Add WP-0030 delegation register; refresh INTENT and SCOPE
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s

Founder directive: ops-warden works with, never replaces or duplicates,
secrets-engine / tenant-engine / user-engine. Covering an unfilled gap is
acceptable only as a tracked interim with a named intended owner.

- INTENT §9 "Cover gaps, but never silently own them"; success criterion 7;
  tenant-engine and user-engine added to the literacy table; non-goal on
  permanently owning another component's lane
- WP-0030 (proposed): delegation: metadata, backfill, warden route gaps,
  promotion gate, publish the register to owner repos
- history/2026-08-11-delegation-surface-assessment.md: 2 of 24 lanes carry
  exec_owner; 11 proxies record no intended owner
- SCOPE refreshed to 2026-08-11 (was 6 workplans behind); completeness C5 -> C4

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
tegwick 2026-08-11 11:11:01 +02:00
parent 95ecfe51e2
commit 9d42dd5abd
6 changed files with 512 additions and 15 deletions

View file

@ -0,0 +1,87 @@
# Delegation surface assessment — 2026-08-11
**Trigger:** founder directive — ops-warden should work with, but never replace or
duplicate, secrets-engine, tenant-engine, user-engine and other NetKingdom
components. Covering an unfilled gap is acceptable if the gap stays visible, gets
filled with proper governance, and ops-warden then delegates.
**Method:** enumerate `registry/routing/catalog.yaml` by execution mode; check
`wiki/AccessRouting.md` and `wiki/playbooks/catalog-lane-promotion.md` for existing
interim/delegation doctrine; compare against SCOPE/INTENT claims.
---
## 1. Execution surface (24 catalog entries)
| Mode | Count | Entries |
| --- | --- | --- |
| `warden_executes: true` — ops-warden's own authority | 1 | `ssh-cert-host-access` |
| `exec_owner:` set — delegated, route-primary/proxy-fallback | 2 | `whynot-design-npm-publish` (secrets-engine), `ops-warden-warden-sign-token` (railiance-platform broker) |
| `exec_capable` proxy, **no** `exec_owner` | 11 | `openbao-api-key`, `key-cape-oidc-login`, `issue-core-ingestion-api-key`, `reuse-surface-hub-write-token`, `openrouter-llm-connect`, `railiance-backup-offsite-lane`, `forgejo-admin-api-token`, `binky-company-email-imap`, `binky-qonto-api`, `rapp-qonto-keycape-client`, `agent-harness-forgejo-deploy` |
| route-only pointer | 10 | remainder |
**Finding.** The delegation primitive exists, is proven in production, and is used by
**2 of 24** lanes. Eleven lanes have ops-warden as the de facto front door with no
record of who should own it instead.
## 2. The doctrine is not written down
- `wiki/AccessRouting.md` — the canonical "what ops-warden answers" page — contains
**no mention of secrets-engine** and no section on interim positions. A worker or
agent reading it cannot tell that `warden access` proxying a workload secret is a
stopgap rather than the design.
- `wiki/playbooks/catalog-lane-promotion.md` gates draft→active on the lane
*working* (zero placeholders, resolvable, tests green). It never asks whether
ops-warden should be the one executing it.
- The delegation intent for `whynot-design-npm-publish` lives in WP-0019 prose and
SCOPE; the *machine-readable* expression (`exec_owner`) was a by-product, not a
policy applied catalog-wide.
Consequence: an absorbed need is indistinguishable from a designed one. Ownership
drift is invisible by construction, which is exactly the failure mode the directive
targets.
## 3. Drafted classification of the eleven
Not authoritative — architecture judgement belongs to the founder (WP-0030 T02).
| Lane | Draft reading | Intended owner / blocker |
| --- | --- | --- |
| `key-cape-oidc-login` | **Permanent** | Login is key-cape's; the proxy is caller convenience, not custody |
| `openbao-api-key` | **Permanent (by design)** | Generic escape hatch for any OpenBao path; a catch-all, not a lane |
| `binky-company-email-imap` | Interim | **tenant-engine** — WP-0028 defined the tenant custody pattern; no tenant front door executes it |
| `binky-qonto-api` | Interim | **tenant-engine** — same |
| `rapp-qonto-keycape-client` | Interim | **tenant-engine** / key-cape — tenant workload client credential |
| `issue-core-ingestion-api-key` | Interim | **secrets-engine** — same shape WP-0019 closed for npm publish |
| `openrouter-llm-connect` | Interim | **secrets-engine** — high-risk provider key |
| `reuse-surface-hub-write-token` | Interim | **secrets-engine** |
| `railiance-backup-offsite-lane` | Interim | **secrets-engine** / railiance-platform |
| `forgejo-admin-api-token` | Interim | **secrets-engine** |
| `agent-harness-forgejo-deploy` | Interim | **secrets-engine** |
**No lane names `user-engine` as owner.** It appears only as a *consumer* inside
`coulomb-social-runtime-env` (route-only, owned by railiance-platform), whose rotation
guidance points at the OpenBao path `user-engine/user-engine-runtime` for
`USER_ENGINE_PROXY_SECRET`. So a user-engine runtime secret exists and is routed, but
user-engine fronts nothing itself. Whether it should own that lane is worth confirming
rather than assuming either way.
## 4. Secondary finding — SCOPE drift
`SCOPE.md` "Where we are" was dated **2026-07-01** and stated *"Active work: none
open in ops-warden after WP-0022/0023."* Six workplans have shipped since
(WP-00240026, WP-0028, WP-0029 finished; WP-0027 sits in `backlog`), adding
`warden plan`, `warden desk`, `warden taint`, `warden rotate-guide`, experiential
memory, the tenant custody pattern, and the build-phase organization posture axis.
SCOPE understated the repo by roughly six weeks of work. Corrected in this pass.
## 5. Recommendation
WARDEN-WP-0030 — record `delegation:` (mode / intended_owner / blocked_on) on every
entry, expose `warden route gaps`, gate promotion on the ownership question, and
publish the resulting interim register to the owner repos. Absence of a delegation
block should read as *interim, owner unknown* — a question — never as settled
ownership.
The measure of success is not fewer proxies. It is that no proxy exists without an
answer to *"who should own this front door, and what is missing?"*