Bootstrap studio & local adoption control plane

Your projects,
governed like a company.

Company Orchestrator prepares new projects for coding agents and safely adopts company standards into existing repositories — inspection without mutation, reviewed proposals, guarded merges, and certification backed by immutable evidence.

Not the product repo.
The plane above it.

Every repository holds only part of the story — code, pipelines, standards, and agent sessions each know a fragment. Company Orchestrator sits one level up: it registers your projects, reads their evidence, and keeps a living catalog of what each one runs, exposes, and depends on.

  • Inspect without writingRegistration and inspection are read-only. Immutable snapshots, exact commits, zero mutation.
  • Propose, never pushChanges arrive as versioned, digest-protected proposals with a reviewable diff — applied only after approval.
  • Certify with evidenceDelivered standards are verified against exact pipeline runs and sealed with immutable receipts.

The adoption workflow

Six gates between an idea
and a merged standard.

  1. 01Register

    Add a workspace or existing repository inside an approved local root.

  2. 02Inspect

    Read structure, declarations, pipelines, and exact HTTP/MQTT evidence — without writing.

  3. 03Propose

    Generate a versioned, digest-protected change plan from the inspected state.

  4. 04Approve

    Review the plan and diff. Stale-state and path checks block anything out of date.

  5. 05Deliver

    Apply to an orchestrator-owned checkout, publish a review branch, pass PR checks, merge guarded.

  6. 06Certify

    Verify the exact merged runs and record immutable receipts. Compliance becomes current.

Company standards

Standards that ship themselves —
under review.

SmartSystem catalog

Evidence-backed discovery reconciles real HTTP and MQTT traffic across projects. Unique matches become code-confirmed relationships; the rest stay visible as potential boundaries.

ACR deployment metadata

Governed onboarding of container deployment records, certified against the exact artifacts in your registry — digest-pinned, never assumed.

Azure Pipeline Security

Adopts a hardened pipeline contract, validates it against your project's own CI, and certifies the result from immutable run receipts — with a no-rebuild state pipeline.

External image trust

Base images from outside registries are discovered, validated, and admitted through the same guarded proposal flow — including Docker Hardened Images.

Project network

A global map of observed links and reviewed contracts between your projects — provider and consumer proposals are generated from real evidence, never guessed.

Agent access

Coding agents get read-only MCP access to catalog context — what a project is, what it talks to, which standards apply — before they write a line.

Pipeline Map

See what the code
says will run.

A static, evidence-backed graph of your Azure pipelines: stages, jobs, checks, dependencies, and artifact boundaries — projected from exact commits, tied to immutable inspection snapshots, with revision history and structural change summaries. No source code, no secrets, no execution controls.

  • Global blueprint and per-project snapshots
  • Keyboard-accessible graph and list views
  • Unsupported constructs stay visible as bounded unknowns

The safety model

Automation you can
let near your repos.

Read-only by default

Registration, inspection, discovery, and mapping never touch a working tree.

Isolated candidates

Changes are prepared in orchestrator-owned checkouts. Your checkout stays untouched.

Human approval gates

Generation, approval, and delivery are separate operations with stale-state checks.

Fail-closed certification

Missing build IDs, commits, or digests block state generation. No evidence, no compliance.

One control plane.
Every project accounted for.

Company Orchestrator is a working system, developed and run in production on real projects and pipelines.