diff --git a/H22026-business-map.md b/H22026-business-map.md index b525b0e..1b96030 100644 --- a/H22026-business-map.md +++ b/H22026-business-map.md @@ -132,6 +132,59 @@ ap4ap.org, sol-calc.com, uksrs.org), TSYS Group holding structure. --- +## Agent Identity Ownership (Bitwarden account tiers) + +**Principle:** credentials live in the BW account of the executive line +that operates the identity — not one shared vault. The "council of four" +(board / CTO / COO / CCO) each get their own Bitwarden account. + +### COO BW account (exists, `coo@turnsys.com` on pwvault.turnsys.com) + +Owns ALL current identities (the COO line is the group's shared +services). 10/10 enrolled + TOTP as of 2026-08-14: + +- **SVP tier:** svp-knel, svp-tctc +- **VP tier (KNEL):** vp-techops, vp-secops, vp-techcompliance +- **VP tier (TCTC):** vp-investing, vp-trading, vp-compliance +- **VP tier (other):** vp-facilities + +Still to flesh out on the COO side (do NOT enroll into this vault): +nothing until H22026.md locks the org chart — then directors +(director-infra, director-sre, director-soc, ...) and IC worker/reviewer +pairs (ic-*-1 / ic-*-2) join THIS vault, since they work under the COO +line. Estimate: ~15-25 identities. + +### CTO BW account (Charles to stand up) + +- `ctpo` (invite already issued, intentionally parked in the invites + file — do not merge into the COO provisioner manifest) +- Future: Suborbital Systems agents, ventures portfolio ICs + (RackRental/MerchantsOfHope/TeamRental/ap4ap/sol-calc/uksrs pods) + +### CCO BW account (Charles to stand up) + +- `cco` (invite already issued, parked likewise — the AI executive) +- Future: Side Door Group agents (501c3/c4/PAC compliance ICs), + Redwood Springs Capital Partners agents (securities compliance), + Redwood Family Office agents, High Flight co-op agents + +### Board BW account (Charles to stand up) + +- `board-secretariat` (agenda/minutes/resolutions) +- `director-audit` (independent audit chair; reports to board only) + +### Provisioning mechanics note + +The provisioner (KNEL/agent-identity-provisioning) is COO-vault-bound +via `~/.config/bw/env`. Other tiers need their own env files +(e.g. `~/.config/bw/env-ctpo`) and a compose override or BW_ENV_FILE +switch before their invites can be accepted. ctpo/cco invites in +~/cloudron-invites.txt must be EXCLUDED from merge-invites.py runs +until then (they currently WOULD be appended as new agents — filter +them or split the file). + +--- + ## Lineage - Charles has been designing this organization since age 14 (currently