# Choose your workflow

Source: https://www.testifysec.com/docs/start/workflows

Start with your use case, then follow the shared evidence and trust model through CI/lock, Pushgate, and the platform.

The same system supports several starting points. Learn the [architecture](https://www.testifysec.com/docs/concepts/architecture) and [trust model](https://www.testifysec.com/docs/concepts/trust-model) once, then follow the task you need to complete.

 

## Record and verify work

 

Start here when you need a signed record of a build, test, scan, or operational check.

 

1. [Install CI/lock](https://cilock.dev/getting-started/installation).
 2. [Record your first attestation](https://cilock.dev/getting-started/first-attestation).
 3. Review [which producer and policy you trust](https://www.testifysec.com/docs/cilock/trust).
 4. Decide whether the result will support a gate decision, a technical-control assessment, or standalone verification.

 

## Protect a repository

 

Start here when a push must meet configured evidence requirements before it enters a repository through the gate.

 

1. Read the [Pushgate overview](https://www.testifysec.com/docs/pushgate).
 2. Follow the [repository setup guide](https://pushgate.dev/docs).
 3. Review [security coverage and bypass boundaries](https://www.testifysec.com/docs/pushgate/security-coverage).
 4. Exercise a successful push and a deliberately missing required result in an authorized test repository.

 

## Manage several gates

 

Start here when the same team needs to manage requirements across repositories.

 

Review the [policy and assignment boundaries](https://www.testifysec.com/docs/concepts/architecture#follow-a-repository-change), then the [policy decision reference](https://pushgate.dev/docs/trust/policy). Confirm which policy-release and activation features are enabled in your deployed version before planning a rollout.

 

## Demonstrate a technical control

 

Start with one operational question: did the recovery rehearsal succeed, was a vulnerable component remediated, or did the configuration meet the stated requirement?

 

Define the test and accepted producer, record it with CI/lock, and review the result before mapping it to the control. Follow the [technical-assessment flow](https://www.testifysec.com/docs/concepts/architecture#follow-a-technical-control-assessment). A mapping must retain the scope and limits of the underlying test.

 

## Operate the platform

 

Start with your deployment boundary. Agree who operates identity, trust roots, storage, backups, updates, and recovery. Review the [deployment architecture](https://www.testifysec.com/docs/concepts/architecture#deployment-changes-who-operates-the-boundary) and [trust infrastructure](https://www.testifysec.com/docs/pushgate/trust-architecture) with the supported configuration for your version.

 

The software appliance runs the platform in your environment. It is the same evidence and policy system, with a different operating responsibility.
