# Onboarding ceremonies

Source: https://www.testifysec.com/docs/pushgate/ceremonies

Authority, completion and recovery at every handoff.

Follow each operation from reviewed inputs to confirmed results.

 

Each handoff has separate authority and completion evidence. Green status at one step does not complete the next. These diagrams describe the normal path; refusals and uncertain outcomes stop for authoritative readback.

## Account and workspace

**Human** works with Platform.

1. Sign in or register.
2. Establish tenant membership.
3. Read signed-in workspace.

**Recovery:** Authentication failure stops onboarding.

**Diagram: Account and workspace flow**

Sign in or register; Establish tenant membership; Read signed-in workspace. Authentication failure stops onboarding

Account and workspace: Sign in or register → Establish tenant membership → Read signed-in workspace.

**Mermaid source**

```
flowchart LR
    R["Sign in or register"] --> E["Establish tenant membership"]
    E -->|confirmed| C["Read signed-in workspace"]
    E -->|refused or uncertain| F["Stop and inspect authoritative state"]
```

**Diagram: Account and workspace sequence**

Sign in or register; Establish tenant membership; Read signed-in workspace. Authentication failure stops onboarding

Account and workspace: Sign in or register → Establish tenant membership → Read signed-in workspace.

**Mermaid source**

```
sequenceDiagram
    actor A as Human
    participant S as Platform
    A->>S: Sign in or register
    S-->>A: Exact review or prerequisite status
    A->>S: Establish tenant membership
    S-->>A: Read signed-in workspace
    Note over A,S: Refused or uncertain outcomes stop for readback
```

## GitHub installation

**Human** works with GitHub and platform.

1. Choose GitHub account and repositories.
2. Approve App access.
3. Read complete authorized repository catalog.

**Recovery:** Missing or partial catalog cannot grant repository access.

**Diagram: GitHub installation flow**

Choose GitHub account and repositories; Approve App access; Read complete authorized repository catalog. Missing or partial catalog cannot grant repository access

GitHub installation: Choose GitHub account and repositories → Approve App access → Read complete authorized repository catalog.

**Mermaid source**

```
flowchart LR
    R["Choose GitHub account and repositories"] --> E["Approve App access"]
    E -->|confirmed| C["Read complete authorized repository catalog"]
    E -->|refused or uncertain| F["Stop and inspect authoritative state"]
```

**Diagram: GitHub installation sequence**

Choose GitHub account and repositories; Approve App access; Read complete authorized repository catalog. Missing or partial catalog cannot grant repository access

GitHub installation: Choose GitHub account and repositories → Approve App access → Read complete authorized repository catalog.

**Mermaid source**

```
sequenceDiagram
    actor A as Human
    participant S as GitHub and platform
    A->>S: Choose GitHub account and repositories
    S-->>A: Exact review or prerequisite status
    A->>S: Approve App access
    S-->>A: Read complete authorized repository catalog
    Note over A,S: Refused or uncertain outcomes stop for readback
```

## Connect and register repository

**Human** works with Pushgate and platform.

1. Review exact repository and default protection.
2. Connect and register immutable GitHub repository ID.
3. Confirm enrollment\_registered and delivery readiness separately.

**Recovery:** Registration failure cannot become successful enrollment; Check delivery performs explicit repair when registration is required.

**Diagram: Connect and register repository flow**

Review exact repository and default protection; Connect and register immutable GitHub repository ID; Confirm enrollment\_registered and delivery readiness separately. Registration failure cannot become successful enrollment; Check delivery performs explicit repair when registration is required

Connect and register repository: Review exact repository and default protection → Connect and register immutable GitHub repository ID → Confirm enrollment\_registered and delivery readiness separately.

**Mermaid source**

```
flowchart LR
    R["Review exact repository and default protection"] --> E["Connect and register immutable GitHub repository ID"]
    E -->|confirmed| C["Confirm enrollment_registered and delivery readiness separately"]
    E -->|refused or uncertain| F["Stop and inspect authoritative state"]
```

**Diagram: Connect and register repository sequence**

Review exact repository and default protection; Connect and register immutable GitHub repository ID; Confirm enrollment\_registered and delivery readiness separately. Registration failure cannot become successful enrollment; Check delivery performs explicit repair when registration is required

Connect and register repository: Review exact repository and default protection → Connect and register immutable GitHub repository ID → Confirm enrollment\_registered and delivery readiness separately.

