Choose your workflow
The same system supports several starting points. Learn the architecture and trust model once, then follow the task you need to complete.
Record and verify work
Start here when you need a signed record of a build, test, scan, or operational check.
- Install CI/lock.
- Record your first attestation.
- Review which producer and policy you trust.
- Decide whether the result will support a gate decision, a technical-control assessment, or standalone verification.
Protect a repository
Start here when a push must meet configured evidence requirements before it enters a repository through the gate.
- Read the Pushgate overview.
- Follow the repository setup guide.
- Review security coverage and bypass boundaries.
- Exercise a successful push and a deliberately missing required result in an authorized test repository.
Manage several gates
Start here when the same team needs to manage requirements across repositories.
Review the policy and assignment boundaries, then the policy decision reference. Confirm which policy-release and activation features are enabled in your deployed version before planning a rollout.
Demonstrate a technical control
Start with one operational question: did the recovery rehearsal succeed, was a vulnerable component remediated, or did the configuration meet the stated requirement?
Define the test and accepted producer, record it with CI/lock, and review the result before mapping it to the control. Follow the technical-assessment flow. A mapping must retain the scope and limits of the underlying test.
Operate the platform
Start with your deployment boundary. Agree who operates identity, trust roots, storage, backups, updates, and recovery. Review the deployment architecture and trust infrastructure with the supported configuration for your version.
The software appliance runs the platform in your environment. It is the same evidence and policy system, with a different operating responsibility.