Documentation
ORBIT docs
Practical guides for installing and operating Guardian. Start here when you want commands, files, and checks.
Start here
Human Start Here
A plain-English entry point: what ORBIT is, what your phone will do, what proof you get, and where the limits are.
For agentsAI Start Here
The agent-side contract: route tool calls through the hook, respect allow / wait / block, and never overclaim what ORBIT observed.
ConceptsHow ORBIT works
How installed coverage, policy outcomes, human authority, decision receipts, execution reports, and proof verification remain separate.
Getting started
Using ORBIT day to day
Needs You
What a held request looks like, how to decide, what happens on timeout, and how temporary access stays bounded.
Private pilotDeploy approval
A provisioned GitHub Actions authority gate with reviewed workflow placement, tenant identity binding, signed authorization, and separate deploy execution evidence.
ReceiptsVerifying receipts
Current web and iPhone file/QR transport, the internal signature and Merkle inclusion boundary, safe sharing, and what remains unproven.
When things go wrong
Break-glass & recovery
Turn ORBIT off, restore your settings, or uninstall — locally, even if the service is unreachable. Governance is never a trap.
Fix itTroubleshooting
Symptom-to-fix mappings for sign-in loops, install, approval alerts not arriving, hook not firing, lost API key, expected-block-was-allowed, offline-verify mismatch, and when to email support.
FAQFAQ
Frequently asked questions: what ORBIT sees, default policy, approval-alert timeout, privacy, receipts, bypass, uninstall, and how it differs from Claude Code permissions.