# Agent Identity Provisioning Playwright-based automation for provisioning AI agent identities across the TSYS Group stack: Cloudron enrollment (with 2FA), SSO login, API key generation, and Bitwarden credential storage. ## Overview Each AI agent (VP TechOps, VP SecOps, etc.) gets: 1. A dedicated Cloudron user (identity root — SSO provisions everywhere) 2. TOTP 2FA enrolled and stored in Bitwarden 3. API keys generated in Gitea, Discourse, Redmine (stored in Bitwarden) 4. All credentials owned by the agent, sourced via `bw-run.sh` (no `~/.creds/` files) See `~/Q3/agent-identity-bootstrap.md` for the full architecture. ## Usage ```bash # 1. Create the manifest from the example cp agents.yaml.example agents.yaml # Edit: add Cloudron invite links for each agent # 2. Set BW credentials export BW_CLIENTID="..." export BW_CLIENTSECRET="..." # 3. Build and run docker compose up --build # Or run a single agent docker compose run --rm provision --agent vp-techops ``` ## Manifest format See `agents.yaml.example`. Each agent defines: - Cloudron invite link - Display name - Priority (Q3 vs Q4) - System scopes (Redmine projects, Gitea orgs, Discourse categories)