Skip to content

Repository workspaces

Open a repository to see its Overview, Work, Releases, Hooks, Monitoring, Secrets, and Activity. Overview keeps HQ expectations separate from provider evidence. Work shows open PR and issue totals, recent and aging PR samples, review requests, head checks and dependency-bot attribution without provider writes. Releases shows bounded published-version, deployment and immutable commit-comparison evidence from its enrolled GitHub source. Hooks and Monitoring list explicitly related resources with links to their independent operator surfaces. Secrets embeds the same provider-neutral workspace, initially limited to explicitly related enrolled resources; its operation history is scoped on the server using captured repository attribution. A distribution may deliberately select destinations outside that initial repository context, so review every destination before confirming. Activity uses the same goal grouping, pagination, and search contract as the global journal, scoped on the server to this repository.

Browse the inventory

Repositories uses compact, aligned rows for repository name, explicit project association, tracking classification, observed status, and evidence freshness. Open anywhere on a row, or follow its keyboard-focusable name, for the complete description and resource workspace. Narrow layouts retain all column facts as labeled groups; full names wrap without shrinking the shared type scale. Missing project associations remain unassigned rather than being inferred from repository names.

Status counts describe the whole selected workspace, independently of search and tracking filters. The result range describes only matching records. Search matches repository names, descriptions, and explicitly linked project names. Active, needs-attention, unverified, and archived filters use the same domain assessment as Overview; an overdue review can need attention while still being unverified. Tracking is an HQ classification, not proof of GitHub administration permission. Freshness and review reminders age on a local display clock without fetching more data, and hidden tabs stop that clock.

Sort by natural repository name in either direction, attention, project name, or the most recently updated HQ metadata. Attention ordering places critical and warning observations first, then overdue reviews, unverified repositories, and healthy repositories; it does not alter health. Named projects precede unassigned records. Name and stable identity break ties so a changed input order does not shuffle otherwise equal results.

Search, status, tracking, sort, page, and bounded page size are represented by q, filter, classification, sort, page, and pageSize in the URL. Repository sections and the return link retain this inventory context without copying workspace authority or arbitrary navigation destinations. Browser Back and reload retain the URL selections. Changing a filter, search, sort, or page size starts at the first matching page; explicit page navigation moves focus to its result summary. Invalid query choices use safe defaults and out-of-range pages render the last available page. The controls and page remain selected when records arrive through push, including while an enrollment draft is open. A live change can alter the rows at a page boundary; this inventory is not fixed historical pagination like Activity.

Filtering, sorting, and pagination operate on the bounded, authorized Repositories view already in the browser. They add no provider calls, Activity subscriptions, or HTTP read per interaction. Initial loading and gap or authority recovery keep the shared view contract; the page size bounds rendered rows rather than the initial data payload. CLI and MCP retain the same repository reads and domain semantics. No new privileged capability or provider operation is introduced by the presentation controls.

To find additional repositories or reconcile verified GitHub renames, transfers and archive changes, owners can use Review enrollment from the workspace inventory. It uses an explicitly selected read source, leaves additions and collection membership opt-in, and preserves existing HQ decisions and resource links. Follow fleet enrollment for review, coverage and interrupted-request recovery.

Read the repository overview

Access & operations is available in every repository section. It explains your live HQ role and any client-scope restrictions, the enrolled GitHub credential's availability, and which provider owns each operation. It does not probe or grant provider permissions. Maintained and Watchlist are tracking choices, not administration roles. See repository and provider permissions for webhook authority and unavailable features.

The overview starts with the explicit project, its Importance and Portfolio decision, tracking state, and expectation assessment. CI and security summarize the latest accepted GitHub observation, naming its source and observation time. Not configured, awaiting evidence, disabled collection, stale evidence, incomplete coverage, and fresh results remain distinct. Zero findings do not mean complete security coverage. Open Expectation check for the assessment reasons and GitHub evidence details for individual check results. A source's disabled observations remain inspectable but do not establish a fresh expectation assessment on this screen.

Expectations remain a separate compact summary. Edit expectations opens the structured editor for HQ's assessment rules and repository context, not provider configuration. Expected visibility checks the observed repository visibility; it does not change that visibility. A Review date marks the repository as due in Overview without sending a notification. Maintainer context expands a saved note when one exists. Source or journal updates do not replace an open draft. Sources opens GitHub coverage filtered to the repository and its selected connection, including archived context when necessary. Upstream links appear only when an explicit GitHub source covers the repository or GitHub observations exist; a local-only, unpublished record does not acquire an invented remote just because its name resembles owner/repo. These are navigation links, not a provider permission grant.

Operational checks places Hookrelay subscription and Endpoint Monitor evidence beside the repository's assessment rules. Opening Overview or choosing Check linked resources reads only explicitly linked resources through the enrolled connections, within the shared read budget. It never runs probes, sends notifications or changes provider configuration. Manage hooks and Manage monitoring open the corresponding operator workspace; missing links offer setup instead of implying that saving a requirement creates a resource.