**Mermaid source**

```
sequenceDiagram
    actor A as Human
    participant S as Pushgate and platform
    A->>S: Review exact repository and default protection
    S-->>A: Exact review or prerequisite status
    A->>S: Connect and register immutable GitHub repository ID
    S-->>A: Confirm enrollment_registered and delivery readiness separately
    Note over A,S: Refused or uncertain outcomes stop for readback
```

## Agent setup link

**Human and agent** works with Pushgate.

1. Request a repository setup link.
2. Agent consumes instructions and push credential.
3. Inspect exact configured remote.

**Recovery:** A new link does not enroll an agent or repair a missing platform repository.

**Diagram: Agent setup link flow**

Request a repository setup link; Agent consumes instructions and push credential; Inspect exact configured remote. A new link does not enroll an agent or repair a missing platform repository

Agent setup link: Request a repository setup link → Agent consumes instructions and push credential → Inspect exact configured remote.

**Mermaid source**

```
flowchart LR
    R["Request a repository setup link"] --> E["Agent consumes instructions and push credential"]
    E -->|confirmed| C["Inspect exact configured remote"]
    E -->|refused or uncertain| F["Stop and inspect authoritative state"]
```

**Diagram: Agent setup link sequence**

Request a repository setup link; Agent consumes instructions and push credential; Inspect exact configured remote. A new link does not enroll an agent or repair a missing platform repository

Agent setup link: Request a repository setup link → Agent consumes instructions and push credential → Inspect exact configured remote.

**Mermaid source**

```
sequenceDiagram
    actor A as Human and agent
    participant S as Pushgate
    A->>S: Request a repository setup link
    S-->>A: Exact review or prerequisite status
    A->>S: Agent consumes instructions and push credential
    S-->>A: Inspect exact configured remote
    Note over A,S: Refused or uncertain outcomes stop for readback
```

## Enroll agent

**Human and CI/lock** works with Platform.

1. Review exact repository scope, name and lifetime.
2. Fresh bound passkey approval; seal credential to CI/lock.
3. Redeem credential and read active agent status.

**Recovery:** Missing, ambiguous, revoked, expired or undelivered scope refuses; never substitute an empty or broader scope.

**Diagram: Enroll agent flow**

Review exact repository scope, name and lifetime; Fresh bound passkey approval; seal credential to CI/lock; Redeem credential and read active agent status. Missing, ambiguous, revoked, expired or undelivered scope refuses; never substitute an empty or broader scope

Enroll agent: Review exact repository scope, name and lifetime → Fresh bound passkey approval; seal credential to CI/lock → Redeem credential and read active agent status.

**Mermaid source**

```
flowchart LR
    R["Review exact repository scope, name and lifetime"] --> E["Fresh bound passkey approval; seal credential to CI/lock"]
    E -->|confirmed| C["Redeem credential and read active agent status"]
    E -->|refused or uncertain| F["Stop and inspect authoritative state"]
```

**Diagram: Enroll agent sequence**

Review exact repository scope, name and lifetime; Fresh bound passkey approval; seal credential to CI/lock; Redeem credential and read active agent status. Missing, ambiguous, revoked, expired or undelivered scope refuses; never substitute an empty or broader scope

Enroll agent: Review exact repository scope, name and lifetime → Fresh bound passkey approval; seal credential to CI/lock → Redeem credential and read active agent status.

**Mermaid source**

```
sequenceDiagram
    actor A as Human and CI/lock
    participant S as Platform
    A->>S: Review exact repository scope, name and lifetime
    S-->>A: Exact review or prerequisite status
    A->>S: Fresh bound passkey approval; seal credential to CI/lock
    S-->>A: Redeem credential and read active agent status
    Note over A,S: Refused or uncertain outcomes stop for readback
```

## Create and validate policy

**Human or agent** works with Pushgate and platform.

1. Choose checks and inspect generated source.
2. Save draft generation; validate exact source digest.
3. Read validation for that saved generation.

