From the Inside Claude Code: The Claude Code Ecosystem architecture map

Start with the gate order in the Run Orchestrator

observation · medium · verified

run.ts decides whether untrusted input reaches Claude at all. It checks the trigger, then the actor and write permission, then on PRs restores config from the base branch, and only then prepares tag or agent mode. Reading these calls in order explains most of the action's security model before any prompt code.

Learn the GitHubContext union in src/github/context.ts next: every gate branches on isEntityContext and the event type.

The trail

  1. Run Orchestrator
  2. Trigger Check
  3. Actor and Permission Checks
  4. Sensitive Config Restore
  5. Tag Mode
Open on the map

More from this board

© 2026 Syntaxia App Platform Ltd.

Syntaxia App Platform Ltd. Registered in England and Wales, company no. 15272701 Registered office: 3rd Floor, 86–90 Paul Street, London EC2A 4NE, United Kingdom contact@provenmap.com