| name | hmg-migrate |
| description | Execute a reviewed HMG migration plan with provenance, dry-run safety, and secret rejection. |
HMG Migrate
Use this workflow only after an import plan has been reviewed.
Workflow
- Confirm dry-run output, source provenance, scope mapping, and DLP result.
- Execute through typed HMG CLI or MCP writes.
- Keep imported atoms tagged with source/provenance.
- Run scoped recall smoke after import.
- Record a handoff with migration scope, validation, risks, and rollback notes.
Secrets and raw credentials remain rejected by default.