Wire supervised startup and publish corrected Secret guidance
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 5s

This commit is contained in:
codex 2026-09-28 18:25:30 +02:00
parent 416dbf961c
commit ca4c174467
5 changed files with 90 additions and 88 deletions

View file

@ -186,6 +186,38 @@ get wrong.
---
## Agent supervision at session start
Read `docs/agent-autonomy-decision.md` and the record for the identified agent.
For the Custodian Codex assignment, that record is
`.kaizen/agents/custodian-codex/supervision.json`. Check its scope, supervisor,
mode and runtime-enforcement status before privileged work. Do not inherit a
record belonging to another agent or scope. Missing promotion evidence means
supervised-mode; neither a mode label nor preapproved shell prefixes establish
credential isolation or an autopilot grant.
Summarize the existing record without changing authority:
```bash
python3 scripts/summarize_agent_supervision.py .kaizen/agents/custodian-codex/supervision.json
```
Before submitting a new privileged-action proposal, retain its stable proposal
ID, exact original revision/digest, target, expected result, verification and
rollback, and cost/risk estimates in the existing record or referenced receipt.
Record the supervisor disposition and approved revision, then the exact executed
revision, verified outcome, refinements and recovery. A revision is part of the
same trial, not another success. Preserve failed and unverified outcomes. Do not
backfill missing approval evidence into a scored success.
Existing session authorization remains valid within its scope; do not ask again
merely to populate a record. Routine authorized preparation, local edits and
checks continue. The reporting utility cannot approve actions or promote the
agent. Autopilot requires an explicit scoped grant, EUR cost/risk limits and
verified runtime enforcement; it is not enabled for this assignment.
---
## Workplan Convention (ADR-001)
Work items originate as files in this repo — not in the hub. The hub is a