B8Grid Source Graph trust plane showing session, audit, policy, and provenance lanes
BB8Grid Source Graph

Cloud Trust first

A trust plane for source, not another forge-shaped dashboard.

Source Graph treats identity, policy, audit, and source movement as one product loop, so teams can trust local and hosted work without hidden actor spoofing.

Install
Direct B8Grid CLI install
Identity
Cloud Trust session
Operations
CLI and web parity
Posture
production-paas-alpha / Not GA
01

Install

Download a signed B8Grid CLI artifact from B8Grid Releases.
02

Log in

Use device-style Cloud Trust auth and keep token material out of project config.
03

Initialize

Run source init so the local workspace and cloud project become one visible spine.
04

Operate

Review, sync, audit, and manage the same Source Graph actions from CLI or web.

Security and platform teams

One user loop, two trusted surfaces

Source Graph treats identity, policy, audit, and source movement as one product loop, so teams can trust local and hosted work without hidden actor spoofing.

  • Cloud Trust sessions are the authority for hosted actions.
  • Session metadata is safe to persist; token material stays in secure storage or env handoff during alpha.
  • Audit, policy, provenance, and production posture are surfaced as product state.

System checklist

Done vs left

Done

  • Local Source Graph primitives, review proposals, native remotes, and Git compatibility.
  • Hosted product and management pages with metadata-only source safety.
  • Signed local actor sessions and focused hosted acceptance gates.

Left

  • Production B8Grid Releases signing infrastructure and installer mirrors.
  • External IdP, KMS, WAF/rate limits, audit export, support, billing, and deployed smoke evidence.
  • Promotion remains blocked: generalAvailability is false and production-paas-alpha is Not GA.

CLI/Web parity

Same Source Graph control from both sides

OperationCLIWebStatus
source.initsupportedsupportedProject appears in app after local init.
proposal.reviewsupportedsupportedReview, comments, queue, merge, audit.
policy.managementsupportedsupportedRules, import preflight, roster, admin actions.
workspace.local-hydratesupportedintentionally-local-onlyKeeps local filesystem materialization honest.