WARDEN-WP-0027: move Strand B to backlog
No activation gate met after WP-0026/0028 closeout. Keep capture only; promote to ready only when mass-rotate or policy-reconcile is justified.
This commit is contained in:
parent
59f0277f20
commit
6bfbf64108
1 changed files with 8 additions and 6 deletions
|
|
@ -4,13 +4,13 @@ type: workplan
|
||||||
title: "Tamper-resistant credential governance + mass rotation/lockdown (Strand B)"
|
title: "Tamper-resistant credential governance + mass rotation/lockdown (Strand B)"
|
||||||
domain: infotech
|
domain: infotech
|
||||||
repo: ops-warden
|
repo: ops-warden
|
||||||
status: active
|
status: backlog
|
||||||
owner: codex
|
owner: codex
|
||||||
topic_slug: custodian
|
topic_slug: custodian
|
||||||
planning_priority: medium
|
planning_priority: medium
|
||||||
planning_order: 27
|
planning_order: 27
|
||||||
created: "2026-07-16"
|
created: "2026-07-16"
|
||||||
updated: "2026-07-16"
|
updated: "2026-07-17"
|
||||||
state_hub_workstream_id: "7d697c52-766a-4562-b2ad-a722880bcdcb"
|
state_hub_workstream_id: "7d697c52-766a-4562-b2ad-a722880bcdcb"
|
||||||
---
|
---
|
||||||
|
|
||||||
|
|
@ -29,10 +29,12 @@ governance against silent drift or malicious change.
|
||||||
|
|
||||||
## Status: backlog (captured, not scheduled)
|
## Status: backlog (captured, not scheduled)
|
||||||
|
|
||||||
This is deliberately **not `ready`**. It carries real cost and blast radius
|
Frontmatter `status: backlog` as of 2026-07-17 (Strand A / WP-0026 and tenant
|
||||||
(break-glass re-key, trust-root design) that is not justified until Strand A is in
|
custody WP-0028 are finished; no activation gate has fired). This is
|
||||||
production and a concrete trigger appears. See **Activation gate** below. Nothing
|
deliberately **not `ready`**. It carries real cost and blast radius
|
||||||
here is implemented until the gate is met and Bernd promotes it to `ready`.
|
(break-glass re-key, trust-root design) that is not justified until a concrete
|
||||||
|
trigger appears. See **Activation gate** below. Nothing here is implemented
|
||||||
|
until the gate is met and Bernd promotes it to `ready`.
|
||||||
|
|
||||||
## Activation gate (promote to `ready` only when ≥1 holds)
|
## Activation gate (promote to `ready` only when ≥1 holds)
|
||||||
|
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue