AI-native change governance

Know what changed, what can fail, and what needs attention.

Amberly runs four independent agents against the exact SHA, verifies evidence, and publishes separate Risk and Attention signals. Green keeps the usual flow. Unknown means Hold.

Amberly Signal

Exact SHA 8f3b91a

Red · Hold

Authentication boundary can fail closed.

Evidence reproduced the changed authorization path

One contradiction remains visible in the dossier

Every required risk surface was checked at this SHA

Required action: resolve the Critical finding before merge.

How it works

Durable work, independent evidence, one clear decision.

Graphile Worker runs the four stages durably. Evidence Verification seals its blind pass before Production Risk Review is revealed. The integrity guard validates the result and enforces safety floors.

01 Exact-SHA change map
Amberly reviews the complete base and head archives and names every coverage gap.
02 Four independent agents
Change Intelligence, Production Risk Review, Evidence Verification, and Governance Synthesis stay separate.
03 Risk + Attention
A semantic decision says what risk exists and what human attention the change needs.
04 One current card
GitHub receives one Amberly Signal Card that updates when the exact head SHA changes.

Amberly Signal Card

Risk and Attention are different questions.

Risk is Green, Amber, Red, or Unknown. Attention is No extra attention, Focused attention, Expert attention, or Hold. All supported Critical findings remain visible, with evidence and named gaps.

Risk
Red
Attention
Hold
Evidence
Supported
Exact SHA
8f3b91a

Outcome loop

Outcomes inform evaluation without rewriting history.

Amberly records human decisions, deployment state, and exact-SHA reverts in an immutable ledger. These observations do not prove that Amberly caused an outcome.

Review
First eligible review timing.
Delivery
Deployment success or failure.
Stability
Seven-day revert observation.

Security program: building

Content-minimized by design.

Raw source, full patches, prompts, and model responses are not persisted. Analytics receives allowlisted metadata only. Read the current controls and honest gaps on our security page.

Read security details