# host-operator — Ramp-up checklist **Phase:** `ramp_up` **Exit:** all RU-* complete with evidence → set engagement phase to `operating` | ID | Criterion | Evidence path | |----|-----------|---------------| | RU-01 | Access path verified | `access-plan.md` + note of successful observe session | | RU-02 | Host baseline documented | `vault/baselines/.md` | | RU-03 | Coach / orientation brief filed | `reports/orientation.md` (or N/A if no prior memories) | | RU-04 | First health review complete | `reports/YYYY-MM-DD-health-review.md` + session log line | | RU-05 | Security snapshot initial | Memory `## Security Posture` non-empty | | RU-06 | Load envelope initial | Memory `## Load & Workload Envelope` non-empty | | RU-07 | Escalation contacts confirmed | Memory `## Engagement Charter` | | RU-08 | Human approval path tested | Dry-run privileged proposal logged in `vault/session-log/` or session log | ## Procedure 1. Read bound agent definition and this checklist. 2. Verify access (warden/cert/ops-bridge) — **no secrets in vault**. 3. Run baseline capture (OS, disk, memory, load, top workloads, k3s if present). 4. Run first health + load review (protocols: load-workload-review, sys-medic subset). 5. Fill security posture from observe-class checks. 6. Confirm who to escalate to (human operator / on-call). 7. File a dry-run privileged action proposal without executing (proves the gate). 8. Mark RU-* in `checklists/ramp-up-status.md`; charge ramp-up Kai package if funded.