Estate compliance
Source drift across every Roving site: the roving-site marker, the Workshop & Web footer credit,
retired pipeline patterns, baked-in secrets, and CMS fields nothing reads. The scan reads a repo tree over the
GitLab API โ no workspace, no npm ci โ so it runs estate-wide on a schedule.
Sign in requiredCompliance results are scoped to the sites you can reach.
Why this matters beyond tidiness
Commander asserts the
roving-site marker during a create run. Adopted sites never ran that
gate, so none of them carry it โ which means none of them could pass verification if promoted from
adopted_readonly to managed. Clearing this backlog is the prerequisite that makes
take-ownership possible.