Monitoring coverage requires a passing, configuration-matching target check and a fresh completed scheduler run that was enabled and used the saved configuration. An open incident remains a warning while recovery checks are passing; a successful probe does not resolve it. Hookrelay coverage verifies an enabled subscription with a destination, not GitHub webhook installation, live ingress or successful delivery. Its name-based links require a unique match in a complete subscription inventory; duplicate names, disappeared entries or a partial list remain unverified even when a matching entry was read. Disabled connections, missing resources, unavailable reads, changed configuration, expired evidence and incomplete inspection cannot establish coverage. Every linked resource must satisfy the rule; a passing resource or connection does not stand in for another. These minimized observations also inform repository and project assessment and the fleet's coverage-gap list.

Not inspected within this read means a bounded provider read could not establish coverage, not that the resource is missing. Open Manage hooks or Manage monitoring to inspect the provider's paginated inventory. All linked subscriptions on one connection share the inventory read, but large inventories and multiple connections still compete with target checks for the shared read budget.

Evidence retains its original deadlines after a failed refresh. A local clock marks it expired even without another request. Retained results are not continuous monitoring, and a live dashboard connection is not a new provider check. The read window is shared across observers and survives page reload; use the displayed next-check time or inspect the provider workspace. Links, connection changes and accepted monitoring operations invalidate related results. A provider change outside HQ is discovered on a subsequent read or when the old evidence expires.

If another observer has a check in progress, its accepted operational evidence arrives through the repository's pushed records. The card then reads HQ's saved coverage and check status without contacting the provider again. A failed saved-result read offers Retry saved result, independently of the provider-check cooldown. That retry does not run probes, acquire a collection lease or renew an evidence deadline. Check linked resources remains the explicit provider-read action.

Expand Linked resources for bounded Hookrelay, Monitoring and Secrets previews with exact linked-resource counts. A count describes HQ context, not health, secret names, or proof that a provider resource exists. Operational previews identify their connection and whether the resource is shared. Secrets previews identify the provider and resource label without reading secret names or values; a renamed repository binding is marked for review. Disabled connections stay visible. Missing links are reported explicitly, and project membership never supplies an implicit repository link. Follow a resource for status and details, or use its repository section to browse the complete list.

Recent activity previews the repository's newest journal groups, including verbatim goal text and source-linked GitHub refresh events. Long descriptions are visually abbreviated; View journal opens the complete goal-aware journal. View refresh receipt opens that exact source and run. Failed link and journal reads recover independently through their Retry buttons, without disguising an unavailable read as an empty result.

The overview mounts bounded metadata, repository-filtered journal and operational coverage reads only while visible. It does not download another tab's inventory. Push invalidates association metadata, operational reads and the live journal independently, while changed repository/evidence records update the scoped view cache. Establishing or restoring the push subscription revalidates active auxiliary reads to close the initial-read gap; this can add a bounded catch-up read, not a polling loop. GitHub progress and unrelated Activity do not trigger operational provider reads. The local freshness clock makes no HTTP requests and stops while hidden.

Set expectations across repositories

In Repositories, choose Set expectations. Select the exact repositories, using search, tracking and Include archived when needed. Select this page selects only the displayed page, not hidden matches. Select all matches is offered when the complete filtered set fits the batch limit. The selection stays intact when you change selection pages or filters and is bounded by EXPECTATION_BULK_LIMITS.REPOSITORIES. Opening the editor from a project keeps the selection list within that project. Nothing is selected automatically.

Choose a preset or turn on only the fields you want to change. CI and security requires those checks; Running service also requires endpoint monitoring; Observe only removes requirements for CI, security, monitoring and hooks in HQ. Presets are suggestions, not provider configuration or permission changes. Choosing one replaces the batch's selected fields while keeping individual exceptions. Visibility, notes and review dates stay unchanged unless explicitly selected. Selecting an empty note or review date clears that field, so inspect its before/after values carefully.

Under Repositories and exceptions, exclude a repository or expand Exceptions to override an individual field. Turning off an override returns to the batch choice. Review changes shows each repository's before/after values and distinguishes unchanged rows. Apply saves the exact reviewed changes together; unchanged rows receive no new revision or change event. Owners and operators with metadata access can prepare and apply reviews. Watchlist classification does not prevent changing HQ expectations, and it does not grant provider administration rights.

Optional and Not managed here do not establish healthy evidence. They express what you require, not what a provider observed. Missing evidence and observed problems remain independently inspectable in Overview. Changing expectations does not create, refresh or erase provider observations, nor does it connect monitoring or hooks.

Reviews expire after the shared plan TTL and are bound to the workspace, reviewing identity and credential, exact selected repository revisions and selected changes. An edit, move, removal or changed authority rejects the whole batch. Go Back to choices, use Use latest repository versions when offered, then inspect a fresh review. The selected changes are preserved; live push never silently rewrites the draft's baseline. Cancel or navigation asks before discarding unsaved choices.

