Skip to content

Visibility channel and automation matrix

Status: prepared recommendations only. Nothing in this document applies GitHub settings, registers a service, submits a directory entry or posts externally.

GitHub About recommendation

  • Description: Open-source local proof of concept for governed AI-agent actions across business systems, with policy, approval, brokered execution, authoritative readback, and receipts.
  • Topics: ai-agents, agent-governance, ai-governance, policy-enforcement, human-in-the-loop, auditability, docker, crm, erp, openclaw
  • Homepage: leave unset until PanSphaira owns a stable canonical project or documentation URL. Do not point it at an unverified or temporary site.

Apply these only through a separately authorized GitHub-settings change and read them back anonymously afterward. Topic inclusion describes relevant subject matter; it does not claim complete integrations or production support.

Channel and automation matrix

ChannelCurrent postureSafe deterministic automationHuman/owner gate
GitHub repository/AboutPrepared, not appliedValidate source description/topics against this fileRequired to mutate settings
GitHub Releases AtomLive read-only feedReachability, newest-entry and privacy readbackNo mutation needed; publishing remains release-governed
GitHub commit AtomAvailable but intentionally not promotedOptional read-only developer checkRequired before prominent promotion
Future owned docs siteNot createdBuild, internal-link, canonical, sitemap, feed and structured-data validationRequired for deploy/domain mutation
Package/container registriesNo publication authorizedValidate private package metadata and candidate manifestsRequired for publish or registry creation
OpenSSF / Software Heritage / ZenodoNot registered herePrepare metadata and read-only eligibility checksRequired for registration or sync
Curated software directories / awesome-* listsNo submissionMaintain a candidate/evidence dossier onlyEditorial approval for every submission
Community, launch and social channelsNo posting automationDraft locally; validate links, claims and privacyHuman approval for every post
Agent-native networksMonitor-only conceptRead-only, isolated safety assessment if separately authorizedRegistration, credentials and posting require explicit approval
WikipediaNo-go at current evidence levelNoneReconsider only after substantial independent reliable coverage and COI review

Automation boundary

Automation may verify owned deterministic artifacts: repository metadata consistency, feeds, links, sitemaps, structured data and anonymous readback with receipts. It must not create accounts, publish packages, submit directories, open third-party pull requests, post to communities or simulate adoption.

Prohibited tactics include keyword stuffing, llms.txt as a ranking trick, directory spam, bought stars/backlinks, fake reviews and unattended third-party posting. Private prompts, credentials, host paths, inventories, analytics identifiers and non-public security details must never enter visibility artifacts.

Review and rollback

Review the recommendation when the proved category, Latest release, canonical site or supported integration surface changes. If later-applied metadata overclaims maturity, remove or narrow it immediately; the repository README, Security Assurance, Known Limitations and release governance remain the public truth sources.

Local synthetic proof of concept — not a production release or security certification.