Domain status

Active

Workflow dispatch guard is canonical; deployment guard available under engagement.

Workflow guard

Workflow Dispatch Guard

Shipped

Part of Infrastructure & DevOps

Guard readout

Status
Shipped
Control steps
06
// RISK BEFORE HUMBLEAF

A CI token can dispatch any workflow — no per-action authorization, only after-the-fact logs.

// CONTROLLED FLOW
  • 01Dispatch proposed by automation or agent
  • 02Actor recognized (service identity continuity)
  • 03Policy checks workflow class and scope
  • 04Risk advises if behavior looks abnormal
  • 05High-risk dispatches escalate to human approval
  • 06Execute or block — evidence bundle preserved

Risk advises. Policy decides. Evidence proves.

// APPROVAL GATE

Sensitive workflow class or abnormal dispatch pattern.

// EVIDENCE

Evidence bundle binding the dispatch action, policy in force, identity snapshot, risk context, and approval record when escalated.

// BUSINESS OUTCOME

Govern privileged automation per action — not per standing token.

Pilot

Pilot this guard

Start with a protected workflow pilot — shadow first, gate when ready.