id: glas-claude-agent-dev-anthropic kind: kv org: coulomb repo: sand-boxer stage: prod description: Proposed native exec-env delivery for CCR-2026-0016. KV custody exists; no runtime grant or activation yet. mount: platform path: workloads/glas-harness/claude-agent-dev mount_management: existing fields: - ANTHROPIC_API_KEY consumers: - name: sand-boxer-glas-agent-dev auth: approle claim: catalog:glas-claude-agent-dev-anthropic purpose: Owner-admitted glas-harness agt run through the reviewed local profile; no caller-facing key fetch workload_delivery: [] delivery_config: exec_owner: status: pending owner: rein-aharness MessagesOwner with sand-boxer runtime boundary reason: Exact installed metered-once runtime is proved; native holder review, immutable owner configuration and private state/profile/service admission remain SECRETS-WP-0009-T03 and HFACT-WP-0001-T03/T04. No arbitrary child may receive this key while the owner binding is pending. delivery_modes: - exec-env - read-check delivery_auth: method: approle management: engine policy_name: se-prod-glas-claude-agent-dev-anthropic role_name: se-prod-glas-claude-agent-dev-anthropic metadata_read: false token_ttl: 5m token_max_ttl: 15m secret_id_ttl: 5m secret_id_num_uses: 1 token_num_uses: 8 approval: model: ccr human_control: true decision_ref: CCR-2026-0016 notes: Custody only has been completed. Native apply and exec require durable exact-action authorization, engine consume, scoped backend authority and verified delivery state. This entry is not authorization. verification: positive: Exact scoped AppRole reads only ANTHROPIC_API_KEY into the approved child; owner binding and redaction pass. negative: Wrong owner profile/project/actor, direct caller fetch, sibling KV, metadata, listing and writes denied. risk: classification: high notes: API spend; provider expiry 2027-01-31T21:00:00Z is not enforced by Bao token TTL. Workspace scope and budget unverified. rotation: owner: railiance-platform + sand-boxer expectation: Provider replacement, versioned CAS custody, stop old runs, verify replacement then revoke predecessor at Anthropic and prove denial. ttl: provider-defined deactivation: owner: railiance-platform + sand-boxer expectation: Disable lane, stop affected runs, revoke Bao sessions and provider key. Preserve custody history. audit: evidence: CCR id, actor, exact path, field name, provider key identifier if non-secret, timestamps, and pass/fail only