chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-09-04: - update .custodian-brief.md for rein-aharness Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a06ba0-10aa-7ea0-b20a-4f3fac39efe9
This commit is contained in:
parent
7641fcde40
commit
f01b765668
20 changed files with 1027 additions and 165 deletions
13
INTENT.md
13
INTENT.md
|
|
@ -46,10 +46,15 @@ place.**
|
|||
verifies the local commit, reports to the State Hub and to the
|
||||
instance's kaizen metrics.
|
||||
|
||||
The harness is the **only credential holder and the only policy
|
||||
enforcement point** for agent sessions. Instances declare policy; the
|
||||
harness enforces it. Instances pin a harness major version; upgrades
|
||||
happen centrally.
|
||||
Among tenant repositories, blueprints, and scheduling records, only the
|
||||
selected rein may receive session credential material, and it holds that
|
||||
material only for the bounded session (ADR-002). The harness is the
|
||||
**repository-transaction and rein-local tool-policy enforcement point**
|
||||
inside a chained grant — not the only credential holder or the only
|
||||
policy enforcement point in the estate. Queue, profile, sandbox,
|
||||
credential custody/authorization, and provider boundaries enforce their
|
||||
own grants; this runtime must not weaken them. Instances declare policy
|
||||
and pin a harness major version; upgrades happen centrally.
|
||||
|
||||
## Strategic role
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue