{
  "id": "artifact:when-the-agent-had-to-ask-github",
  "slug": "when-the-agent-had-to-ask-github",
  "title": "When the Agent Had to Ask GitHub",
  "thesis": "A mature autonomous system must know where its authority and evidence end, and route unresolved questions to the human or institution that actually owns the answer.",
  "abstract": "A field story from Control Tower convergence: a GitHub App token-revocation contradiction could not be resolved from local evidence or public documentation, so the system failed closed, assembled an evidence-grade escalation, crossed a human institutional boundary, consumed GitHub Support's clarification, and replaced an unenforceable provider-state invariant with an enforceable client-side contract.",
  "topics": [
    "ghostmesh",
    "control-tower",
    "governed-autonomy",
    "human-in-the-loop",
    "authority-routing",
    "github",
    "credential-lifecycle",
    "fail-closed-systems",
    "engineering-evidence"
  ],
  "date": "2026-08-11",
  "dateLabel": "Published",
  "published": true,
  "publicationState": "PUBLISHED",
  "updated": "2026-08-11",
  "sourceDates": {
    "created": "2026-08-11",
    "updated": "2026-08-11",
    "external_authority_response": "2026-08-11",
    "published": "2026-08-11"
  },
  "kind": "Engineering field story",
  "sourceFamily": "SharePlane Platform",
  "href": "architecture/when-the-agent-had-to-ask-github/index.html",
  "contextHref": "records/when-the-agent-had-to-ask-github/context.txt",
  "recordHref": "records/when-the-agent-had-to-ask-github/work.json",
  "receiptHref": "records/when-the-agent-had-to-ask-github/receipt.json",
  "packageHref": "downloads/works/when-the-agent-had-to-ask-github.zip",
  "canonicalUrl": "https://shareplane.malott.ai/architecture/when-the-agent-had-to-ask-github/",
  "sources": [
    {
      "id": "source:shareplane-platform-issue-389",
      "type": "governing-publication-authority",
      "title": "When the Agent Had to Ask GitHub",
      "locator": "https://github.com/pinklon/shareplane-platform/issues/389",
      "role": "Governs the locked manuscript, evidence boundary, voice, Creative Lock, Development publication boundary, and owner UAT.",
      "publiclyExposed": true
    },
    {
      "id": "source:github-rest-installation-revocation",
      "type": "primary-vendor-documentation",
      "title": "REST API endpoints for GitHub App installations",
      "locator": "https://docs.github.com/en/rest/apps/installations",
      "role": "Current primary corroboration for the documented revocation endpoint, HTTP 204 success response, invalidation posture, and requirement to create a new installation token for later authenticated requests.",
      "publiclyExposed": true
    },
    {
      "id": "source:github-credential-types",
      "type": "primary-vendor-documentation",
      "title": "GitHub credential types",
      "locator": "https://docs.github.com/en/organizations/managing-programmatic-access-to-your-organization/github-credential-types",
      "role": "Current primary corroboration for GitHub App installation-token lifecycle and revocation guidance.",
      "publiclyExposed": true
    }
  ],
  "posture": "Owner-originated field story grounded in internal Control Tower evidence, a sanitized external GitHub Support response, and current GitHub primary documentation for the client-facing revocation contract.",
  "media": [],
  "schema": "shareplane.portable-work.v1",
  "author": {
    "name": "Tony Malott",
    "url": "https://malott.ai/"
  },
  "content": {
    "mediaType": "text/plain",
    "path": "records/when-the-agent-had-to-ask-github/context.txt",
    "sha256": "8559021ca474c8e9af65868a618a24de4b5bd6ffcf6414003be6f8f5511442d2",
    "complete": true,
    "extraction": "Native presentation reading order; scripts, styles, and platform chrome excluded."
  },
  "relationships": [
    {
      "source": "artifact:when-the-agent-had-to-ask-github",
      "target": "artifact:the-agent-is-not-the-product-the-control-plane-is",
      "type": "foundation",
      "group": "foundations",
      "label": "Start with the governed control-plane boundary",
      "explanation": "The control-plane thesis establishes that authority, containment, evidence, and recovery belong outside model behavior; this Work shows that principle holding when provider truth lives beyond the local system."
    },
    {
      "source": "artifact:when-the-agent-had-to-ask-github",
      "target": "artifact:stop-prompting-agents-start-managing-workers",
      "type": "foundation",
      "group": "foundations",
      "label": "Start with bounded worker authority",
      "explanation": "The worker-management model establishes bounded roles, evidence, supervision, and earned autonomy; this Work extends the same logic to an external institutional authority boundary."
    },
    {
      "source": "artifact:when-the-agent-had-to-ask-github",
      "target": "artifact:the-mesh-is-no-longer-a-diagram",
      "type": "architecture_companion",
      "group": "architecture_companion",
      "label": "Internal semantic companion: The Mesh Is No Longer a Diagram",
      "explanation": "The current GhostMesh architecture checkpoint is semantically related but remains protected Development and is therefore not projected as reader navigation."
    }
  ],
  "representations": {
    "html": "architecture/when-the-agent-had-to-ask-github/index.html",
    "text": "records/when-the-agent-had-to-ask-github/context.txt",
    "json": "records/when-the-agent-had-to-ask-github/work.json",
    "package": "downloads/works/when-the-agent-had-to-ask-github.zip"
  }
}
