and push: Submit signed Git push for exact refs and commit → Verify identity and evidence; evaluate immutable policy; store VSA → Read refusal or admission with exact commit.
Mermaid source
sequenceDiagram
    actor A as Enrolled agent
    participant S as Pushgate and platform
    A->>S: Submit signed Git push for exact refs and commit
    S-->>A: Exact review or prerequisite status
    A->>S: Verify identity and evidence; evaluate immutable policy; store VSA
    S-->>A: Read refusal or admission with exact commit
    Note over A,S: Refused or uncertain outcomes stop for readback

Deliver and confirm

Pushgate observer works with GitHub and receipt notary.

  1. Forward admitted update once.
  2. Persist terminal upstream result and receipt request.
  3. Read delivered ref; verify receipt where supported.

Recovery: Queued is not delivered; retry persisted receipt without forwarding again; receipt availability is version/profile dependent.

Deliver and confirm flowForward admitted update once; Persist terminal upstream result and receipt request; Read delivered ref; verify receipt where supported. Queued is not delivered; retry persisted receipt without forwarding again; receipt availability is version/profile dependentForward admitted updateonce→Persist terminal upstreamresult and receipt request→Read delivered ref; verifyreceipt where supported↓ Refused or uncertainStop and inspect authoritative state
Deliver and confirm: Forward admitted update once → Persist terminal upstream result and receipt request → Read delivered ref; verify receipt where supported.
Mermaid source
flowchart LR
    R["Forward admitted update once"] --> E["Persist terminal upstream result and receipt request"]
    E -->|confirmed| C["Read delivered ref; verify receipt where supported"]
    E -->|refused or uncertain| F["Stop and inspect authoritative state"]
Deliver and confirm sequenceForward admitted update once; Persist terminal upstream result and receipt request; Read delivered ref; verify receipt where supported. Queued is not delivered; retry persisted receipt without forwarding again; receipt availability is version/profile dependentPushgate observerGitHub and receipt notaryForward admitted update oncePersist terminal upstream result and receipt requestRead delivered ref; verify receipt where supported
Deliver and confirm: Forward admitted update once → Persist terminal upstream result and receipt request → Read delivered ref; verify receipt where supported.
Mermaid source
sequenceDiagram
    actor A as Pushgate observer
    participant S as GitHub and receipt notary
    A->>S: Forward admitted update once
    S-->>A: Exact review or prerequisite status
    A->>S: Persist terminal upstream result and receipt request
    S-->>A: Read delivered ref; verify receipt where supported
    Note over A,S: Refused or uncertain outcomes stop for readback

Override or break glass

Authorized human works with Pushgate and platform.

  1. Review exact failed decisions and bounded duration.
  2. Approve explicit override.
  3. Read recorded override and resulting delivery separately.

Recovery: Missing, malformed or unstored decision provenance is never bypassable.

Override or break glass flowReview exact failed decisions and bounded duration; Approve explicit override; Read recorded override and resulting delivery separately. Missing, malformed or unstored decision provenance is never bypassableReview exact faileddecisions and boundedduration→Approve explicit override→Read recorded override andresulting deliveryseparately↓ Refused or uncertainStop and inspect authoritative state
Override or break glass: Review exact failed decisions and bounded duration → Approve explicit override → Read recorded override and resulting delivery separately.
Mermaid source
flowchart LR
    R["Review exact failed decisions and bounded duration"] --> E["Approve explicit override"]
    E -->|confirmed| C["Read recorded override and resulting delivery separately"]
    E -->|refused or uncertain| F["Stop and inspect authoritative state"]
Override or break glass sequenceReview exact failed decisions and bounded duration; Approve explicit override; Read recorded override and resulting delivery separately. Missing, malformed or unstored decision provenance is never bypassableAuthorized humanPushgate and platformReview exact failed decisions and bounded durationApprove explicit overrideRead recorded override and resulting delivery separately
Override or break glass: Review exact failed decisions and bounded duration → Approve explicit override → Read recorded override and resulting delivery separately.
Mermaid source
sequenceDiagram
    actor A as Authorized human
    participant S as Pushgate and platform
    A->>S: Review exact failed decisions and bounded duration
    S-->>A: Exact review or prerequisite status
    A->>S: Approve explicit override
    S-->>A: Read recorded override and resulting delivery separately
    Note over A,S: Refused or uncertain outcomes stop for readback