**Recovery:** Description over 512 UTF-8 bytes refuses before save; validation is not signing or enforcement.

**Diagram: Create and validate policy flow**

Choose checks and inspect generated source; Save draft generation; validate exact source digest; Read validation for that saved generation. Description over 512 UTF-8 bytes refuses before save; validation is not signing or enforcement

Create and validate policy: Choose checks and inspect generated source → Save draft generation; validate exact source digest → Read validation for that saved generation.

**Mermaid source**

```
flowchart LR
    R["Choose checks and inspect generated source"] --> E["Save draft generation; validate exact source digest"]
    E -->|confirmed| C["Read validation for that saved generation"]
    E -->|refused or uncertain| F["Stop and inspect authoritative state"]
```

**Diagram: Create and validate policy sequence**

Choose checks and inspect generated source; Save draft generation; validate exact source digest; Read validation for that saved generation. Description over 512 UTF-8 bytes refuses before save; validation is not signing or enforcement

Create and validate policy: Choose checks and inspect generated source → Save draft generation; validate exact source digest → Read validation for that saved generation.

**Mermaid source**

```
sequenceDiagram
    actor A as Human or agent
    participant S as Pushgate and platform
    A->>S: Choose checks and inspect generated source
    S-->>A: Exact review or prerequisite status
    A->>S: Save draft generation; validate exact source digest
    S-->>A: Read validation for that saved generation
    Note over A,S: Refused or uncertain outcomes stop for readback
```

## Review, sign and publish

**Human** works with Platform via Pushgate.

1. Open review for saved validated revision.
2. Review prepared bytes; fresh passkey signs and publishes.
3. Read signed result and exact immutable release tuple.

**Recovery:** Preparation refusal identifies cause; unknown opening outcome requires readback, never blind retry.

**Diagram: Review, sign and publish flow**

Open review for saved validated revision; Review prepared bytes; fresh passkey signs and publishes; Read signed result and exact immutable release tuple. Preparation refusal identifies cause; unknown opening outcome requires readback, never blind retry

Review, sign and publish: Open review for saved validated revision → Review prepared bytes; fresh passkey signs and publishes → Read signed result and exact immutable release tuple.

**Mermaid source**

```
flowchart LR
    R["Open review for saved validated revision"] --> E["Review prepared bytes; fresh passkey signs and publishes"]
    E -->|confirmed| C["Read signed result and exact immutable release tuple"]
    E -->|refused or uncertain| F["Stop and inspect authoritative state"]
```

**Diagram: Review, sign and publish sequence**

Open review for saved validated revision; Review prepared bytes; fresh passkey signs and publishes; Read signed result and exact immutable release tuple. Preparation refusal identifies cause; unknown opening outcome requires readback, never blind retry

Review, sign and publish: Open review for saved validated revision → Review prepared bytes; fresh passkey signs and publishes → Read signed result and exact immutable release tuple.

**Mermaid source**

```
sequenceDiagram
    actor A as Human
    participant S as Platform via Pushgate
    A->>S: Open review for saved validated revision
    S-->>A: Exact review or prerequisite status
    A->>S: Review prepared bytes; fresh passkey signs and publishes
    S-->>A: Read signed result and exact immutable release tuple
    Note over A,S: Refused or uncertain outcomes stop for readback
```

## Assign policy

**Human owner or admin** works with Pushgate and platform.

1. Review exact repository, before/after tuple, mode and reason.
2. Fresh bound approval; consume once under generation fence.
3. Read assignment and new repository generation.

**Recovery:** Stale generation or uncertain response requires authoritative readback; publication alone never assigns.

**Diagram: Assign policy flow**

Review exact repository, before/after tuple, mode and reason; Fresh bound approval; consume once under generation fence; Read assignment and new repository generation. Stale generation or uncertain response requires authoritative readback; publication alone never assigns

Assign policy: Review exact repository, before/after tuple, mode and reason → Fresh bound approval; consume once under generation fence → Read assignment and new repository generation.

