docs: put agent identity behind a real uid
Join the older storage and authority audits to the SAF principal contract. Passwd entries are not isolation while one human-owned process still executes every agent, and the existing souveraine account is machined's—not Souvie's.\n\nKeep the readiness task honest: its current health fields inventory paths, but do not yet prove admission or the UID handling a live turn.
This commit is contained in:
parent
1d9f62974e
commit
9815185caa
6 changed files with 52 additions and 20 deletions
|
|
@ -97,6 +97,13 @@ voice on hits a silent failure.
|
|||
**Fixed in this batch:** read-only fields for agent id, subconscious
|
||||
id, memory/subconscious paths, disk existence check.
|
||||
|
||||
This is inventory health, not identity health. It still does not say
|
||||
whether the agent has a node-local Unix account or whether the live turn
|
||||
and its tools are running as that account instead of the human. The living
|
||||
acceptance contract is
|
||||
`../../../../souveraine/saf/identity/02-agent-principal.md`: missing admission
|
||||
is `unadmitted`; uid-1000 execution is `acting-as-human`, never green.
|
||||
|
||||
## TUI Interaction Gaps (flagged by Casey, May 18)
|
||||
|
||||
These also block a comfortable first session — they match open entries in the
|
||||
|
|
|
|||
Loading…
Reference in a new issue