Documentation
ORBIT docs
Practical guides for installing and operating Guardian. Start here when you want commands, files, and checks.
Start here
Human Start Here
A plain-English entry point: what ORBIT is, what your phone will do, what proof you get, and where the limits are.
For agentsAI Start Here
The agent-side contract: route tool calls through the hook, respect allow / wait / block, and never overclaim what ORBIT observed.
ConceptsHow ORBIT works
The model behind the product: deterministic authority at the tool boundary — allow, step-up, or deny, always with a receipt. Stable while screens evolve.
Getting started
Using ORBIT day to day
Agent Policy
How default rules work, what is live versus target launch behavior, the Allow / Ask me first / Block verdicts, and how to draft policy edits safely.
ApprovalsApprovals
What an approval alert looks like, how to decide, what happens on timeout, standing approvals (10M / 30M / 1H), and the approvals queue.
CI/CDDeploy approval
Gate production deploys on ORBIT approval: request, policy, signed receipt, and CI-side verification before anything in your cloud changes. GitHub Actions today.
ReceiptsVerifying receipts
What the .orbitproof file contains, web verification that is live today, planned offline CLI verification, receipt tiers, and what failed verification means.
When things go wrong
Break-glass & recovery
Turn ORBIT off, restore your settings, or uninstall — locally, even if the service is unreachable. Governance is never a trap.
Fix itTroubleshooting
Symptom-to-fix mappings for sign-in loops, install, approval alerts not arriving, hook not firing, lost API key, expected-block-was-allowed, offline-verify mismatch, and when to email support.
FAQFAQ
Frequently asked questions: what ORBIT sees, default policy, approval-alert timeout, privacy, receipts, bypass, uninstall, and how it differs from Claude Code permissions.