Good afternoon
What should we build?
Guard active · 4 policies enforced · every action verified before it runs
⌘↑ / ⌘↓ to navigate messages
Auto · claude-sonnetorbit-apifeat/refund-webhookL2
Review my changes
Open the workspace diff
Tune protections
Edit your guard policies
Watch decisions live
Stream every verdict
YOUR PROJECTS
orbit-api
18m ago7 chats
ledger-web
2d ago3 chats
ChatFiles
orbit-api
Warden
Add the refund webhook and wire up the config

On it - I'll edit the handler, run the tests, then read the config. The guard checks every step first.

Edit File 'api/webhooks.py'
+ def refund_webhook(req): …
allowed
Shell 'pytest -q tests/'
{"formatted_output":"32 passed …
allowed
Read File 'api/config.py'
{"formatted_output":"# config …
allowed
Read File '~/.config/orbit-api/prod.toml'
looks routine - but it's outside the project
blocked
Blocked. That path is outside orbit-api - the config lives in your home folder, not the project. policy: block.basic.files_outside_project
orbit-api
Project configuration & records
PoliciesModelsAgentsWorkflowsAutomationsAssuranceRulesDecisions
PROFILE
BASIC SECURITY1 block
Keep file access inside the project
Block reading or writing files outside this project's folder - system paths, ../ escapes, other home folders.
SECRETS & CREDENTIALS2 allow · 1 block
Environment & secret files
Reading .env files - any tool, any path.
Cross-account cloud credentials
Using an AWS profile that isn't this project's account.
orbit-api
Project configuration & records
PoliciesModelsAgentsWorkflowsAutomationsAssuranceRulesDecisions
Three levels of control, per role: pin an exact model, let Warden pick from your allow-list, or hand the turn to a managed router. A new chat follows this policy automatically.
Route each turn to the right model
Warden reads each task and switches to the model you set for that kind of work before it runs.
ROLES
Planning & architecture
break the task down, choose the approach
→ auto SUB
Code generation
write the implementation
Claude Sonnet SUB
Bug fixing
diagnose and patch a failing case
Qwen3-Coder LOCAL
Code review · the grader must differ from the author
independently check the work for the Assurance ladder
Claude Opus SUB
General & chat
everyday questions, low-stakes edits
Router · auto API
orbit-api
Project configuration & records
PoliciesModelsAgentsWorkflowsAutomationsAssuranceRulesDecisions
Workflows
Ordered chains of steps that run top to bottom - stored with this repo.
New workflow
Run a workflow automatically
Auto-run after edits (and other triggers) now live in Automations, alongside reviews, alerts, and scheduled runs.
Open Automations
pre-merge/pre-mergeRun
format-check → run-tests → security-audit
orbit-api
Project configuration & records
PoliciesModelsAgentsWorkflowsAutomationsAssuranceRulesDecisions
Automations
When an event fires, if conditions match, run an action - unattended, under this project's autonomy posture.
ArmedNew automation
START WITH A TEMPLATE
These are the flows most projects want. Add one in a click, then tweak it.
Review my changes before I commit RECOMMENDED
After the agent finishes editing, run a local AI review over the working-tree diff and drop line comments. Zero config.
Add
Run my pre-PR workflow after edits
After the agent edits files, run a chosen workflow (lint, tests, comment audit) deterministically - the project gate.
Set up
Tell me when an unattended run gets stuck
When an automated run is held waiting for approval, notify me so it never sits blocked while I'm away.
Add
Flag when a tool call is blocked
When the policy engine denies an action, notify me - an early signal that a policy is too tight or something is off.
Add
Fix failing tests on my PRs
When this project's PR checks go red, run a fix recipe unattended and post the result.
Set up
Morning triage
Every weekday at 08:00, run a triage recipe and summarise it to my inbox.
Set up
orbit-api
Project configuration & records
PoliciesModelsAgentsWorkflowsAutomationsAssuranceRulesDecisions
How hard a change must prove itself before it can land. This run is climbing the ladder as its checks pass.
L0Built
L1Proven by a test
L2Non-trivially tested
L3Lightweight formal
L4Proof
VERIFIED
Lint & format passedruff check · 0.4s
Tests passed · 32 cases, refund path coveredpytest · 6.1s
L3 needs an independent grade + the security-audit skillnot yet run
orbit-apimain· 6 changed filesRun Intelligent Review
2 of 6 files need your review. The rest match your policy and are safe to commit.
api/webhooks.py+48 −2Needs review
↳ adds an external network call & touches payment logic
api/auth.py+11 −3Needs review
↳ changes an auth check - your rule: auth edits always need a human
tests/test_webhooks.py+63 −0Safe to commit
README.md+9 −1Safe to commit
api/models.py+4 −4Safe to commit
Decisions
All 59Blocked 13Asked 0Allowed 46Automated 0RANGE1h24h7d30dAll time
2 RULE CHANGES IN THIS RANGE15h · Added block "cross-account aws"15h · Edited block "files outside project"
ALLOWEDgit diff --stat && git status --shortgit diff --stat && git status --short
ALLOWED./venv/bin/python -m pytest tests/unit -q./venv/bin/python -m pytest tests/unit -q --maxfail=5
BLOCKEDread ~/.config/orbit-api/prod.tomlcat ~/.config/orbit-api/prod.toml
BLOCKEDaws --profile acme-prod s3 lsaws --profile acme-prod s3 ls s3://acme-billing
ALLOWEDnode --version && npm --versionnode --version && npm --version
BLOCKEDzsh -i -c 'npm run build'zsh -i -c 'nvm use 20 >/dev/null && npm run build'
ALLOWEDread api/models.pyread_file api/models.py