ops-warden/workplans
tegwick f787e09a1b plan(WARDEN-WP-0015): rescope to two-axis Workload Security Posture
Folds the workload-maturity axis into WP-0015. The model is now two
orthogonal axes — environment posture (dev/test/prod, how the secret
store is secured) and workload maturity (M0-M3, how trusted a workload
is to receive secrets/classified data) — unified by a secret-flow
lattice (deliver only if posture==prod AND workload.maturity >=
secret.required_maturity). "Critical secrets must not flow to workloads
below maturity M" is the no-write-down case.

Layering: generic WorkloadMaturityLevel + lattice → info-tech-canon
(reusing its DataClassification / DevSecOps gates / Security criticality
/ CARING); NetKingdom M0-M3 requirements → net-kingdom canon. ops-warden
authors + checks conformance, not enforcement. Still proposed.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-27 18:00:50 +02:00
..
archived feat: close WP-0009/WP-0013 production integration stewardship strand 2026-06-24 12:44:32 +02:00
WARDEN-WP-0012-routing-scenario-playbooks.md Complete WARDEN-WP-0012 routing scenario playbooks 2026-06-25 10:27:23 +02:00
WARDEN-WP-0014-operator-access-assist.md docs(WARDEN-WP-0014): T5 — assist-layer docs, security model, INTENT/SCOPE 2026-06-27 17:35:57 +02:00
WARDEN-WP-0015-secret-lifecycle-tiering.md plan(WARDEN-WP-0015): rescope to two-axis Workload Security Posture 2026-06-27 18:00:50 +02:00