ops-warden/workplans
tegwick 5b1a508610
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
docs: mark the unknown cell, measure the coverage we asked to publish
gate-house ruled the v0.8 assent round (GH-DEC-2026-011, net-kingdom@64394e9):
ask 1 declined, ask 2 adopted.

Ask 1's refusal is accepted without reservation and the reason is better than
the ask -- a sanctioned transitional fail_open is indistinguishable at runtime
from the stance the rule forbids, and would make the rule optional at the only
moment it costs anything.

Ask 2 gave §13.1 a Coverage column with this repo's figures as its first
entries. Since we asked for the column, we owe it accuracy:
scripts/report_coverage.py measures both populations from the artifacts the
runtime uses (reusing the workload-join build rather than re-deriving it), and
a test asserts pep-stance.yaml's published block equals what it measures.
A hand-counted number in a register that explicitly does not recompute it
decays silently, and a stale figure beside a marked cell is worse than the
blank the other four rows carry.

pep-stance.yaml marks the unknown cell inline as a declared gap -- assent, the
measured reason for not flipping, the declined ask, WARDEN-WP-0040 as route --
and a second test keeps it marked while it is fail_open, failing when it is
flipped. standard_version stays 0.7 because that is what binds; v0.8 is
proposed, so it gains standard_version_reviewed rather than pre-adopting.

Separately, gate-house corrected GH-DEC-2026-008: the claim/decision digest
comparison it originally required is unimplementable and a fail-closed
consumer obeying it would have denied permanently. We had never copied the
wording, so nothing to unwind -- but everything they have sent about this lane
was living in an inbox thread, a bad home for a correction that only matters
when someone finally wires the consume. Now wiki/ApprovalConsumption.md,
leading with "nothing is wired", carrying the corrected target and the
attribution gap that digest matching does not discharge.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013EPuTc18FjU5WFqoSEKH3C

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1276224@bnt-lap001
Assistant-Session: 426ec497-e1c4-4dd3-b417-dfce1ca1dbc3
2026-09-10 08:02:10 +02:00
..
archived repo.work.assign_missing_identifiers 2026-09-01 00:51:59 +02:00
ADHOC-2026-06-27.md repo.work.assign_missing_identifiers 2026-09-01 00:51:59 +02:00
ADHOC-2026-06-29.md repo.work.assign_missing_identifiers 2026-09-01 00:51:59 +02:00
ADHOC-2026-08-11.md repo.work.assign_missing_identifiers 2026-09-01 00:51:59 +02:00
ADHOC-2026-08-17.md repo.work.assign_missing_identifiers 2026-09-01 00:51:59 +02:00
ADHOC-2026-09-08.md chore: record hub ids for 2026-09-08 workplans 2026-09-08 14:57:42 +02:00
WARDEN-WP-0016-ops-bridge-tunnel-cert-pilot.md feat(WARDEN-WP-0016): ops-bridge cert_command readiness gate + handoff 2026-06-27 19:50:28 +02:00
WARDEN-WP-0017-access-front-door-discoverability.md feat(WARDEN-WP-0018): activate whynot-design npm publish lane + resolvable flag 2026-06-29 00:32:00 +02:00
WARDEN-WP-0018-whynot-design-npm-lane-activation.md chore(WARDEN-WP-0018): stamp state_hub task ids from consistency sync 2026-06-29 00:36:35 +02:00
WARDEN-WP-0019-route-to-secrets-engine.md chore(WARDEN-WP-0019): stamp state_hub ids from consistency sync 2026-06-29 17:43:44 +02:00
WARDEN-WP-0020-ops-warden-worker.md feat(WARDEN-WP-0020): T4 scheduling tick + T5 SCOPE — worker complete 2026-06-30 00:41:04 +02:00
WARDEN-WP-0021-enable-scheduled-worker-tick.md feat(WARDEN-WP-0021): T3-T5 — visibility, approve loop, runbook (scheduled worker complete) 2026-06-30 15:24:10 +02:00
WARDEN-WP-0022-audit-trail-and-activity.md Implement WP-0022 audit trail and WP-0023 INTENT–SCOPE closeout 2026-07-01 23:32:38 +02:00
WARDEN-WP-0023-intent-scope-alignment-closeout.md Implement WP-0022 audit trail and WP-0023 INTENT–SCOPE closeout 2026-07-01 23:32:38 +02:00
WARDEN-WP-0024-experiential-memory-and-agent-sessions.md Implement WARDEN-WP-0024 experiential memory and agent sessions. 2026-07-02 23:40:45 +02:00
WARDEN-WP-0025-forgejo-admin-api-token-lane.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:16:12 +02:00
WARDEN-WP-0026-credential-disclosure-hygiene.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:16:12 +02:00
WARDEN-WP-0027-credential-governance-lockdown.md WARDEN-WP-0027-T02: the owner gate closed five days ago 2026-08-28 22:01:47 +02:00
WARDEN-WP-0028-tenant-secret-custody.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:16:12 +02:00
WARDEN-WP-0029-policy-front-door-and-founder-surface.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:16:12 +02:00
WARDEN-WP-0030-delegation-register.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:16:12 +02:00
WARDEN-WP-0031-policy-caller-identity.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:16:12 +02:00
WARDEN-WP-0032-security-zones.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:16:12 +02:00
WARDEN-WP-0033-native-lane-handoff.md WARDEN-WP-0033 finished — key-cape accepted the issuance question five days ago 2026-08-28 22:00:09 +02:00
WARDEN-WP-0034-layer-model-v07-conformance.md docs: record the answers received and the questions routed 2026-09-09 16:40:46 +02:00
WARDEN-WP-0035-policy-nexus-forgejo-source-read-route.md repo.work.assign_missing_identifiers 2026-09-01 00:51:59 +02:00
WARDEN-WP-0036-attended-login-openbao-output.md repo.work.assign_missing_identifiers 2026-09-01 00:51:59 +02:00
WARDEN-WP-0037-whynot-design-forgejo-npm-lane.md docs: record the answers received and the questions routed 2026-09-09 16:40:46 +02:00
WARDEN-WP-0038-plan-mutation-intent.md feat: refuse to answer a write with a read (WARDEN-WP-0038) 2026-09-10 08:02:10 +02:00
WARDEN-WP-0039-explicit-policy-refusal.md docs: record the answers received and the questions routed 2026-09-09 16:40:46 +02:00
WARDEN-WP-0040-unknown-zone-fail-closed-adoption.md docs: mark the unknown cell, measure the coverage we asked to publish 2026-09-10 08:02:10 +02:00