# Glas Claude exec delivery Proposed native lane `glas-claude-agent-dev-anthropic`, provenance railiance-platform CCR-2026-0016; implementation/activation record SECRETS-WP-0009. KV custody is already confirmed at version 2. Do not provision or rotate it as part of native read-lane adoption. The generated plan checks existing mount `platform`, creates policy and AppRole `se-prod-glas-claude-agent-dev-anthropic`, and grants read only on `platform/data/workloads/glas-harness/claude-agent-dev`. Field ANTHROPIC_API_KEY is selected by the exec adapter; KV policies scope entries, not fields. `delivery_auth.metadata_read: false` excludes the metadata endpoint; existing lanes retain their previous metadata access by default. Token TTL 5m, maximum 15m, SecretID TTL 5m and single use, token use budget 8. No wildcard, listing, workload writes, mount mutation, provider creation or default-policy change is included in this plan. Verify effective token identity policies at activation. Sand-boxer's owner-configured credential route binds profile, project, actor and nonempty run id before invoking secrets-engine's exec-env interface. The provider injects the key into a private host helper that directly forwards it to the namespace broker. The broker injects only ANTHROPIC_API_KEY into the command and redacts exact values before truncating output. No OpenBao token crosses into the sandbox; no key is returned through Glas's API. Values are available to the trusted workload and descendants; encoding/exfiltration by hostile workload code is not prevented by an output redactor. Existing sandbox, egress, artifact verification and profile admission boundaries remain required. A synthetic provider proves the transport only. It does not stand in for native approval, OpenBao access, provider authentication or production readiness. ## Activation requirements The current engine's production stance refuses before opening the backend: `production action 'exec' requires a durable access-engine decision record; live production remains disabled`. This refusal was exercised with the proposed catalog and service-jwt selection. No real value was requested. Activation depends on SECRETS-WP-0007-T04 (exact production actions) and SECRETS-WP-0008-T02/T06 (decision consumption and service authority). Require canonical ActionAuthorization for each protected action, successful consume, and exact scoped backend authority. This draft cannot authorize itself; an operator browser token or unsafe-demo flag is not a runtime substitute. Once those services exist: obtain the reviewed apply authorization, apply this exact policy/AppRole with scoped authority, verify positive read and denied metadata/sibling/write access without exposing values, and record delivery-ready state. Bind approved exec authorization and named engine service authentication to the sand-boxer owner route. Prove actual provider authentication and a bounded Glas task, then activate routing and only the validated profile. Rotation: store replacement with CAS, stop old runs, verify replacement, revoke predecessor at Anthropic and prove denial. Bao session expiration does not revoke the provider key. Compromise disables the provider key and affected runs first.