company-email: mark OpenBao lane provisioned and active

Red provision and capabilities-safe verify complete (WARDEN-WP-0028).
This commit is contained in:
tegwick 2026-07-17 00:33:20 +02:00
parent b2ff07b036
commit 260f734806

View file

@ -1,6 +1,6 @@
# Company Email → Net Kingdom / OpenBao Integration Plan
> Status: Blue facts complete — 2026-07-17 (WARDEN-WP-0028).
> Status: lane active — provision done — 2026-07-17 (WARDEN-WP-0028).
> Goal: `bernd.worsch@binky-hedgehog.com` becomes an agent-readable event
> source so StB replies, bank and authority notices reach the control plane.
> **Credential handover is a single Red-lane founder step** — no agent solicits
@ -63,7 +63,7 @@ password so consumers get one fetch surface. **Password never in git/chat.**
| Fields | `IMAP_USERNAME`, `IMAP_PASSWORD` |
| Policy | `workload-kv-read-binky-company-email-imap` |
| OIDC role | `binky-company-email-imap-workload-kv-read` |
| Catalog | `binky-company-email-imap` (draft until provision) |
| Catalog | `binky-company-email-imap` (active, resolvable) |
| Risk | high |
## email-connect consumer config (non-secret)
@ -91,8 +91,8 @@ Scan output under `mailmeta/` — metadata only (no message bodies in git).
3. [x] CCR-2026-0007 + policy + OIDC role applied (metadata only)
4. [x] ops-warden draft catalog + playbooks
5. [x] Confirm IMAP host/provider facts (IONOS: `imap.ionos.de:993` SSL/TLS)
6. [ ] **Red lane — founder:** provision username/password via `@file` only
7. [ ] Capabilities-safe verify + promote catalog to active/resolvable
6. [x] **Red lane — founder:** provision username/password via `@file` only
7. [x] Capabilities-safe verify + promote catalog to active/resolvable
8. [ ] First read-only scan; file metadata evidence; add to OperatingRhythm
9. [ ] Recurring scan via activity-core (BINKY-WP-0003 follow-ons)