ops-warden/workplans/WARDEN-WP-0029-policy-front-door-and-founder-surface.md
tegwick cb762e06cb
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
WARDEN-WP-0029: hub workstream/task id write-back
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-18 16:40:16 +02:00

144 lines
5.3 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

---
id: WARDEN-WP-0029
type: workplan
title: "Policy front door: posture-aware access planning + founder interaction surface"
domain: infotech
repo: ops-warden
status: active
owner: codex
topic_slug: custodian
planning_priority: high
planning_order: 29
created: "2026-07-18"
state_hub_workstream_id: "6e396e7e-99c5-43aa-98a0-27f157de12a3"
---
# WARDEN-WP-0029 — Policy front door + founder interaction surface
## Origin
Founder directive 2026-07-18 (binky-control cutover prep): agents proposed
raw credential mechanics to the founder ("attach the deploy key in the
forgejo UI", "save the PAT to /tmp/...") although a catalogued lane
(`forgejo-admin-api-token`, WARDEN-WP-0025) already covered the need — the
installed CLI's catalog was stale, and nothing forced the ask-warden-first
step. Directive: **ops-warden is the service to ask what can and needs to be
done** per NetKingdom policy; the founder is bothered only when policy makes
it absolutely necessary, and then preferably via a purpose-built interaction
surface, not CLI/file handoffs. The organization is in **build phase** and
ops-warden must know that posture. INTENT.md principles 7 and 8 (added with
this workplan) capture the direction.
## Goal
1. `warden plan "<need>"` — a policy decision front door: given a need, answer
*autonomous / founder-act-required / unroutable*, with the exact commands
or the exact founder act, posture-stated.
2. Declared **organization posture** (`build`) that answers and scorecards
reference.
3. A **founder interaction surface**: local web page for the rare founder
acts (approve, OIDC-login prompt, paste-once secret capture straight into
OpenBao) — no values through CLI history or files.
4. Catalog freshness + agent guidance so ask-warden-first is the enforced
default.
## Tasks
### T01 — `warden plan` decision front door
```task
id: WARDEN-WP-0029-T01
status: todo
priority: high
state_hub_task_id: "32e4a755-fb74-4979-920f-32d44888df9d"
```
New command: `warden plan "<need>" [--actor agt-...] [--domain ...]`.
Resolves the routing catalog + posture + policy gates and returns a typed
verdict: `autonomous` (with the exec-capable command sequence),
`founder_required` (with the minimal founder act, e.g. "OIDC login role X" or
"Red-lane approval Y"), or `unroutable` (with a CCR proposal stub). JSON
output for agents. Every plan call audited (metadata only).
### T02 — Declared organization posture (build phase)
```task
id: WARDEN-WP-0029-T02
status: todo
priority: high
state_hub_task_id: "73ae528c-384d-43dd-a62a-455a32ec1ea5"
```
Add `organization_posture: build` to the posture/registry configuration
(alongside env posture dev/test/prod and workload maturity M0M3), with the
build-phase policy relaxations spelled out (workstation OIDC acceptable,
per-repo deploy keys, advisory flex-auth) and the graduation triggers (first
customer data, first non-founder operator, prod tier). `warden plan` and
scorecard must state the posture in their output.
### T03 — Founder interaction surface (local web approval page)
```task
id: WARDEN-WP-0029-T03
status: todo
priority: medium
state_hub_task_id: "2ea768b7-d756-4c45-ac65-1670e069fafb"
```
`warden desk` (working name): serves a localhost, short-lived page when a
plan needs a founder act — renders the exact action in plain language
(approve/deny, launch OIDC login, or paste-once secret capture that writes
straight to the OpenBao path and never echoes). No values in terminal
scrollback, shell history, or files. Metadata-only audit per interaction.
Build-phase scope: localhost only, no auth beyond OS session; hardening
graduates with posture.
### T04 — Retire file-drop patterns from playbooks
```task
id: WARDEN-WP-0029-T04
status: todo
priority: medium
state_hub_task_id: "61d25118-14ec-4846-8d53-3e09d437cac3"
```
Sweep wiki/playbooks (starting with
`forgejo-admin-api-token.md` `/tmp/forgejo-tegwick-api-token` steady-state
remnants) and replace file drops with `warden access --exec` / `--fetch`
lanes or T03 paste-once capture. Update the two live consumers:
railiance-platform `forgejo_package_prune` docs and binky-control cutover
runbook.
### T05 — Catalog freshness + agent guidance
```task
id: WARDEN-WP-0029-T05
status: todo
priority: medium
state_hub_task_id: "2121d102-806a-424a-8b62-bd25d7a9324e"
```
The stale-CLI failure mode: `warden` resolved an old catalog and hid an
existing lane. Add a catalog version/freshness check (warn when installed
catalog is older than repo/registry head; `warden route list` shows catalog
date) and update AGENTS/CLAUDE guidance in ops-warden + consuming repos:
agents must run `warden plan` before ever drafting a founder credential
step.
## Acceptance
- `warden plan "forgejo deploy key for binky-control"` returns `autonomous`
with the admin-lane command sequence; `warden plan` for a new tenant
secret returns `founder_required` with exactly one founder act.
- Posture `build` visible in plan output and scorecard.
- One real founder act completed through the web surface with zero secret
values in CLI/files.
- No playbook instructs a founder file drop.
## See also
- INTENT.md §7 (founder escalated, never tasked) and §8 (build-phase posture)
- WARDEN-WP-0025 (forgejo admin token lane), WARDEN-WP-0026/0027 (disclosure
hygiene, governance lockdown)
- binky-control DEC-2026-003 (first consumer: cutover without founder
mechanics)