# audit-core sender registry ## Worker checklist This file is a pointer only. ops-warden does not issue sender tokens and does not duplicate the operating procedure. - Construction plan: `ops-mason/plans/audit-core-openbao-runtime-custody.md` - Package and operator runbook: `audit-core/docs/operator-runbook.md` - Database leases (separate lane): `warden route show database-dynamic-credentials` - Authoritative senders shape: `audit-core/docs/senders.example.json` (placeholders only) First deploy mints sender tokens in-cluster into Secret `audit-core/audit-core-senders`. The OpenBao path `platform/workloads/audit-core/senders` is the later authority, filled by a Mason wrap-migrate — not by a founder `bao kv put`. Never place a sender token, bearer, or `senders.json` value in Git, State Hub, logs, or chat.