# Offline approval mirror for the canonical State Hub decision # 4589dcb7-c0df-4073-9a0b-4f80a0fcdb93 (SECRETS-WP-0004). # # Build-mode short-circuit: the operator (Bernd) authorized the warden-sign prod # apply and the canonical hub decision is recorded; this mirror lets # `secrets-engine apply warden-sign --stage prod` resolve the lane's decision_ref # (SECRETS-WP-0004) without waiting. The hub decision is the audit record; resolve # it formally with "Approved:". NON-SECRET: contains no token value. id: SECRETS-WP-0004 title: "warden-sign auth-capability lane — prod apply (FLEX-WP-0007 T4)" status: resolved superseded_by: null decided_by: "human" review_url: "http://127.0.0.1:8000/decisions/4589dcb7-c0df-4073-9a0b-4f80a0fcdb93" rationale: >- APPROVE: establish the warden-sign OpenBao policy + AppRole granting update on ssh/sign/{agt,adm,atm}-role only, for the FLEX-WP-0007 T4 production policy-gate smoke. Tightly scoped (denial probes confirm no token-create/sudo/root/admin). No secret value exposed or stored. Operator-authorized in build mode.