A CI token can dispatch any workflow — no per-action authorization, only after-the-fact logs.
Domain status
Active- Shipped today
- Workflow Dispatch GuardShipped
- Deployment & Config Change GuardShipped
Workflow dispatch guard is canonical; deployment guard available under engagement.
Guard readout
- Status
- Shipped
- Control steps
- 06
- 01Dispatch proposed by automation or agent
- 02Actor recognized (service identity continuity)
- 03Policy checks workflow class and scope
- 04Risk advises if behavior looks abnormal
- 05High-risk dispatches escalate to human approval
- 06Execute or block — evidence bundle preserved
Risk advises. Policy decides. Evidence proves.
Sensitive workflow class or abnormal dispatch pattern.
Evidence bundle binding the dispatch action, policy in force, identity snapshot, risk context, and approval record when escalated.
Govern privileged automation per action — not per standing token.
