Skip to content

docs(osapi): clarify when key enforcement begins - #133

Merged
retr0h merged 2 commits into
mainfrom
docs/clarify-agent-key-store
Sep 18, 2026
Merged

retr0h merged 2 commits into
mainfrom
docs/clarify-agent-key-store

Conversation

@retr0h

@retr0h retr0h commented Sep 18, 2026

Copy link
Copy Markdown
Contributor

Clarify session on 002-agent-key-store, one question.

Q: When the controller holds no key for an agent — today, every agent — must it refuse that agent's messages, or accept them until re-enrolment?

A: Refuse, but only once the operator enables enforcement for that side, with the fleet view showing who still lacks a key so re-enrolment can be staged.

FR-009 rewritten from a question into that rule, and SC-007 added for the rollout it implies. Matches the fail-closed choice already shipped in the other direction, where an agent without a cached controller key refuses jobs.

Next: plan, then tasks.

🤖 Generated with Claude Code

FR-009 asked what happens to an agent with no stored key, which today is
every agent. Answer: enforcement is something the operator turns on per
side, never a side effect of upgrading, and once on a message from an
agent with no stored key is refused there.

Adds SC-007 for the staged rollout that implies: enable one side, see
who would be refused, re-enrol them, finish without the fleet stopping
at a moment nobody chose.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FuKUsHFG1EqZXamffh9M2c
@github-actions

Copy link
Copy Markdown

Thank you for contributing to this project! 😊🕹️

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FuKUsHFG1EqZXamffh9M2c
@retr0h
retr0h merged commit 2230fde into main Sep 18, 2026
6 checks passed
@retr0h
retr0h deleted the docs/clarify-agent-key-store branch September 18, 2026 03:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant