Factory docs, home
Page navigation

No study yet: this module has no plate position.

What it does for you: It keeps a map of the outside services each Product uses (such as Vercel, Clerk, Sentry, App Store Connect or Google Play) and of where every credential for them lives: which GitHub secret or variable, which workflow job uses it, which template names it, and which provider it is passed on to. It is built to record names, places, dates and whether something is present, never a secret itself; its tests prove that for the kinds of file and value they plant, not for every file anyone could write. From that map it answers one question for other parts of the Factory: can this need (a service, an environment, a purpose such as "publish a build") be met now, and by which route? The answer is ready, missing, unknown or refused. It says missing only when it has seen a complete list, so it never asks you to register something that may already exist, and it flags things worth fixing, such as a public value stored as a secret or a secret passed on a command line, as proposals.

How it links: It stores everything in the Command journal and uses the Portfolio's way of counting, where only an exact count shows zero. Each repository or 1Password vault belongs to exactly one Product, so one Product's services and credentials are never visible from another's. Nothing uses it yet; later steps will read your repositories' secret names, prepare registration steps for you to carry out yourself, and check afterwards that the credential arrived.

Honest limits:

  • Nothing reads a live source yet. Everything is proven on made-up test files shaped like Tally; the real Tally map comes in the next step and may differ.
  • It sees names, never values, so it cannot tell whether a credential works or when it expires. Other branches, older history, values held inside Vercel or Convex, your Keychain and your local files stay unknown.
  • A file path, secret name or other name that looks like a key is never recorded, and the scan is marked incomplete instead. This is a check on shapes, not a secret scanner: a secret that looks like an ordinary name cannot be told apart, and an unusually long name with digits in it is skipped too.
  • Where a workflow or settings template is written in a way that could be read more than one way (a value spread over several lines, an unusually long line, YAML shortcuts such as anchors), it stops reading or marks the scan incomplete rather than guess, so text inside a value is never mistaken for a name.
  • Secrets kept at an organisation's level (for repositories an organisation owns) are not read yet, so for such a repository "missing" can be wrong: the secret may exist at that level.
  • A name is only called missing when every list it could be in was read in full and every place that uses it shows which list that is. A job whose environment it cannot read, or a workflow that other workflows call (whose credentials come from the caller), leaves the answer unknown instead, and such a called workflow never counts as a ready route on its own.
  • A Product with no secrets yet shows "unknown" rather than "missing", because an empty list alone never proves that nothing exists; a later step will let you confirm it.
  • Each Product can have one repository for now. A second is refused rather than overwriting the first repository's map.
  • It spots services from a reviewed list of eleven kinds; anything else shows as unclassified until a new kind is reviewed, and a name the list gets wrong is corrected in the list, not per Product. Its findings are suggestions, not verdicts.
  • Registering for a service, accepting terms, creating keys and anything that costs money stay yours: the Factory will only prepare the steps and check the result. When the answer is that only you can do something (at the service's own website), it says so, so no part of the Factory tries to act on it.
  • Its records are attribution: anyone who can write the journal could forge them, and nothing here proves who you are.

Status: In review: provisionally accepted on Fable 5.1's interim round 1 (max); Astra's review is pending until 3 October 2026, when the highest-numbered astra-r*.md report holds the verdict. Increment 1 was built on 29 September 2026 and revised the same day after a design reviewer's feedback and after an adversarial test pass, whose fourteen attacks each found a flaw that is now fixed. Its first independent code review (Astra) found eight flaws, all now fixed. It is provisionally accepted — Fable 5.1 (max) round 1; Astra review pending (Codex usage limit until 2026-10-03 18:00): a second independent reviewer passed it in the meantime, and Astra's review from 3 October decides whether the acceptance stands. The gap for organisation-level secrets must be closed before any live repository is read. This is local development only, not a release or a customer benefit, and all 27 epics remain open.

Agent reference →

Source: docs/guide/service-access.md