feat: Native Intent → Execution → Evidence foundation with optional ISEE governance
Maintainers usually reply within 2 days
Assessment
This issue has not been assessed yet.
Description
Summary
Establish a portable governance foundation for Git-Ape that records deployment
Intent, captures what actually executed, and preserves immutable Evidence without
requiring the ISEE suite to be installed.
ISEE remains an optional governance and independent-verification layer that can
be installed before or after Git-Ape records are created.
Motivation
Git-Ape already performs security, cost, architecture, approval, deployment, and
validation stages. However, these stages need portable, machine-readable records
that preserve:
- what was intended;
- which execution path actually occurred;
- which artifacts and control results were produced;
- who or what authorized the deployment;
- whether records were independently governed or verified.
These records should remain useful without introducing a mandatory runtime or
package dependency.
Scope
- Save onboarding and deployment Intent as ADRP-compatible draft records.
- Declare versioned deployment execution graphs.
- Capture immutable, graph-bound execution traces.
- Derive CI traces from actual workflow step outcomes.
- Label interactive traces as
agent-observed. - Emit immutable AERP-compatible Evidence bundles for successful and failed runs.
- Bind Evidence to exact artifact bytes and archived graph versions.
- Support delayed adoption by ADRP, ASRP, and AERP tooling.
- Preserve truthful lifecycle states:
- native Intent is
draft; - native Evidence is
generated; - only authoritative tooling may ratify or independently verify records.
- native Intent is
- Retain Git-Ape's existing Bash,
jq, and SHA-256 dependency baseline.
Relationship to #148
#148 delivers the structured execution-trace portion of this foundation.
The trace implementation deliberately uses workflow-owned reconstruction in CI
rather than requiring agents to self-report their own completeness. Interactive
agent observations remain supported, but are explicitly identified as
agent-observed and are not represented as independent proof.
The Intent, trace, Evidence, and optional ISEE integration are tightly connected
and may be delivered through one implementation PR referencing both issues.
Acceptance criteria
- Onboarding preserves platform Intent as an ADRP-compatible draft.
- Each deployment preserves deployment-specific Intent before execution.
- Each workflow attempt receives an immutable invocation identity.
- The exact execution graph used by each attempt is archived.
- Traces are bound to the archived graph digest.
- Trace validation checks nodes, transitions, receipts, ordering, continuity,
required successful nodes, and terminal outcomes. - Failed attempts can produce valid traces ending at the failed node.
- Evidence bundles include trace, validation, graph, state, test, and relevant
deployment artifacts. - Evidence is emitted for successful and failed attempts.
- Optional ISEE adoption validates existing records without regenerating or
automatically ratifying them. - Record or Evidence failures do not rewrite Azure deployment lifecycle state.
- Native operation introduces no runtime dependency beyond existing Bash/
jq
tooling. - Scaffolding, tests, evaluations, and user documentation cover the lifecycle.
- Dominant language
- JavaScript
- Stars
- 269
- Forks
- 48
- Avg merge
- 3d 32m
- Merged PRs (30d)
- 14
Getting set up
Starts the project's dev container in your browser, under your own GitHub account.
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from Azure/git-ape
-
daily-status report
Difficulty 3/5 Half a day Newbie friendliness 5/100
Maintainers usually reply within 2 days
-
agentic-workflows workshop workshop-sync
Difficulty 1/5 Under an hour Newbie friendliness 1/100
Maintainers usually reply within 2 days
-
report workshop-coverage
Difficulty 5/5 Over a week Newbie friendliness 1/100
Maintainers usually reply within 2 days
-
agentic-workflows
Difficulty 4/5 3-5 days Newbie friendliness 25/100
Maintainers usually reply within 2 days
-
agentic-workflows
Difficulty 4/5 3-5 days Newbie friendliness 35/100
Azure/git-ape#370 · 1 comment ·
Maintainers usually reply within 2 days
Similar issues
-
Difficulty 1/5 Under an hour Newbie friendliness 72/100
yjh051108/dsh-routing-suite#216 ·
-
bug user-priority/P2
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Maintainers usually reply within 4 days
-
bug confirmed perf
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
videojs/video.js#9400 · 1 comment ·
Maintainers usually reply within 1 day
-
agent/scanner bug hive/hosted-available-lke648397-260827-5n31
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
Maintainers usually reply within 1 day