The whole thesis of IntentMesh is that a claim is worth what a stranger can check. So the estate does not describe its own condition — it runs the machinery that measures, records and proves it, and commits every number as a diff anyone can re-derive.
These are the distinctive workflows behind that. Each seals a fact, merges a record from live domains, or audits the estate against itself — and each page links to the exact YAML that runs it and the format it keeps current. A self-auditing estate, in the open.
The past tense, sealed. One entry per thing that shipped, hashed so a stranger can re-verify it, and merged across the estate from what each property actually publishes.
The future tense, decaying. What each repository means to do, filed where the work happens and never allowed to over-report how current it still is.
Who an organisation is to a stranger: the record it is the authority for, and the door it opens — validated at the point each is made, so a bad one fails where it was written.
The estate auditing itself. Every number here is committed as a diff and read from the live network, so a regression arrives as a failing check rather than a slightly worse percentage nobody looked at.
registry.yml10 / 10surfaces.ymlgraph.ymladoption-signal.yml0hygiene.ymlscoreboard.ymlshipos-gate.ymlflashyos-branch-mesh.ymlThe rest is the build, security and publish machinery every serious repository runs — distinctive to nobody, and listed here honestly rather than dressed up. Each links to its own workflow.
ci.yml ↗codeql.yml ↗sbom.yml ↗scorecard.yml ↗secret-scan.yml ↗deploy.yml ↗publish-agent.yml ↗publish-mcp.yml ↗canon-fanout.yml ↗gatewayz-verify.yml ↗Every claim on these pages is checkable against a file the estate publishes. The triggers are read from each workflow’s real on: block, the honest numbers are read from committed JSON, and a drift test fails the build if a page names a workflow that does not exist or a real workflow goes uncategorised.