Refine security blocker posture review

This commit is contained in:
2026-06-27 18:22:06 +02:00
parent da0735a05a
commit 4a66ebfbb6
4 changed files with 90 additions and 10 deletions

View File

@@ -50,7 +50,13 @@ Hygiene status:
## Blocker Board
No live credential, access, or approval gate is unowned. Do not ask
`ops-warden` for secret values; use the route catalog and the owning subsystem.
`ops-warden` for secret values; use the route catalog, the `warden access`
assist/proxy surface where the catalog lane allows it, and the owning subsystem.
For credential-related blockers, classify the environment posture and workload
maturity first. Dev/test work can use synthetic contract doubles; production
real-value work needs owner custody, policy gates where applicable, and
non-secret evidence. See `docs/ops-warden-secret-posture-review.md`.
| Gate | Owner/route | Non-secret evidence to collect | Next action |
| --- | --- | --- | --- |