The Machine

How the estate stays honest.

The whole thesis of IntentMesh is that a claim is worth what a stranger can check. So the estate does not describe its own condition — it runs the machinery that measures, records and proves it, and commits every number as a diff anyone can re-derive.

These are the distinctive workflows behind that. Each seals a fact, merges a record from live domains, or audits the estate against itself — and each page links to the exact YAML that runs it and the format it keeps current. A self-auditing estate, in the open.

The record

The past tense, sealed. One entry per thing that shipped, hashed so a stranger can re-verify it, and merged across the estate from what each property actually publishes.

Shiplog
Every thing this repository shipped, sealed so a stranger can re-verify it.
shiplog.yml
Estate record
The estate’s two tenses, merged from the live sites and never from these checkouts.
estate-record.yml

The intent

The future tense, decaying. What each repository means to do, filed where the work happens and never allowed to over-report how current it still is.

Backlog
What this repository intends to do, published the way facts are and never allowed to go stale quietly.
backlog.yml

The relationships

Who an organisation is to a stranger: the record it is the authority for, and the door it opens — validated at the point each is made, so a bad one fails where it was written.

Directory
This repository’s slice of the record, validated at the point it is made.
directory.yml
Front door
The door this repository opens to strangers, re-emitted and validated on every push.
frontdoor.yml

The measurement

The estate auditing itself. Every number here is committed as a diff and read from the live network, so a regression arrives as a failing check rather than a slightly worse percentage nobody looked at.

Registry
A badge granted once and never re-checked becomes a sticker, so this re-verifies every conformant org.
registry.yml10 / 10
Surfaces
Can a stranger actually read what this estate says it publishes.
surfaces.yml
Estate graph
One graph, assembled from what properties actually publish rather than from any checkout.
graph.yml
Adoption signal
Is anybody outside the estate actually using this — and the honest answer is the whole point.
adoption-signal.yml0
Hygiene
The estate’s own condition, ratcheted against a floor so nothing fixed can quietly break.
hygiene.yml
Scoreboard
The estate grades itself in public, read from the live sites the way a stranger would.
scoreboard.yml
ShipOS gate
Is tested-and-green work waiting past budget anywhere in the estate.
shipos-gate.yml
FlashyOS branch mesh sync
This repository’s active branches, reported to the mesh under the role that owns each one.
flashyos-branch-mesh.yml

The operational baseline

The rest is the build, security and publish machinery every serious repository runs — distinctive to nobody, and listed here honestly rather than dressed up. Each links to its own workflow.

CIci.yml
Typecheck, lint and the whole test suite, on every pull request and every push off main.
CodeQLcodeql.yml
GitHub’s static security analysis over the source, on main and production and weekly.
SBOMsbom.yml
A software bill of materials generated on every published release.
OpenSSF Scorecardscorecard.yml
The OpenSSF supply-chain posture score, on main, on branch-protection changes and weekly.
secret-scansecret-scan.yml
Scans pushes and pull requests for committed credentials, and sweeps weekly.
Deploy proddeploy.yml
Builds and deploys production on every push to main.
Publish packages to npmpublish-agent.yml
Publishes the open packages when a version bump to one of them lands on main.
Publish @flashyos/mcp to npmpublish-mcp.yml
Publishes the MCP server on its own cadence, when packages/mcp changes on main.
Canon fan-outcanon-fanout.yml
When a fact this host is the authority for changes, signals every property that renders it — a notification, not a push: the receiving repository still decides what to do with it, which is the difference between propagation and a write nobody consented to.
Gatewayz seam verificationgatewayz-verify.yml
On-demand smoke test of the inference-provider seam, run from an environment that can reach the provider — an operational check of one integration, not estate-condition machinery, and already the “stays honest” workflow on /packages/llm-gateway.
Why this is not marketing

Every claim on these pages is checkable against a file the estate publishes. The triggers are read from each workflow’s real on: block, the honest numbers are read from committed JSON, and a drift test fails the build if a page names a workflow that does not exist or a real workflow goes uncategorised.

The formats these keep current →The estate’s own scoreboard →The conformance ladder →