# Current platform work Reviewed 2026-09-05. Six open workplans: five blocked on explicit owner/live gates and one ready for local work. Completed designs and implementations are under `archived/`; their IDs and UUIDs are preserved. The number of blocked plans is not a count of missing implementations or independent incidents. | Workplan | Purpose and next gate | S3 boundary | | --- | --- | --- | | [RPF-WP-0027](RPF-WP-0027-keycape-live-secret-exposure-recovery.md) | Incident custody and final evidence; accept NetKingdom's residual disposition and publish exact custody handoff | The bundle was already rotated. Provider/MFA reconciliation belongs to NetKingdom. | | [RPF-WP-0029](RPF-WP-0029-backup-credential-default-removal.md) | Backup credential exposure; attended provider invalidation and replacement recovery receipts | S3 retains custody acceptance; S1 and forge own their backup execution. | | [RPF-WP-0025](RPF-WP-0025-openbao-operator-only-access.md) | Private OpenBao access; fresh attended callback/login then guarded retraction | Coordinate package, issuer, tunnel and DNS owners; keep the window separate. | | [RPF-WP-0015](RPF-WP-0015-audit-core-custody-and-recovery-coordination.md) | Two prepared recovery exercises; fresh synthetic-load/outage approvals and custody readiness | S3 contributes lease/ESO and snapshot/unseal proof; S1/S2 and audit-core execute their parts. | | [RPF-WP-0035](RPF-WP-0035-credential-lane-implementation.md) | One implementation queue for secrets-engine JWT, Fluid operator KV and preflight signing | Three independent task gates; no new approval inherited from the completed designs. | | [RPF-WP-0036](RPF-WP-0036-platform-service-assurance.md) | **Ready:** service guarantees, recurring evidence, S3 emission, admission consistency, ownership handoff and demand review | Local design/checking can progress while live work waits. | Start with RPF-WP-0036-T02/T05 for work that does not require a live credential or outage. Treat credential exposure closure as the highest-priority attended work; task order does not combine or waive approvals. [Assessment and disposition of every plan](../history/2026-09-05-platform-intent-workplan-assessment.md) and [generated current record index](../WORK-RECORDS.md). Do not recreate completed workplans because an old Hub alias or generated brief still shows them active. Use source IDs, and follow AGENTS.md for verified sync.