kaizen-agentic/engagements/pilots/eng-coulomb-railiance01-ho-001/CUSTODY.md
tegwick d691135c4a
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
ci / test (push) Successful in 52s
docs: consolidate agent execution and custody
2026-08-20 22:43:55 +02:00

2.4 KiB

Custody — eng-coulomb-railiance01-ho-001

Decision

The engagement record and vault are owned by the coulomb client and classified client_confidential. Their present location in kaizen-agentic is transitional supplier custody, not supplier ownership.

The selected receiving authority is:

repository: railiance-infra
path: docs/evidence/resource-hosteurope-railiance01/engagements/
      eng-coulomb-railiance01-ho-001/

railiance-infra is the canonical S1 owner for Railiance01 inventory, hardening, access, and host-operational evidence, and already maintains the resource-hosteurope-railiance01 evidence interface. reef-railiance is not the target: it owns grouped reef identity, topology, and bindings, not detailed host-operation records.

Current data classes

Tree Classification Intended custody
ENGAGEMENT.yaml, request, schedule, bound definition client operational record receiving repo
vault/, reports, checklists, access plan client confidential receiving repo
engagement-local .kaizen/metrics/ client execution evidence receiving repo
commercial/ client settlement metadata receiving repo or financial authority
reusable role craft under roles/host-operator/ supplier craft remains in kaizen-agentic

The committed access plan contains operational routing and host identity, but no credential value. Secrets, private keys, tokens, and passwords must never be added to this tree or to a transfer package.

Transfer gate

The supplier copy remains the source of truth until all of these are true:

  1. The receiving repository accepts the path and confidentiality policy.
  2. The complete engagement tree is copied with history or an attributable import commit, and the receiver validates its manifest.
  3. The receiver records the accepted commit and acceptance date in vault/handoff/custody-transfer.yaml.
  4. Scheduled execution and access references are changed to the receiving path.
  5. Only then may this supplier copy be reduced to a non-confidential pointer or removed in a separately reviewed, recoverable change.

Until acceptance, do not add new sensitive operational evidence here unless it is necessary to maintain the active engagement. Do not claim that a handoff pack created inside this repository has itself transferred custody.