Visibility channel and automation matrix
Status: prepared recommendations only. Nothing in this document applies GitHub settings, registers a service, submits a directory entry or posts externally.
GitHub About recommendation
- Description:
Open-source local proof of concept for governed AI-agent actions across business systems, with policy, approval, brokered execution, authoritative readback, and receipts. - Topics:
ai-agents,agent-governance,ai-governance,policy-enforcement,human-in-the-loop,auditability,docker,crm,erp,openclaw - Homepage: leave unset until PanSphaira owns a stable canonical project or documentation URL. Do not point it at an unverified or temporary site.
Apply these only through a separately authorized GitHub-settings change and read them back anonymously afterward. Topic inclusion describes relevant subject matter; it does not claim complete integrations or production support.
Channel and automation matrix
| Channel | Current posture | Safe deterministic automation | Human/owner gate |
|---|---|---|---|
| GitHub repository/About | Prepared, not applied | Validate source description/topics against this file | Required to mutate settings |
| GitHub Releases Atom | Live read-only feed | Reachability, newest-entry and privacy readback | No mutation needed; publishing remains release-governed |
| GitHub commit Atom | Available but intentionally not promoted | Optional read-only developer check | Required before prominent promotion |
| Future owned docs site | Not created | Build, internal-link, canonical, sitemap, feed and structured-data validation | Required for deploy/domain mutation |
| Package/container registries | No publication authorized | Validate private package metadata and candidate manifests | Required for publish or registry creation |
| OpenSSF / Software Heritage / Zenodo | Not registered here | Prepare metadata and read-only eligibility checks | Required for registration or sync |
Curated software directories / awesome-* lists | No submission | Maintain a candidate/evidence dossier only | Editorial approval for every submission |
| Community, launch and social channels | No posting automation | Draft locally; validate links, claims and privacy | Human approval for every post |
| Agent-native networks | Monitor-only concept | Read-only, isolated safety assessment if separately authorized | Registration, credentials and posting require explicit approval |
| Wikipedia | No-go at current evidence level | None | Reconsider only after substantial independent reliable coverage and COI review |
Automation boundary
Automation may verify owned deterministic artifacts: repository metadata consistency, feeds, links, sitemaps, structured data and anonymous readback with receipts. It must not create accounts, publish packages, submit directories, open third-party pull requests, post to communities or simulate adoption.
Prohibited tactics include keyword stuffing, llms.txt as a ranking trick, directory spam, bought stars/backlinks, fake reviews and unattended third-party posting. Private prompts, credentials, host paths, inventories, analytics identifiers and non-public security details must never enter visibility artifacts.
Review and rollback
Review the recommendation when the proved category, Latest release, canonical site or supported integration surface changes. If later-applied metadata overclaims maturity, remove or narrow it immediately; the repository README, Security Assurance, Known Limitations and release governance remain the public truth sources.