Guard
Blocked unless explicitly allowed. Use for secrets, destructive data changes, protected production paths, and untrusted actors.
Orbit Authority Enterprise
Run agent work across the org without handing every team, vendor, tool, or automation blank-check authority. Orbit applies policy, standing approvals, exceptions, and receipts at the action boundary.
Contact salesBlocked unless explicitly allowed. Use for secrets, destructive data changes, protected production paths, and untrusted actors.
Allowed inside a bounded mandate or after an approval. Use for deploys, payouts, trades, exports, and delegated work.
No checkpoint for low-risk activity. Keep routine work fast and reserve review for consequential actions.
Actor requests a consequential action.
vendor agent: export EU records
Orbit Authority checks authority and scope.
policy: region scope violation + vendor data class guarded
Allow, escalate to a human, or deny.
BLOCK. Owner can create a narrow exception if needed.
Receipt and audit trail recorded.
Receipt records actor, vendor, region, policy, verdict, and timestamp.
Team, account, vendor, tool, environment, and data-class scopes.
Recurring allowed actions with thresholds, expiry, and revocation.
Escalate to owner, wait, timeout, deny, and record the outcome.
Actor, action hash, policy reason, approver, timestamp, and signature.
Deployment boundary
Enterprise ORBIT can run beside your own infrastructure and custom agent frameworks.
Run ORBIT beside your own agent stack, translate your agents' actions into ORBIT's standard format, and keep all traffic inside your boundary.
Use ORBIT-hosted services only when that deployment model is explicitly selected, approved, and scoped.
Some integrations can block before an action runs; others can only watch. ORBIT says which, instead of treating every signal as enforcement.
Receipts and keys
Decisions should produce signed evidence that names the actor, action hash, policy, verdict, timestamp, and key reference.
Enterprise deployments can use customer-controlled or explicitly scoped signing keys where the deployment model requires it.
Receipts prove decisions without exposing secrets, raw prompts, raw file contents, or private infrastructure details.