A narrow facade over governed work

Evidence without a side door.

Read the shared governance estate, submit structured issues only to repositories already present in the exported governed inventory, inspect exact recorded evidence, and manage tenant-scoped API data. The facade does not bypass governance gates or promise future pickup.

Production origin: https://governance-api.preview.aicoe.io. Bearer-token API at /v1. Signed-action HTTP routes are disabled pending a separate direct STOP-aware authority broker.

What the API actually exposes

Read-heavy by design.

Public health, authenticated shared-state reads, tenant-scoped account data, and narrow attributed writes.

01

Classify

Use the deployment's advisory JEV relay for work kind, risk, impact, and spec readiness.

POST /v1/jev/classify
02

Submit

Create an attributed GitHub issue only after the exported inventory confirms the repository is governed. Later processing remains subject to normal policy and sweeps.

POST /v1/submissions
03

Verify status

Inspect the exported queue, issue state, attempts, spec state, and last outcome.

GET /v1/issues/…/status
04

Read evidence

Retrieve recorded receipts and digests. The API reports evidence that exists; it does not invent it.

GET /v1/issues/…/evidence

Governed path

Submit. Classify. Spec. Verify. Evidence.

Accepted API submissions create issues in inventory-confirmed repositories. They do not guarantee pickup, and no endpoint skips into implementation.

Input

Structured, attributed writes

A submit token can open a template-complete issue or answer an existing governance ask. The resulting GitHub artifact carries token-name attribution.

Output

Exact exported state

Status and evidence endpoints read the sanitized governance snapshot. Missing or unavailable state fails closed instead of being guessed.

Non-negotiable boundaries

Useful access, limited authority.

AuthorityNo code-authoring endpoint. No merge endpoint. No signed-action endpoint.

The non-root facade cannot atomically inspect the global STOP sentinel at an action append boundary. Signed-action HTTP routes are disabled until a separate direct STOP-aware authority broker exists.

TenancyTenant-owned data is isolated; loop state is shared.

Models, quality receipts, usage, abuse records, quota counters, and tokens are scoped to the calling token's tenant. Health, queue, issue, evidence, and policy reads expose the shared governance estate for this deployment.

Server-rendered, no JavaScript required

Request a tenant or open your account.

Signup is reviewed by an operator. This beta deployment has no mail connector: the verification code is shown once to the requester and retained only as a salted hash. Status checks use POST bodies, never URL credentials. The account dashboard keeps tokens out of URLs, hidden fields, browser storage, and rendered pages.