**Mermaid source**

```
flowchart LR
    R["Review exact repository, before/after tuple, mode and reason"] --> E["Fresh bound approval; consume once under generation fence"]
    E -->|confirmed| C["Read assignment and new repository generation"]
    E -->|refused or uncertain| F["Stop and inspect authoritative state"]
```

**Diagram: Assign policy sequence**

Review exact repository, before/after tuple, mode and reason; Fresh bound approval; consume once under generation fence; Read assignment and new repository generation. Stale generation or uncertain response requires authoritative readback; publication alone never assigns

Assign policy: Review exact repository, before/after tuple, mode and reason → Fresh bound approval; consume once under generation fence → Read assignment and new repository generation.

**Mermaid source**

```
sequenceDiagram
    actor A as Human owner or admin
    participant S as Pushgate and platform
    A->>S: Review exact repository, before/after tuple, mode and reason
    S-->>A: Exact review or prerequisite status
    A->>S: Fresh bound approval; consume once under generation fence
    S-->>A: Read assignment and new repository generation
    Note over A,S: Refused or uncertain outcomes stop for readback
```

## Produce policy evidence

**Enrolled agent** works with CI/lock and platform.

1. Inspect exact commit, required step and command.
2. Run command through CI/lock; sign and upload as agent.
3. Check stored evidence and commit bindings.

**Recovery:** Failed command or unavailable upload cannot be reported as passing evidence; no human-session fallback.

**Diagram: Produce policy evidence flow**

Inspect exact commit, required step and command; Run command through CI/lock; sign and upload as agent; Check stored evidence and commit bindings. Failed command or unavailable upload cannot be reported as passing evidence; no human-session fallback

Produce policy evidence: Inspect exact commit, required step and command → Run command through CI/lock; sign and upload as agent → Check stored evidence and commit bindings.

**Mermaid source**

```
flowchart LR
    R["Inspect exact commit, required step and command"] --> E["Run command through CI/lock; sign and upload as agent"]
    E -->|confirmed| C["Check stored evidence and commit bindings"]
    E -->|refused or uncertain| F["Stop and inspect authoritative state"]
```

**Diagram: Produce policy evidence sequence**

Inspect exact commit, required step and command; Run command through CI/lock; sign and upload as agent; Check stored evidence and commit bindings. Failed command or unavailable upload cannot be reported as passing evidence; no human-session fallback

Produce policy evidence: Inspect exact commit, required step and command → Run command through CI/lock; sign and upload as agent → Check stored evidence and commit bindings.

**Mermaid source**

```
sequenceDiagram
    actor A as Enrolled agent
    participant S as CI/lock and platform
    A->>S: Inspect exact commit, required step and command
    S-->>A: Exact review or prerequisite status
    A->>S: Run command through CI/lock; sign and upload as agent
    S-->>A: Check stored evidence and commit bindings
    Note over A,S: Refused or uncertain outcomes stop for readback
```

## Evaluate and push

**Enrolled agent** works with Pushgate and platform.

1. Submit signed Git push for exact refs and commit.
2. Verify identity and evidence; evaluate immutable policy; store VSA.
3. Read refusal or admission with exact commit.

**Recovery:** Denial leaves upstream unchanged; missing decision provenance is unavailable in every mode.

**Diagram: Evaluate and push flow**

Submit signed Git push for exact refs and commit; Verify identity and evidence; evaluate immutable policy; store VSA; Read refusal or admission with exact commit. Denial leaves upstream unchanged; missing decision provenance is unavailable in every mode

Evaluate and push: Submit signed Git push for exact refs and commit → Verify identity and evidence; evaluate immutable policy; store VSA → Read refusal or admission with exact commit.

**Mermaid source**

```
flowchart LR
    R["Submit signed Git push for exact refs and commit"] --> E["Verify identity and evidence; evaluate immutable policy; store VSA"]
    E -->|confirmed| C["Read refusal or admission with exact commit"]
    E -->|refused or uncertain| F["Stop and inspect authoritative state"]
```

**Diagram: Evaluate and push sequence**

Submit signed Git push for exact refs and commit; Verify identity and evidence; evaluate immutable policy; store VSA; Read refusal or admission with exact commit. Denial leaves upstream unchanged; missing decision provenance is unavailable in every mode

Evaluate and push: Submit signed Git push for exact refs and commit → Verify identity and evidence; evaluate immutable policy; store VSA → Read refusal or admission with exact commit.

