the governance layer behind Core618

Build fast.
Stay governed.

Orbit618 is the governance engine that controls how AI builds software. Every signal enters a governed pipeline — spec-driven, policy-enforced, fully auditable. Speed without chaos.

GitHub — coming soon See it work
Open source Apache 2.0 Self-hosted or managed
Signal
Triage
Discovery
Spec
🚦Gate
Execute
PR + Merge

Every transition validated. Every action audited. Every actor — human, agent, or LLM — governed.

Orbit doesn't build your product. It governs how it's built.

Core618 ventures run on Ton618 — a shared platform with billing, messaging, CRM, contracts, and landing pages. Orbit618 sits on top, governing every development action: who can do what, when, and under which policies. The result is startups that ship fast and stay auditable.

Founders · AI Agents · Humans
◉ Orbit618 — governance & policies
Ton618 — platform core · billing · messaging · CRM · AI
MyAstralMap Beaver LiveClub

Speed without governance is technical debt accelerated.

AI coding agents write code 10x faster. But speed without guardrails creates risk: status changes without validation, code generation without specs, PRs without review, agents acting without constraints. When the auditor asks "who approved this AI-generated code?", you have no answer.

90%

AI adoption increase

+9%

more bugs reported

+91%

more review time

0

governance solutions

From Sentry alert to merged PR in 8 minutes.

This is the single demo that proves the entire Orbit618 thesis.

0:00

Signal arrives

Sentry fires at 3 AM: AttributeError: 'NoneType' in auth/middleware.py:42. 47 occurrences, 12 users affected.

0:15

Triage + Discovery

Orbit reads the actual codebase (not generic LLM guess), identifies root cause: user.session is None for anonymous users. Risk: LOW.

1:30

Spec generated

Structured spec created: problem statement, proposed fix, acceptance criteria, affected files. Not a prompt — a governed artifact.

2:00

Governance gate

LOW risk + balanced template = auto-approved. For HIGH risk, a human reviews. Configurable per company, project, and module.

3:00

Agent executes

Claude Code writes the fix step by step, governed by file scope per step. Adds null check + test. Every action logged.

6:00

PR created

Full governance trail attached: trigger → spec → approval → execution log. CI runs. Tests pass.

8:00

Auto-merged

LOW risk + CI green = auto-merge. Dev wakes up to a resolved incident with complete audit trail. Sentry marked resolved.

FSM

State machine enforcement

Canonical lifecycle: Backlog → Spec → Arch → In Progress → Review → Staging → Done. Invalid transitions are rejected and automatically reverted. No exceptions, no shortcuts.

POLICY

Policy-as-code

Declarative, version-controlled rules. Require specs before architecture. Enforce human approval before staging. Restrict which agents can act in which states. Ship as policy packs.

GUARD

Context guard

Control what each actor can see and do, scoped by project and state. LLM A only operates on Project X during Spec. Deploy agent only triggers in Staging. Precise, granular boundaries.

AUDIT

Audit-first architecture

Every governed action produces a structured event: actor identity, transition, rule applied, decision, timestamp. Immutable log. Enterprise compliance-ready from day one.

AGENT

Agent governance layer

Identity registration, capability model, 3-tier risk classification (EU AI Act aligned), rate limiting, circuit breaker, and configurable human-in-the-loop gates.

MCP

Model context protocol

7 governed MCP tools. Every call respects FSM + policies + context. Claude Code, GPT, or any MCP-compatible LLM connects instantly. Pull-based agent model.

9 signal sources. One governed pipeline.

Every trigger is normalized into a canonical intake. Deduplicated, rate-limited, and risk-classified before entering the pipeline.

ClickUp
Jira
GitHub
Sentry
DataDog
Slack
REST API
PR Comments
Scheduled

From full oversight to hands-free delivery.

Configure governance gates per hierarchy level. Conservative for new features, aggressive for bug fixes. Every team finds their own balance.

CompanyGlobal defaults
ProjectOverride per project
ModuleFine-grain per module
conservative balanced aggressive hands-free
Orbit618 Dashboard
CapabilityDevinSweepCodeRabbitOrbit618
Trigger sourcesSlack, JiraGitHub IssuesPR webhook9 sources
Discovery / ResearchAI-driven sessions
Spec generationBusiness + Technical
Risk classificationPartialPer company/project/module
Configurable gates0 to 4+ per risk level
Audit trailReplay logGit onlyPR commentsFull lineage
Auto-mergeLOW risk + CI green
Executor freedomDevin onlySweep onlyN/AAny executor
Open sourcePartialApache 2.0

Zero vendor lock-in.

Push or pull model. Use the executor that fits your workflow. Switch anytime.

pull · MCP

Claude Code

Primary executor. Agent pulls tasks from Orbit via 7 governed MCP tools. Every action respects FSM, policies, and context guards. The fastest path from spec to merged PR.

142 governed actions Pull-based model Real-time audit
push

OpenHands

API-based. Orbit pushes execution steps to the agent runtime.

pull

Continue

IDE integration. Developer-assisted execution with governance overlay.

local

Local agent

Run your own executor. Orbit governs, you execute.

EU AI Act

3-tier risk classification for autonomous agents. HIGH-risk gates enforced.

SOC 2

CC6 / CC7 controls coverage. Audit trail satisfies evidence requirements.

ISO 42001

AI management system alignment. Policy-as-code maps to control objectives.

Colorado AI Act

Algorithmic accountability requirements. Full decision lineage from trigger to merge.

Open Source

Free

Apache 2.0 forever

  • Core governance engine
  • Discovery + executors + MCP
  • CLI + admin UI
  • ClickUp / GitHub connectors
  • Community support

Enterprise

$x,xx/user/mo

For regulated industries

  • Everything in Team
  • SSO + SCIM + scoped RBAC
  • Policy versioning + audit exports
  • Tenant isolation + SLA
  • Dedicated support

141

specs implemented

45

specs backlog

1,493

tests passing

9

trigger sources

Live

ClickUp GitHub MCP (Claude, GPT)

Coming soon

Jira GitLab Linear Sentry DataDog Slack Asana Bitbucket

Governance that ships with you.

Open source. Self-hosted or managed. Apache 2.0.

GitHub — coming soon Talk to us ← Back to Core618