5.3 KiB
| id | type | title | domain | repo | status | owner | topic_slug | planning_priority | planning_order | created | state_hub_workstream_id |
|---|---|---|---|---|---|---|---|---|---|---|---|
| WARDEN-WP-0029 | workplan | Policy front door: posture-aware access planning + founder interaction surface | infotech | ops-warden | active | codex | custodian | high | 29 | 2026-07-18 | 6e396e7e-99c5-43aa-98a0-27f157de12a3 |
WARDEN-WP-0029 — Policy front door + founder interaction surface
Origin
Founder directive 2026-07-18 (binky-control cutover prep): agents proposed
raw credential mechanics to the founder ("attach the deploy key in the
forgejo UI", "save the PAT to /tmp/...") although a catalogued lane
(forgejo-admin-api-token, WARDEN-WP-0025) already covered the need — the
installed CLI's catalog was stale, and nothing forced the ask-warden-first
step. Directive: ops-warden is the service to ask what can and needs to be
done per NetKingdom policy; the founder is bothered only when policy makes
it absolutely necessary, and then preferably via a purpose-built interaction
surface, not CLI/file handoffs. The organization is in build phase and
ops-warden must know that posture. INTENT.md principles 7 and 8 (added with
this workplan) capture the direction.
Goal
warden plan "<need>"— a policy decision front door: given a need, answer autonomous / founder-act-required / unroutable, with the exact commands or the exact founder act, posture-stated.- Declared organization posture (
build) that answers and scorecards reference. - A founder interaction surface: local web page for the rare founder acts (approve, OIDC-login prompt, paste-once secret capture straight into OpenBao) — no values through CLI history or files.
- Catalog freshness + agent guidance so ask-warden-first is the enforced default.
Tasks
T01 — warden plan decision front door
id: WARDEN-WP-0029-T01
status: todo
priority: high
state_hub_task_id: "32e4a755-fb74-4979-920f-32d44888df9d"
New command: warden plan "<need>" [--actor agt-...] [--domain ...].
Resolves the routing catalog + posture + policy gates and returns a typed
verdict: autonomous (with the exec-capable command sequence),
founder_required (with the minimal founder act, e.g. "OIDC login role X" or
"Red-lane approval Y"), or unroutable (with a CCR proposal stub). JSON
output for agents. Every plan call audited (metadata only).
T02 — Declared organization posture (build phase)
id: WARDEN-WP-0029-T02
status: todo
priority: high
state_hub_task_id: "73ae528c-384d-43dd-a62a-455a32ec1ea5"
Add organization_posture: build to the posture/registry configuration
(alongside env posture dev/test/prod and workload maturity M0–M3), with the
build-phase policy relaxations spelled out (workstation OIDC acceptable,
per-repo deploy keys, advisory flex-auth) and the graduation triggers (first
customer data, first non-founder operator, prod tier). warden plan and
scorecard must state the posture in their output.
T03 — Founder interaction surface (local web approval page)
id: WARDEN-WP-0029-T03
status: todo
priority: medium
state_hub_task_id: "2ea768b7-d756-4c45-ac65-1670e069fafb"
warden desk (working name): serves a localhost, short-lived page when a
plan needs a founder act — renders the exact action in plain language
(approve/deny, launch OIDC login, or paste-once secret capture that writes
straight to the OpenBao path and never echoes). No values in terminal
scrollback, shell history, or files. Metadata-only audit per interaction.
Build-phase scope: localhost only, no auth beyond OS session; hardening
graduates with posture.
T04 — Retire file-drop patterns from playbooks
id: WARDEN-WP-0029-T04
status: todo
priority: medium
state_hub_task_id: "61d25118-14ec-4846-8d53-3e09d437cac3"
Sweep wiki/playbooks (starting with
forgejo-admin-api-token.md /tmp/forgejo-tegwick-api-token steady-state
remnants) and replace file drops with warden access --exec / --fetch
lanes or T03 paste-once capture. Update the two live consumers:
railiance-platform forgejo_package_prune docs and binky-control cutover
runbook.
T05 — Catalog freshness + agent guidance
id: WARDEN-WP-0029-T05
status: todo
priority: medium
state_hub_task_id: "2121d102-806a-424a-8b62-bd25d7a9324e"
The stale-CLI failure mode: warden resolved an old catalog and hid an
existing lane. Add a catalog version/freshness check (warn when installed
catalog is older than repo/registry head; warden route list shows catalog
date) and update AGENTS/CLAUDE guidance in ops-warden + consuming repos:
agents must run warden plan before ever drafting a founder credential
step.
Acceptance
warden plan "forgejo deploy key for binky-control"returnsautonomouswith the admin-lane command sequence;warden planfor a new tenant secret returnsfounder_requiredwith exactly one founder act.- Posture
buildvisible in plan output and scorecard. - One real founder act completed through the web surface with zero secret values in CLI/files.
- No playbook instructs a founder file drop.
See also
- INTENT.md §7 (founder escalated, never tasked) and §8 (build-phase posture)
- WARDEN-WP-0025 (forgejo admin token lane), WARDEN-WP-0026/0027 (disclosure hygiene, governance lockdown)
- binky-control DEC-2026-003 (first consumer: cutover without founder mechanics)