chore(registrar): assign State Hub identifiers
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

This commit is contained in:
repo-manager 2026-08-21 21:39:10 +02:00
parent f106ee941c
commit c54de0f3d0
3 changed files with 16 additions and 0 deletions

View file

@ -14,6 +14,7 @@ related:
- RISK-F-0009
origin: routed
origin_ref: "State Hub message 828e4903-30fe-4903-acfd-cd2ecdda437d"
state_hub_workstream_id: "b4701216-b235-48d1-a527-b52b8fb7e6fc"
---
# RAILIANCE-WP-0022 — Agent high-risk boundary coverage
@ -39,6 +40,7 @@ establish whether any agent identity actually carries the boundary.
id: RAILIANCE-WP-0022-T01
status: done
priority: high
state_hub_task_id: "44d1a4bf-70bb-4d50-a40a-2158acc96b36"
```
Run the capabilities-only ops-warden audit against the policy. The 2026-08-21
@ -51,6 +53,7 @@ and five without a concrete KV address. No credential value was read.
id: RAILIANCE-WP-0022-T02
status: done
priority: high
state_hub_task_id: "97c73849-716f-45d7-878f-5e1811a594ff"
```
Add deny-data/read-metadata pairs for the six catalog paths: whynot-design npm,
@ -68,6 +71,7 @@ catalog audit reports all 12 catalog entries covered with none uncovered.
id: RAILIANCE-WP-0022-T03
status: done
priority: high
state_hub_task_id: "9a293b09-dc0c-4575-bdc1-05102fb218a8"
```
Under attended platform authority, upload the reviewed policy, read it back,
@ -89,6 +93,7 @@ it with a workload-read policy. No token was minted and no Secret was read.
id: RAILIANCE-WP-0022-T04
status: done
priority: medium
state_hub_task_id: "64ddfacf-b3f2-428e-9630-4b9f436f627f"
```
Reply to ops-warden with the deployment evidence and remaining attachment
@ -106,6 +111,7 @@ versioned generated artifact shape.
id: RAILIANCE-WP-0022-T05
status: wait
priority: high
state_hub_task_id: "47aa5ed9-95c5-4a23-a460-e4bbd3ed6f65"
```
The policy is live but no role attaches it. Do not add the boundary to