.outerlayer/ and the files outerlayer context emit writes from it, such as AGENTS.md, CLAUDE.md, .claude/, .cursor/, .agents/ and .mcp.json.
A factory can instead name one repository as its context source. It lists the repositories it supplies. The CLI writes its instructions into their working trees at the start of every session, and they are never committed there.
Use this when you run several repositories and want one place to change how agents behave and what evidence they must produce.
CLI commands and messages call the context source the control plane. The command that fetches its files is
outerlayer context materialize.
A factory with no context source checks each pull request under the policy in its own repository, at its base branch.
Name the context source
In that repository’s.outerlayer/config.json, list the repositories it governs:
The commit each governed repository must make
In each governed repository, deleteAGENTS.md, .claude/ and .outerlayer/ in one commit to the base branch.
Until that commit lands, the CLI writes nothing. outerlayer context materialize, and the session-start hook that runs it, report that committed files shadow the context source. The message reads committed context files shadow the control plane — remove them in a commit.
One file goes the other way. The CLI writes .outerlayer-pin.json at the repository root, and you do commit it. It records which commit the instructions came from.
What a session does in a governed repository
At session start the CLI asks OuterLayer which repository supplies this checkout, and which branch to read. It fetches that branch from your git host with your own git credentials, and writes the instructions into the working tree. It copies only three paths from the context source, as committed there:AGENTS.md, everything under .claude/, and everything under .outerlayer/. A root CLAUDE.md, .cursor/, .agents/ and .mcp.json are not copied. So a governed repository gets Claude Code’s skills and commands and the shared AGENTS.md, but not Cursor’s or Codex’s skills, and no MCP servers. It also adds the four maintained skills at the installed CLI’s version.
If OuterLayer or the git host cannot be reached, the session keeps what was written last and says which commit it came from. If nothing was ever written, the session runs without those instructions. The session’s detail page shows whether its instructions were verified as current.
Run it by hand:
- the current directory is not in a git repository;
- committed files shadow the context source;
- OuterLayer or the git host cannot be reached, or you have no access to the context source;
- OuterLayer cannot confirm which repository supplies this one;
- the context source’s
governslist does not name this repository.
Set a check’s level everywhere at once
Give a check a level in the context source’s policy, and it applies to every repository it supplies. This turnscode-review off everywhere:
Manage it through the API
The factory’s settings page calls/v1/orgs/{orgName}/apps/{appId}/context-source, and a script can call it too. {appId} is the factory’s id.
A signed-in member’s session works on every plan. A management API key works on an Enterprise plan. A factory’s own API key never can. See Organization API for keys and permissions.