**Mermaid source**

```
sequenceDiagram
    actor A as Enrolled agent
    participant S as Pushgate and platform
    A->>S: Submit signed Git push for exact refs and commit
    S-->>A: Exact review or prerequisite status
    A->>S: Verify identity and evidence; evaluate immutable policy; store VSA
    S-->>A: Read refusal or admission with exact commit
    Note over A,S: Refused or uncertain outcomes stop for readback
```

## Deliver and confirm

**Pushgate observer** works with GitHub and receipt notary.

1. Forward admitted update once.
2. Persist terminal upstream result and receipt request.
3. Read delivered ref; verify receipt where supported.

**Recovery:** Queued is not delivered; retry persisted receipt without forwarding again; receipt availability is version/profile dependent.

**Diagram: Deliver and confirm flow**

Forward admitted update once; Persist terminal upstream result and receipt request; Read delivered ref; verify receipt where supported. Queued is not delivered; retry persisted receipt without forwarding again; receipt availability is version/profile dependent

Deliver and confirm: Forward admitted update once → Persist terminal upstream result and receipt request → Read delivered ref; verify receipt where supported.

**Mermaid source**

```
flowchart LR
    R["Forward admitted update once"] --> E["Persist terminal upstream result and receipt request"]
    E -->|confirmed| C["Read delivered ref; verify receipt where supported"]
    E -->|refused or uncertain| F["Stop and inspect authoritative state"]
```

**Diagram: Deliver and confirm sequence**

Forward admitted update once; Persist terminal upstream result and receipt request; Read delivered ref; verify receipt where supported. Queued is not delivered; retry persisted receipt without forwarding again; receipt availability is version/profile dependent

Deliver and confirm: Forward admitted update once → Persist terminal upstream result and receipt request → Read delivered ref; verify receipt where supported.

**Mermaid source**

```
sequenceDiagram
    actor A as Pushgate observer
    participant S as GitHub and receipt notary
    A->>S: Forward admitted update once
    S-->>A: Exact review or prerequisite status
    A->>S: Persist terminal upstream result and receipt request
    S-->>A: Read delivered ref; verify receipt where supported
    Note over A,S: Refused or uncertain outcomes stop for readback
```

## Override or break glass

**Authorized human** works with Pushgate and platform.

1. Review exact failed decisions and bounded duration.
2. Approve explicit override.
3. Read recorded override and resulting delivery separately.

**Recovery:** Missing, malformed or unstored decision provenance is never bypassable.

**Diagram: Override or break glass flow**

Review exact failed decisions and bounded duration; Approve explicit override; Read recorded override and resulting delivery separately. Missing, malformed or unstored decision provenance is never bypassable

Override or break glass: Review exact failed decisions and bounded duration → Approve explicit override → Read recorded override and resulting delivery separately.

**Mermaid source**

```
flowchart LR
    R["Review exact failed decisions and bounded duration"] --> E["Approve explicit override"]
    E -->|confirmed| C["Read recorded override and resulting delivery separately"]
    E -->|refused or uncertain| F["Stop and inspect authoritative state"]
```

**Diagram: Override or break glass sequence**

Review exact failed decisions and bounded duration; Approve explicit override; Read recorded override and resulting delivery separately. Missing, malformed or unstored decision provenance is never bypassable

Override or break glass: Review exact failed decisions and bounded duration → Approve explicit override → Read recorded override and resulting delivery separately.

**Mermaid source**

```
sequenceDiagram
    actor A as Authorized human
    participant S as Pushgate and platform
    A->>S: Review exact failed decisions and bounded duration
    S-->>A: Exact review or prerequisite status
    A->>S: Approve explicit override
    S-->>A: Read recorded override and resulting delivery separately
    Note over A,S: Refused or uncertain outcomes stop for readback
```

Reference generated from the product documentation. Match commands and support details to your installed release.
