ops-warden/history
tegwick 94f32bd160
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Review layer model v0.6; publish the PEP stance map §6.4 requires
All three v0.4 findings were acted on — §9.1 split into pending/declared-gap and
§5's scope rule adopted as recommended and credited, and §9.6 ruled via the
load-bearing/attributive distinction with ops-warden's `# audit must not block
signing` named as the estate's live example.

Checked the favourable ruling rather than accepting it. §9.6's test is "no
control branches on its presence": the only consumer of audit.jsonl is `warden
activity`, which displays. Nothing gates on a signing record, so the lane is
genuinely attributive. AuditTrail.md now records the ruling instead of the open
question, and states that the trade must be revisited if a control ever gates on
the trail.

CONFORMANCE ACTION. §6.4 obligation 3 requires a stance map "published rather
than held in code", and requires every PEP-shaped consumer to publish one so the
maps can be inventoried — naming ADR-0009 as the reference shape. ops-warden was
not doing it: the map lived in PolicyConfig.failure_modes, a dataclass default.
Not a code comment, but not published either.

pep-stance.yaml publishes it, and the test asserts the published map EQUALS the
shipped default. A published map that may drift from the code is worse than no
map, because it invites reliance it cannot support.

Two findings sent to gate-house, in history/2026-08-29-layer-model-v06-review.md:
§6.4 obligation 1 (no side effect without a decision record) contradicts
obligation 3 and §9.3, with ops-warden's blessed fail-open stance as the
instance; and §6.4 mandates a stance-map inventory in §13 that §13 does not
implement — where ops-warden is currently the only PEP to have published one.

402 tests pass, ruff clean.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YWBMovyFoy9RRrfL7zKvPJ

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 4014535@bnt-lap001
Assistant-Session: d0036016-73e8-4da1-8e47-563e3ab39a3c
2026-08-29 10:20:49 +02:00
..
2026-06-17-intent-scope-assessment.md Define INTENT, refresh SCOPE, and plan NetKingdom stewardship 2026-06-17 08:20:32 +02:00
2026-06-17-intent-scope-reassessment.md WARDEN-WP-0006: NetKingdom stewardship docs and alignment 2026-06-17 08:22:45 +02:00
2026-06-17-openbao-production-verify.md chore(WP-0008): finish and archive production SSH path closeout 2026-06-18 01:28:49 +02:00
2026-06-17-post-wp0007-reassessment.md chore(WP-0008): finish and archive production SSH path closeout 2026-06-18 01:28:49 +02:00
2026-06-18-access-routing-intent-shift-assessment.md docs(WP-0010): rewire INTENT to "issue SSH, route the rest"; add access-routing plan 2026-06-18 20:07:01 +02:00
2026-06-18-post-wp0008-intent-scope-reassessment.md docs: post-WP-0008 INTENT↔SCOPE reassessment and gap snapshot 2026-06-18 01:36:23 +02:00
2026-06-23-flex-auth-policy-gate-local-smoke.md feat: close WP-0009/WP-0013 production integration stewardship strand 2026-06-24 12:44:32 +02:00
2026-06-23-flex-auth-policy-gate-production-smoke.md feat: close WP-0009/WP-0013 production integration stewardship strand 2026-06-24 12:44:32 +02:00
2026-06-23-flex-auth-production-pickup-suggestion.md feat: close WP-0009/WP-0013 production integration stewardship strand 2026-06-24 12:44:32 +02:00
2026-06-24-intent-scope-gap-analysis.md feat: close WP-0009/WP-0013 production integration stewardship strand 2026-06-24 12:44:32 +02:00
2026-06-24-ops-bridge-cert-command-pilot-coordination.md feat: close WP-0009/WP-0013 production integration stewardship strand 2026-06-24 12:44:32 +02:00
2026-06-27-operator-access-assist-charter.md docs(WARDEN-WP-0014): T5 — assist-layer docs, security model, INTENT/SCOPE 2026-06-27 17:35:57 +02:00
2026-06-27-workload-security-posture-charter.md Clarify workload secret posture stewardship 2026-06-27 18:22:09 +02:00
2026-07-01-intent-scope-gap-analysis.md Add July INTENT↔SCOPE gap analysis and WARDEN-WP-0023 alignment closeout 2026-07-01 23:27:14 +02:00
2026-07-16-credential-disclosure-lessons.md WARDEN-WP-0026 T01: capabilities-safe lane verification + incident note 2026-07-16 14:26:05 +02:00
2026-08-11-delegation-surface-assessment.md Classify 5 proxy lanes interim; hold 6 pending secrets-engine 2026-08-12 01:33:29 +02:00
2026-08-19-flex-auth-caller-identity-evidence.md Retire CoulombCore references; correct the 16443 diagnosis 2026-08-19 19:31:41 +02:00
2026-08-28-security-layer-model-assent.md Assent to the NetKingdom security layer model (WARDEN-IN-0001) 2026-08-28 21:47:44 +02:00
2026-08-29-layer-model-v04-review.md Review layer model v0.4; correct an unsound audit claim it exposes 2026-08-29 02:46:50 +02:00
2026-08-29-layer-model-v06-review.md Review layer model v0.6; publish the PEP stance map §6.4 requires 2026-08-29 10:20:49 +02:00