warden route find "state hub read private repository" returned nothing, which is why the need had to be reasoned out from first principles instead of looked up. Pointer-only (warden_executes: false): ops-mason builds the AppRole, policy, and KV path under MASON-WP-0003; the forge owner mints the value; paste_once_provision delivers it. ops-warden routes and executes nothing. Graded high on breadth, not on write authority — the token is read-only but organisation-wide, so a leak reads every private repository. Approved at that breadth 2026-08-26 (ops-mason plan §6). status: draft until MASON-WP-0003-T02 has created the structure and the negative capability check passes. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: opus Assistant-Process: 3377672@bnt-lap001 Assistant-Session: 15463ccf-238f-4e13-b163-93aa25c6d166 |
||
|---|---|---|
| .. | ||
| playbooks | ||
| AccessManagementDirective.md | ||
| AccessRouting.md | ||
| ActorInventoryPatterns.md | ||
| AuditTrail.md | ||
| CertCommandInterface.md | ||
| CredentialRouting.md | ||
| InterHubBootstrapAccessLane.md | ||
| NetKingdomSecurityMap.md | ||
| OpenBaoSshEngineChecklist.md | ||
| OperatorAccessAssist.md | ||
| OpsWardenConfig.md | ||
| OpsWardenMemory.md | ||
| PolicyGatedSigning.md | ||
| WorkloadSecurityPosture.md | ||