ops-warden/history
tegwick fd08950231
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Align INTENT and SCOPE to layer model v0.7; assess gaps; open WARDEN-WP-0034
The standard is accepted at v0.7, with SECURITY-COMPANION.md v0.2 as its
operative form. Four ops-warden findings were adopted between v0.4 and v0.7 —
§9.1's two marks, §5's Tooling scope rule, §6.4 obligation 1's second limb, and
§13.1's existence — and both ops-warden declaration artifacts are now cited in
the text as the estate's reference forms.

INTENT.md gains frontmatter (layer: Staff, pep_shaped: true) because §11 requires
a machine-readable declaration and prose cannot distinguish a declaration from a
transcribed review. The note now covers the agent principal (§3.4), the PEP
shape, the attributive evidence position, and the role the companion assigns:
the estate is told to ask ops-warden which lane, which credential, which route.

SCOPE.md records what is actually shipped against v0.7 and the honest conformance
state — declared gap, which is tracked non-conformance, not conformance.

The assessment checked every obligation against shipped code rather than intent.
Three gaps survive:

- §9.7.2 requires a PEP to state one revocation visibility deadline. Ours is
  unstated, and the honest value is uncomfortable: the cert TTL, up to 48h. A
  cert outlives revocation of the decision that authorized it — no CRL, no KRL
  distribution. That is a design property never written down, which is exactly
  what §9.7.2 exists to force into the open.
- §3.4 rule 1 forbids standing credentials and requires issued, attributable
  authority. ADR-0004's boundary keys on WARDEN_AGENT_ID, which an agent sets
  about itself. key-cape now issues a real coding-agent identity, so the
  ops-warden half can stop being advisory.
- §9.6 cadence remains undeclared. Attributive, so SHOULD not MUST, but silence
  through two reviews is the one outcome that is not defensible.

WARDEN-WP-0034 addresses all three, plus the discoverability gap the companion
creates and two items to route rather than absorb.

402 tests pass, ruff clean.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YWBMovyFoy9RRrfL7zKvPJ

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 4014535@bnt-lap001
Assistant-Session: d0036016-73e8-4da1-8e47-563e3ab39a3c
2026-08-29 14:50:55 +02:00
..
2026-06-17-intent-scope-assessment.md Define INTENT, refresh SCOPE, and plan NetKingdom stewardship 2026-06-17 08:20:32 +02:00
2026-06-17-intent-scope-reassessment.md WARDEN-WP-0006: NetKingdom stewardship docs and alignment 2026-06-17 08:22:45 +02:00
2026-06-17-openbao-production-verify.md chore(WP-0008): finish and archive production SSH path closeout 2026-06-18 01:28:49 +02:00
2026-06-17-post-wp0007-reassessment.md chore(WP-0008): finish and archive production SSH path closeout 2026-06-18 01:28:49 +02:00
2026-06-18-access-routing-intent-shift-assessment.md docs(WP-0010): rewire INTENT to "issue SSH, route the rest"; add access-routing plan 2026-06-18 20:07:01 +02:00
2026-06-18-post-wp0008-intent-scope-reassessment.md docs: post-WP-0008 INTENT↔SCOPE reassessment and gap snapshot 2026-06-18 01:36:23 +02:00
2026-06-23-flex-auth-policy-gate-local-smoke.md feat: close WP-0009/WP-0013 production integration stewardship strand 2026-06-24 12:44:32 +02:00
2026-06-23-flex-auth-policy-gate-production-smoke.md feat: close WP-0009/WP-0013 production integration stewardship strand 2026-06-24 12:44:32 +02:00
2026-06-23-flex-auth-production-pickup-suggestion.md feat: close WP-0009/WP-0013 production integration stewardship strand 2026-06-24 12:44:32 +02:00
2026-06-24-intent-scope-gap-analysis.md feat: close WP-0009/WP-0013 production integration stewardship strand 2026-06-24 12:44:32 +02:00
2026-06-24-ops-bridge-cert-command-pilot-coordination.md feat: close WP-0009/WP-0013 production integration stewardship strand 2026-06-24 12:44:32 +02:00
2026-06-27-operator-access-assist-charter.md docs(WARDEN-WP-0014): T5 — assist-layer docs, security model, INTENT/SCOPE 2026-06-27 17:35:57 +02:00
2026-06-27-workload-security-posture-charter.md Clarify workload secret posture stewardship 2026-06-27 18:22:09 +02:00
2026-07-01-intent-scope-gap-analysis.md Add July INTENT↔SCOPE gap analysis and WARDEN-WP-0023 alignment closeout 2026-07-01 23:27:14 +02:00
2026-07-16-credential-disclosure-lessons.md WARDEN-WP-0026 T01: capabilities-safe lane verification + incident note 2026-07-16 14:26:05 +02:00
2026-08-11-delegation-surface-assessment.md Classify 5 proxy lanes interim; hold 6 pending secrets-engine 2026-08-12 01:33:29 +02:00
2026-08-19-flex-auth-caller-identity-evidence.md Retire CoulombCore references; correct the 16443 diagnosis 2026-08-19 19:31:41 +02:00
2026-08-28-security-layer-model-assent.md Assent to the NetKingdom security layer model (WARDEN-IN-0001) 2026-08-28 21:47:44 +02:00
2026-08-29-layer-model-v04-review.md Review layer model v0.4; correct an unsound audit claim it exposes 2026-08-29 02:46:50 +02:00
2026-08-29-layer-model-v06-review.md Review layer model v0.6; publish the PEP stance map §6.4 requires 2026-08-29 10:20:49 +02:00
2026-08-29-v07-scope-intent-assessment.md Align INTENT and SCOPE to layer model v0.7; assess gaps; open WARDEN-WP-0034 2026-08-29 14:50:55 +02:00