# Custodian Brief — secrets-engine **Domain:** infotech **Last synced:** 2026-08-29 10:00 UTC **State Hub:** http://127.0.0.1:8000 *(adjust if running on a remote machine)* ## Active Workstreams ### Evolve the Lifecycle engine to the accepted security layer model Progress: 0/6 done | workplan_id: `9c9e5164-b2f5-5ea2-a557-5368d65e9fe0` **Open tasks:** - ! Consume access-engine decision records `3eb9cff8` - ! No standing engine credential `d7bc8bdc` - · Publish stance application as shipped behaviour `945735c6` - · Emit evidence under the §9.6 bound `0b54cedf` - · Accept the SSH-CA signing engine surface `581aeee3` - · Accept the secret-use evidence surface `3100d28c` ### Adopt concrete OpenBao credential lanes from ops-warden Progress: 4/6 done | workplan_id: `31f7f8ea-7f73-516c-8877-f03a13f1db82` **Open tasks:** - ! Stage live apply and verification `fb103f1e` - ! Reconcile routing ownership and retire interim proxies `1431edae` ### Production-safe provisioning, authorization, and lifecycle hardening Progress: 2/7 done | workplan_id: `68a39be1-bd9c-5133-ad64-e7bca892aaf3` **Open tasks:** - ! Resume native production lane adoption `a0a1dd92` - ► Split suspend, deactivate, and destroy semantics `bb6073e1` - ► Bind approvals to exact production actions `4b58edec` - ► Make delivery sessions short-lived and explicitly closed `36bcd64d` - ► Strengthen verification, readiness, and evidence `431bc91b` --- ## MCP Orientation (when available) If the state-hub MCP server is reachable, call: `get_domain_summary("infotech")` This provides richer cross-domain context. If the MCP call fails, use this file as your orientation source.