V3: Watch on the mighty #73

Open
opened 2026-08-12 16:16:30 +00:00 by agent.teyla · 1 comment
Contributor

V frontier

In scope

  • Admin-level identities enumerated as declarations: Kanidm admin groups, Bao root-capable policies, unseal-share holders, the curator's signing keys. An identity with ceremony-skipping power that is not declared is itself a finding.
  • Every use of one is a record and a report: root token generation, unseal events, admin-group authentication, policy edits at admin level. Correlated to the ceremony calendar: an unseal during a declared ceremony window is expected and logged; the same act outside one is a page.
  • Dormancy watch both ways: an admin identity used outside ceremony is loud; one never exercised is quietly rotting — drills exist so break-glass is known to work.

Out of scope

  • Blocking any admin act. The mighty are watched, not gated — gating the break-glass is how estates die during incidents.

Boundary

  • Vedanta watches the mighty because identity is its perimeter; who watches Vedanta is answered by the seam, not by privilege: Jostoph's independent chain carries every Vedanta ruling and declared mint, and Jostoph cannot mint. The watcher of admins is watched by a service without the power it watches.

Acceptance

  • A root-token generation outside a ceremony window pages with actor, time, and the calendar entry it lacked.
  • The declared-identities list and the forge/IdP reality are compared by a conformance verb; drift exits non-zero, roster's mold.

Source: JOSTOPH-BACKLOG.md, Milestone V.

`V` `frontier` **In scope** - Admin-level identities enumerated as declarations: Kanidm admin groups, Bao root-capable policies, unseal-share holders, the curator's signing keys. An identity with ceremony-skipping power that is not declared is itself a finding. - Every use of one is a record and a report: root token generation, unseal events, admin-group authentication, policy edits at admin level. Correlated to the ceremony calendar: an unseal during a declared ceremony window is expected and logged; the same act outside one is a page. - Dormancy watch both ways: an admin identity used outside ceremony is loud; one *never* exercised is quietly rotting — drills exist so break-glass is known to work. **Out of scope** - Blocking any admin act. The mighty are watched, not gated — gating the break-glass is how estates die during incidents. **Boundary** - Vedanta watches the mighty because identity is its perimeter; who watches Vedanta is answered by the seam, not by privilege: Jostoph's independent chain carries every Vedanta ruling and declared mint, and Jostoph cannot mint. The watcher of admins is watched by a service without the power it watches. **Acceptance** - A root-token generation outside a ceremony window pages with actor, time, and the calendar entry it lacked. - The declared-identities list and the forge/IdP reality are compared by a conformance verb; drift exits non-zero, roster's mold. Source: JOSTOPH-BACKLOG.md, Milestone V.
Owner

Audit 2026-09-19/20, G55: external-system facts are bounded in umbrella probe Ting/Jostoph#127 (#127). This record probe section and result columns are named there; no implementation claim is made here.

<!-- larandar:groom:v1 --> Audit 2026-09-19/20, G55: external-system facts are bounded in umbrella probe Ting/Jostoph#127 (https://jo.et0.pw/Ting/Jostoph/issues/127). This record probe section and result columns are named there; no implementation claim is made here.
Sign in to join this conversation.
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Reference
Ting/Jostoph#73
No description provided.