docs: agent identity ownership — BW account tiers per council-of-four line

This commit is contained in:
TSYS Group COO
2026-09-07 14:51:13 -05:00
parent 678abc8d74
commit 8acb8616f0
+53
View File
@@ -132,6 +132,59 @@ ap4ap.org, sol-calc.com, uksrs.org), TSYS Group holding structure.
--- ---
## Agent Identity Ownership (Bitwarden account tiers)
**Principle:** credentials live in the BW account of the executive line
that operates the identity — not one shared vault. The "council of four"
(board / CTO / COO / CCO) each get their own Bitwarden account.
### COO BW account (exists, `coo@turnsys.com` on pwvault.turnsys.com)
Owns ALL current identities (the COO line is the group's shared
services). 10/10 enrolled + TOTP as of 2026-08-14:
- **SVP tier:** svp-knel, svp-tctc
- **VP tier (KNEL):** vp-techops, vp-secops, vp-techcompliance
- **VP tier (TCTC):** vp-investing, vp-trading, vp-compliance
- **VP tier (other):** vp-facilities
Still to flesh out on the COO side (do NOT enroll into this vault):
nothing until H22026.md locks the org chart — then directors
(director-infra, director-sre, director-soc, ...) and IC worker/reviewer
pairs (ic-*-1 / ic-*-2) join THIS vault, since they work under the COO
line. Estimate: ~15-25 identities.
### CTO BW account (Charles to stand up)
- `ctpo` (invite already issued, intentionally parked in the invites
file — do not merge into the COO provisioner manifest)
- Future: Suborbital Systems agents, ventures portfolio ICs
(RackRental/MerchantsOfHope/TeamRental/ap4ap/sol-calc/uksrs pods)
### CCO BW account (Charles to stand up)
- `cco` (invite already issued, parked likewise — the AI executive)
- Future: Side Door Group agents (501c3/c4/PAC compliance ICs),
Redwood Springs Capital Partners agents (securities compliance),
Redwood Family Office agents, High Flight co-op agents
### Board BW account (Charles to stand up)
- `board-secretariat` (agenda/minutes/resolutions)
- `director-audit` (independent audit chair; reports to board only)
### Provisioning mechanics note
The provisioner (KNEL/agent-identity-provisioning) is COO-vault-bound
via `~/.config/bw/env`. Other tiers need their own env files
(e.g. `~/.config/bw/env-ctpo`) and a compose override or BW_ENV_FILE
switch before their invites can be accepted. ctpo/cco invites in
~/cloudron-invites.txt must be EXCLUDED from merge-invites.py runs
until then (they currently WOULD be appended as new agents — filter
them or split the file).
---
## Lineage ## Lineage
- Charles has been designing this organization since age 14 (currently - Charles has been designing this organization since age 14 (currently