chore(consistency): renormalize lifecycle state [auto]

Updated by fix-consistency on 2026-07-16:
  - workplan status: backlog → active
This commit is contained in:
custodian-sync 2026-07-16 14:26:36 +02:00
parent 03ffa27b08
commit fb4251bab6

View file

@ -4,13 +4,14 @@ type: workplan
title: "Tamper-resistant credential governance + mass rotation/lockdown (Strand B)"
domain: infotech
repo: ops-warden
status: backlog
status: active
owner: codex
topic_slug: custodian
planning_priority: medium
planning_order: 27
created: "2026-07-16"
updated: "2026-07-16"
state_hub_workstream_id: "7d697c52-766a-4562-b2ad-a722880bcdcb"
---
# Tamper-resistant credential governance + mass rotation/lockdown (Strand B)
@ -61,6 +62,7 @@ path; ops-warden sequences and verifies it.
id: WARDEN-WP-0027-T01
status: wait
priority: high
state_hub_task_id: "604aad14-d398-4c02-85e5-7ff37a905a1b"
```
Turn Strand A's per-lane `rotation:` guidance (WP-0026 T06) into an executable
@ -81,6 +83,7 @@ each verified capabilities-safe, taint cleared only on success.
id: WARDEN-WP-0027-T02
status: wait
priority: medium
state_hub_task_id: "9d004d8f-6215-4178-bd13-5785d24fd152"
```
Design and document a graded lockdown: (a) soft — deny agent roles read on all
@ -99,6 +102,7 @@ policy toggles.
id: WARDEN-WP-0027-T03
status: wait
priority: medium
state_hub_task_id: "94d5dcaf-abf0-417c-a6ef-26e8c50905a8"
```
Policy-as-code for OpenBao policies/roles with tamper-evidence: a signed/hashed