If Apply's response is interrupted, use Check saved receipt or Retry same review. Both retain the original operation identity. A read that has not found a receipt yet is not proof that an earlier Apply cannot finish; do not start another batch while that outcome remains uncertain. Before closing an unconfirmed review, save the review URL offered by the warning. Closing does not cancel Apply. The expectationReview URL parameter reopens the saved review and receipt after reload for the same workspace and identity. An unresolved attempt in the same tab retains its recovery marker across reload, even if an intermediate read reports the review as stale or expired. A confirmed receipt or a definitive rejection of the exact Apply resolves that uncertainty. Applied reviews and receipts are retained for idempotent recovery; expired unapplied reviews may be removed when another review is prepared. Review references are not access grants.

The shared commands are expectations_plan, expectations_review and expectations_apply. Discover their exact schemas through the CLI or MCP. Planning accepts unique repository IDs, revisions and nonempty expectation patches, never replacement repository documents or arbitrary fields. The API checks live authority and all selected revisions in the same atomic database batch as its receipt, repository updates and repository/project-attributed Activity. These commands make no provider calls. A saved receipt describes that committed change, not proof that a repository still has those values after later edits.

A Hookrelay subscription or Endpoint Monitor target may serve several repositories or none. Manage its repository links in the provider detail view using structured selection and Save/Cancel. HQ does not infer relationships from names, URLs, projects, nearby events, or ownership. A project can group work without a repository, and project associations do not implicitly enroll repository links.

The link identity is the workspace, resource kind, connection, and exact provider resource key. Saving replaces the explicitly reviewed repository set at a matching link and connection revision. Conflicts preserve the draft; loading saved state must succeed before replacing it. Workspace membership and edit authority are checked at the write boundary. Viewers can inspect links but cannot change them. Saving links changes HQ metadata, never provider targets, routes, or delivery settings.

Follow a resource from a repository and the provider view keeps a return link and an explicit shared-impact warning. The repository context is navigation context, not a provider authorization boundary. Review the full target, subscription, and operation before acting. Disabled connections and removed provider resources remain distinguishable from empty healthy results. Links and historical operation attribution are retained when a provider target disappears.

Activity attribution

HQ records immutable repository associations with consequential provider operation intent. Monitoring uses the reviewed target's saved links; shared defaults changes capture the connection's linked repositories. Hook retries re-read the exact delivery generation, timestamp, state, and trusted subscription before submission, then retain its links. Association edits record the affected previous and selected repository sets. GitHub refresh events capture their run's selected repository identities atomically with the journal event, including cancellation. A later source edit, receipt expiry, or link edit does not rewrite old history. Events recorded before repository attribution was available are not retroactively assigned from a source's changing scope.

Repository Activity includes directly associated reports and immutable operation associations. Unscoped transitions and general updates for a relevant goal remain visible, but updates explicitly associated with other repositories stay excluded. The insertion watermark applies to relevance as well as pagination, so a new linked update cannot move a goal into an older fixed history page. Reporters should name both goalId and the enrolled repository's resourceId when publishing repository-specific work.

Shared commands and bounds

repository_resources returns a keyset-paginated list for one repository, with an optional resource-kind filter. Its cursor is bound to that workspace, repository, and filter. resource_repositories reads one exact resource association; resource_repositories_save saves its reviewed repository set. Browser, CLI, and both MCP transports use the same service and authorization checks. Read exact schemas through command discovery instead of constructing provider paths or database queries.

repository_context returns one repository's linked Hookrelay, Endpoint Monitor, and provider-neutral Secrets resource metadata with exact totals and samples bounded by REPOSITORY_CONTEXT_LIMITS. It reads local metadata only, never resolves credentials, and checks live membership, credential authority, and repository workspace/revision before returning. Viewer reads are supported; publishers and reporters cannot use it. activity_feed supplies the independently bounded repository journal preview. Its small limit is part of the query identity, so it cannot replace a full journal page in the browser cache.

repository_coverage reads and retains minimized operational evidence for one repository. Browser, CLI and MCP use the same workspace read authority, exact saved links, connection revisions, cooldown, lease and acceptance checks. COVERAGE_LIMITS bounds inspected resources, connections, provider calls, subscription pages, concurrency, elapsed time, shared workspace reads and response bytes. Resources omitted by a read bound remain unverified; another identical check does not continue through omitted links. Open the provider workspace for individual inspection. A connection set above the bound is rejected before provider work. No provider URLs, sink names, raw payloads or credentials enter retained coverage observations. This command is read-only toward providers but writes the derived HQ cache, budget and changed-record notifications.

repository_coverage_get accepts the same exact workspace and repository identifiers and returns retained coverage with saved read progress. It authorizes the reader and validates the saved link context without provider calls, credentials, lease or budget writes, observation acceptance or notifications. Empty, stale and invalidated coverage stays that way. A response's generation time dates the HQ read, not a provider observation. CLI and MCP expose both commands with the same strict input validation; neither accepts a caller-selected URL or an option to bypass the read bounds.

RESOURCE_LINK_LIMITS caps each repository set, workspace association capacity, and read page size. Provider list responses gather links in bounded batches rather than one provider request per repository. Association and journal reads still consume HQ CPU and D1 work; these bounds are not an account-wide cost ceiling. Links alone are not repository health observations.