Skip to main content
By default each repository commits its own agent instructions: .outerlayer/ and the files outerlayer context emit writes from it, such as AGENTS.md, CLAUDE.md, .claude/, .cursor/, .agents/ and .mcp.json. A factory can instead name one repository as its context source. It lists the repositories it supplies. The CLI writes its instructions into their working trees at the start of every session, and they are never committed there. Use this when you run several repositories and want one place to change how agents behave and what evidence they must produce.
CLI commands and messages call the context source the control plane. The command that fetches its files is outerlayer context materialize.
Two things then come from the context source instead of from each repository: A factory with no context source checks each pull request under the policy in its own repository, at its base branch.

Name the context source

In that repository’s .outerlayer/config.json, list the repositories it governs:
Then pick it as the context source in the factory’s settings. A factory has at most one. Naming a second is refused, and the refusal names the one in place.

The commit each governed repository must make

In each governed repository, delete AGENTS.md, .claude/ and .outerlayer/ in one commit to the base branch. Until that commit lands, the CLI writes nothing. outerlayer context materialize, and the session-start hook that runs it, report that committed files shadow the context source. The message reads committed context files shadow the control plane — remove them in a commit. One file goes the other way. The CLI writes .outerlayer-pin.json at the repository root, and you do commit it. It records which commit the instructions came from.

What a session does in a governed repository

At session start the CLI asks OuterLayer which repository supplies this checkout, and which branch to read. It fetches that branch from your git host with your own git credentials, and writes the instructions into the working tree. It copies only three paths from the context source, as committed there: AGENTS.md, everything under .claude/, and everything under .outerlayer/. A root CLAUDE.md, .cursor/, .agents/ and .mcp.json are not copied. So a governed repository gets Claude Code’s skills and commands and the shared AGENTS.md, but not Cursor’s or Codex’s skills, and no MCP servers. It also adds the four maintained skills at the installed CLI’s version. If OuterLayer or the git host cannot be reached, the session keeps what was written last and says which commit it came from. If nothing was ever written, the session runs without those instructions. The session’s detail page shows whether its instructions were verified as current. Run it by hand:
It exits 0 when it wrote the instructions, when they are already current, or when the repository supplies its own. It exits 1 when:
  • the current directory is not in a git repository;
  • committed files shadow the context source;
  • OuterLayer or the git host cannot be reached, or you have no access to the context source;
  • OuterLayer cannot confirm which repository supplies this one;
  • the context source’s governs list does not name this repository.

Set a check’s level everywhere at once

Give a check a level in the context source’s policy, and it applies to every repository it supplies. This turns code-review off everywhere:
A policy error row has no level and cannot be turned off. See Policy and validators.

Manage it through the API

The factory’s settings page calls /v1/orgs/{orgName}/apps/{appId}/context-source, and a script can call it too. {appId} is the factory’s id. A signed-in member’s session works on every plan. A management API key works on an Enterprise plan. A factory’s own API key never can. See Organization API for keys and permissions.