Restore with control.
YellowRose turns approved findings into controlled, verifiable restoration. It prepares tested actions, applies the right approval based on potential impact, records exactly what changed, and confirms that the approved state has been restored.
Nothing acts outside its approved boundary. Anything that changes production waits for human authorization.

YellowRose accepts an approved finding from Vigil or another governed source. It does not invent the problem, expand the scope, or decide that action is authorized.
The proposed restoration follows a reviewed playbook with a known objective, expected impact, verification method, and recovery path — not an improvised fix.
The greater the potential consequence, the stronger the required authorization. YellowRose stages the work and waits wherever human judgment is required.
Every action remains connected to its finding, playbook, authorization, execution history, and result. Where practical, a tested recovery path is prepared before the action begins.
After restoration, the environment is checked again against the approved state. A change is not complete merely because a task ran successfully.
YellowRose operates within three clear action tiers. The system may prepare the work, but authority determines whether automation proceeds, a person must approve, or the action remains practitioner-only.
Low-risk, reversible, tightly bounded actions may run inside a previously approved envelope. They do not alter production outside that authority.
Production-facing or higher-risk actions are prepared and staged, but execution waits for an authorized person to review and approve the change.
Some actions are barred from automation. YellowRose surfaces the finding, prepares the available context, and leaves execution to an authorized practitioner.
GRITS organizes the proof. Vigil reveals the operational truth. YellowRose restores the approved state. StandFast holds the watch.