Workflows
A workflow is a sequence of attested actions, approvals, and handoffs linked by parent IDs.
A workflow is any sequence of Treeship artifacts chained together by parent IDs. Each step links to the previous one, forming a verifiable chain.
Workflow structure
Continue the chain
treeship wrap -- npm testNo --parent needed for the common case: wrap auto-chains onto the previous artifact by reading the local .last file. --parent <id> overrides it explicitly, and TREESHIP_PARENT overrides .last but loses to an explicit --parent. There is no TREESHIP_LAST env var.
Approve a sensitive step
treeship attest approval \
--approver human://alice \
--description "approve deploy to production" \
--allowed-actor agent://deployer \
--allowed-action deploy.production \
--max-uses 1
# -> prints the approval's nonce
# Run the step, then bind it to the approval. wrap itself has no
# --approval-nonce flag; attest action is what consumes the nonce.
treeship wrap -- ./deploy.sh
treeship attest action \
--actor agent://deployer \
--action deploy.production \
--approval-nonce <nonce-from-above> \
--parent <artifact-id-wrap-just-printed>Bundle the chain
treeship bundle create --artifacts art_a1b2,art_c3d4,art_e5f6 --tag deploy-v1.2
treeship bundle export art_bundle_id --out deploy-v1.2.treeshipThe bundle is a portable, self-verifying package of the entire workflow.
Verifying a workflow
treeship verify art_last_stepThe verifier walks the parent chain recursively, checking every signature, every content-addressed ID, and every approval nonce binding.
Bundles verify offline. Share a .treeship file and the recipient can verify the entire workflow without network access, without an account, and without trusting Treeship's infrastructure.
Pushing to the Hub
treeship hub attach
treeship hub push art_last_step
# -> https://treeship.dev/verify/art_xxxAnyone can open that URL and verify the chain.