ops-warden/workplans
tegwick fd08950231
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Align INTENT and SCOPE to layer model v0.7; assess gaps; open WARDEN-WP-0034
The standard is accepted at v0.7, with SECURITY-COMPANION.md v0.2 as its
operative form. Four ops-warden findings were adopted between v0.4 and v0.7 —
§9.1's two marks, §5's Tooling scope rule, §6.4 obligation 1's second limb, and
§13.1's existence — and both ops-warden declaration artifacts are now cited in
the text as the estate's reference forms.

INTENT.md gains frontmatter (layer: Staff, pep_shaped: true) because §11 requires
a machine-readable declaration and prose cannot distinguish a declaration from a
transcribed review. The note now covers the agent principal (§3.4), the PEP
shape, the attributive evidence position, and the role the companion assigns:
the estate is told to ask ops-warden which lane, which credential, which route.

SCOPE.md records what is actually shipped against v0.7 and the honest conformance
state — declared gap, which is tracked non-conformance, not conformance.

The assessment checked every obligation against shipped code rather than intent.
Three gaps survive:

- §9.7.2 requires a PEP to state one revocation visibility deadline. Ours is
  unstated, and the honest value is uncomfortable: the cert TTL, up to 48h. A
  cert outlives revocation of the decision that authorized it — no CRL, no KRL
  distribution. That is a design property never written down, which is exactly
  what §9.7.2 exists to force into the open.
- §3.4 rule 1 forbids standing credentials and requires issued, attributable
  authority. ADR-0004's boundary keys on WARDEN_AGENT_ID, which an agent sets
  about itself. key-cape now issues a real coding-agent identity, so the
  ops-warden half can stop being advisory.
- §9.6 cadence remains undeclared. Attributive, so SHOULD not MUST, but silence
  through two reviews is the one outcome that is not defensible.

WARDEN-WP-0034 addresses all three, plus the discoverability gap the companion
creates and two items to route rather than absorb.

402 tests pass, ruff clean.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YWBMovyFoy9RRrfL7zKvPJ

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 4014535@bnt-lap001
Assistant-Session: d0036016-73e8-4da1-8e47-563e3ab39a3c
2026-08-29 14:50:55 +02:00
..
archived chore(registrar): assign State Hub identifiers 2026-08-28 21:52:03 +02:00
ADHOC-2026-06-27.md chore(registrar): assign State Hub identifiers 2026-08-28 21:52:03 +02:00
ADHOC-2026-06-29.md chore(registrar): assign State Hub identifiers 2026-08-28 21:52:03 +02:00
ADHOC-2026-08-11.md chore(registrar): assign State Hub identifiers 2026-08-28 21:52:03 +02:00
ADHOC-2026-08-17.md chore(registrar): assign State Hub identifiers 2026-08-28 21:52:03 +02:00
WARDEN-WP-0016-ops-bridge-tunnel-cert-pilot.md feat(WARDEN-WP-0016): ops-bridge cert_command readiness gate + handoff 2026-06-27 19:50:28 +02:00
WARDEN-WP-0017-access-front-door-discoverability.md feat(WARDEN-WP-0018): activate whynot-design npm publish lane + resolvable flag 2026-06-29 00:32:00 +02:00
WARDEN-WP-0018-whynot-design-npm-lane-activation.md chore(WARDEN-WP-0018): stamp state_hub task ids from consistency sync 2026-06-29 00:36:35 +02:00
WARDEN-WP-0019-route-to-secrets-engine.md chore(WARDEN-WP-0019): stamp state_hub ids from consistency sync 2026-06-29 17:43:44 +02:00
WARDEN-WP-0020-ops-warden-worker.md feat(WARDEN-WP-0020): T4 scheduling tick + T5 SCOPE — worker complete 2026-06-30 00:41:04 +02:00
WARDEN-WP-0021-enable-scheduled-worker-tick.md feat(WARDEN-WP-0021): T3-T5 — visibility, approve loop, runbook (scheduled worker complete) 2026-06-30 15:24:10 +02:00
WARDEN-WP-0022-audit-trail-and-activity.md Implement WP-0022 audit trail and WP-0023 INTENT–SCOPE closeout 2026-07-01 23:32:38 +02:00
WARDEN-WP-0023-intent-scope-alignment-closeout.md Implement WP-0022 audit trail and WP-0023 INTENT–SCOPE closeout 2026-07-01 23:32:38 +02:00
WARDEN-WP-0024-experiential-memory-and-agent-sessions.md Implement WARDEN-WP-0024 experiential memory and agent sessions. 2026-07-02 23:40:45 +02:00
WARDEN-WP-0025-forgejo-admin-api-token-lane.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:16:12 +02:00
WARDEN-WP-0026-credential-disclosure-hygiene.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:16:12 +02:00
WARDEN-WP-0027-credential-governance-lockdown.md WARDEN-WP-0027-T02: the owner gate closed five days ago 2026-08-28 22:01:47 +02:00
WARDEN-WP-0028-tenant-secret-custody.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:16:12 +02:00
WARDEN-WP-0029-policy-front-door-and-founder-surface.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:16:12 +02:00
WARDEN-WP-0030-delegation-register.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:16:12 +02:00
WARDEN-WP-0031-policy-caller-identity.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:16:12 +02:00
WARDEN-WP-0032-security-zones.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:16:12 +02:00
WARDEN-WP-0033-native-lane-handoff.md WARDEN-WP-0033 finished — key-cape accepted the issuance question five days ago 2026-08-28 22:00:09 +02:00
WARDEN-WP-0034-layer-model-v07-conformance.md Align INTENT and SCOPE to layer model v0.7; assess gaps; open WARDEN-WP-0034 2026-08-29 14:50:55 +02:00