chore(consistency): sync task status from DB [auto]

Updated by fix-consistency on 2026-09-04:
  - update .custodian-brief.md for rein-aharness

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a06ba0-10aa-7ea0-b20a-4f3fac39efe9
This commit is contained in:
custodian-sync 2026-09-04 11:00:20 +02:00
parent 7641fcde40
commit f01b765668
20 changed files with 1027 additions and 165 deletions

View file

@ -46,10 +46,15 @@ place.**
verifies the local commit, reports to the State Hub and to the
instance's kaizen metrics.
The harness is the **only credential holder and the only policy
enforcement point** for agent sessions. Instances declare policy; the
harness enforces it. Instances pin a harness major version; upgrades
happen centrally.
Among tenant repositories, blueprints, and scheduling records, only the
selected rein may receive session credential material, and it holds that
material only for the bounded session (ADR-002). The harness is the
**repository-transaction and rein-local tool-policy enforcement point**
inside a chained grant — not the only credential holder or the only
policy enforcement point in the estate. Queue, profile, sandbox,
credential custody/authorization, and provider boundaries enforce their
own grants; this runtime must not weaken them. Instances declare policy
and pin a harness major version; upgrades happen centrally.
## Strategic role