Drop the "operational access desk" framing (and the rejected "coach" metaphor) for plain language: ops-warden issues short-lived SSH certs and routes every other credential need to its owner. SSH is the only lane it executes. Adds WARDEN-WP-0010/0011/0012 with a pointer-layer routing catalog that points at owner docs rather than restating them, enforced structurally (non-SSH entries carrying a steps block fail CI). Drops the scope-creep-prone `check` command; hides unshipped-path scenarios as draft. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| archived | ||
| WARDEN-WP-0009-flex-auth-policy-gate-production.md | ||
| WARDEN-WP-0010-access-routing-charter.md | ||
| WARDEN-WP-0011-routing-guide-cli.md | ||
| WARDEN-WP-0012-routing-scenario-playbooks.md | ||