Identity and entitlement
Supabase-backed sessions and server decisions gate hosted work. Organization roles, memberships, route eligibility, pooled usage, and concurrency are checked before provider dispatch.
Orrery combines server-enforced cloud access, scoped agent permissions, human approval gates, usage reservations, and evidence receipts. This page describes product behavior, not a certification.
Supabase-backed sessions and server decisions gate hosted work. Organization roles, memberships, route eligibility, pooled usage, and concurrency are checked before provider dispatch.
Agent, room, workspace, connector, route, browser, network, and export permissions are scoped. Child policies may tighten but cannot weaken parent restrictions.
Worst-case provider cost is reserved atomically, actual use is settled afterward, and failed or cancelled work is refunded. Organization kill switches stop new dispatch.
Metadata receipts record lifecycle, approval, route, usage, boundary, and proof state. Raw source, raw diffs, prompts, credentials, and private reasoning stay outside dashboard payloads.
Slack requests are signature-verified and replay-protected. Explicit selected context is mapped to approved workspaces and rooms; broad passive history collection is not the default.
Public binaries are intended to pass signing, package leak, update metadata, and release checks. Current beta artifact and platform availability are shown on the download page.
Orrery does not claim SOC 2, ISO 27001, HIPAA, PCI DSS, FedRAMP, or other certification unless a current written statement says otherwise. BAAs, regulated-industry commitments, custom retention, SSO/SCIM availability, support levels, and data-processing terms require a signed agreement and vendor/legal review.