memory: svos key delivery confirmed by ledger-dev; cutover is with the operator

They pulled it from the vault and verified the sha independently, so delivery is
established rather than assumed. The remaining step — swapping the live
credential in env.sh, flipping worldtree.user_id, registering svos:miranda and
restarting the service — is the operator's, not mine and not theirs off a peer
message.

Also records that the global CLAUDE.md Heimdall routing line was corrected in
place on operator instruction, so the ruling is not carried by this file alone.
This commit is contained in:
2026-09-05 07:07:53 -07:00
parent bcbf92f3d1
commit 85ff740f94
+11 -3
View File
@@ -195,9 +195,17 @@ below is a live commitment or a known-open risk._
current tier back** — no GET, `/admin/usage` returns an empty users list, and
`/admin/events` is a live SSE stream, not an audit log. Guessing would have
handed over a key that quietly differs; `POST /admin/users/svos/tier` fixes it in
one call if their cutover hits a limit. **OPERATOR RULING 2026-09-05: worldtree-dev
owns code only, no ops — key material is infra-ops's.** Supersedes the global
CLAUDE.md line routing "Heimdall scopes (Worldtree auth) → worldtree-dev".
one call if their cutover hits a limit — and ledger-dev has recorded it as a
cutover watch item to fix ON REPORT, explicitly not pre-emptively. ledger-dev
pulled the key from the vault and verified it independently (same sha), so
delivery is confirmed. **The cutover itself — pasting the value into env.sh,
flipping `worldtree.user_id` from `ledger` to `svos`, registering
`svos:miranda`, restarting the service — is WITH THE OPERATOR**, not with me;
they will not do it off a peer message. They will `secret backfill` afterwards
rather than asking for a manual re-put. **OPERATOR RULING 2026-09-05:
worldtree-dev owns code only, no ops — key material is infra-ops's.** The global
`~/.claude/CLAUDE.md` line routing "Heimdall scopes (Worldtree auth) →
worldtree-dev" was corrected in place the same day on operator instruction.
- **Original constraints on that mint** (recorded because the deletion ordering is
a permanent trap, not a one-time step): string