# Submit tasks

> You submit tasks as one archive with a collection name. Each task is pinned to a digest, and nothing runs until you confirm the list.

Source: https://docs.horizon-audit.online/docs/guide/submit

You submit tasks as one archive of task folders, with a collection name. Horizon Audit finds every Harbor task in the archive, pins each one to a digest, and shows you a preview. Nothing runs until you confirm the list.

## The archive and its collection name

You give two things:

| What you give     | What it is                                               |
| ----------------- | -------------------------------------------------------- |
| An archive        | A zip or tar file of task folders                        |
| A collection name | The name of the set of tasks that the archive belongs to |

An archive has no address of its own. The collection name says which set of tasks it is. The name is required: without it, no submission is created.

A collection name is used once. A second archive under a name that your organisation has already used is refused. This holds whatever state the earlier submission is in, and it holds for a submission that you cancelled.

An archive that is larger than the limit on its size is refused, and no submission is created.

## Every task is found and pinned

A task is a folder that holds a `task.toml`. Horizon Audit finds every such folder in the archive.

Each task is then pinned to a digest. The task digest is a hash of the task's files, their paths and their contents, exactly as they were read.

- The same files always give the same digest.
- A change of one byte gives a new digest.
- A file that is added, removed or renamed gives a new digest.

A copy of the files is stored when the task is pinned. The audit works from that copy. A verdict holds for the exact files that were audited.

## The preview

While the archive is read, the submission shows "Reading your source". Then you see the preview. It shows how many tasks were found, and the name, the path and the digest of each one.

You choose which tasks go on, and then you confirm. A task that you deselect becomes "Withdrawn" when you confirm.

## Nothing runs before you confirm

Before you confirm, no environment is built and no sandbox starts. Only the tasks you leave selected are checked and audited.

You can cancel in place of confirming. The submission then shows "Cancelled", its tasks become "Withdrawn", and nothing ran. Its collection name stays used. To send these tasks again, use a new name.

## When the archive cannot be read

An archive that cannot be read is not a failed audit. The submission shows "Needs from you", with the reason. Nothing is pinned. The line is one of these:

| What happened                                                               | The line you see                                                                                                            |
| --------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------- |
| The archive cannot be opened                                                | "Needs from you: access to" followed by the source and the reason                                                           |
| The archive holds no `task.toml`                                            | "Needs from you: at least one Harbor task. No `task.toml` was found in" followed by the source                              |
| Two task folders give the same name in `task.toml`                          | "Needs from you: task names that are not shared. These task folders give the same name:" followed by the name and the paths |
| The archive, once read, is over a limit on its size, its files or its tasks | "Needs from you: a smaller source. This one is over our limit on" followed by the limit and its value                       |

You send a new archive, and it replaces the one that could not be read. The submission keeps its collection name. You can also cancel the submission.

A failure on our side while your archive is read is not shown as a request. The read is tried again, and you keep seeing "Reading your source".

## After you confirm

Every selected task shows "Checking" and is held to [the intake standard](/docs/guide/intake-standard). Tasks do not wait for each other. [After you submit](/docs/how-an-audit-runs) says what happens next.
