Skip to content

I12: The concierge #50

Description

@lex00

Lesson

The concierge has an empty card, so goal and done_when are written with the body. The desk in repo mode takes a request in words, edits one file, runs terraform plan and check-no-new-access, renders the access delta and opens a PR with a PR-only token. The merge is the approval and the sandbox holds no cloud credential. The worked request is "site-publisher needs read on waterpark-artifacts". An unmapped requester is refused with the enrollment path, a boundary change with the platform path. The lesson demonstrates properties V, VIII and IX, closes prescription P13, and enacts estate.md scenario 6, the request.

Build

  • the AWS desk page and its panes, with spec.ts and protocol.ts carrying aws-state, aws-plan and aws-result (phase 3, repo mode in phase 4)
  • scripts/render-delta and scripts/proofs, because delta and proofs are never model output (decision 14)
  • the checked-in Fountain manifest applied with fountain apply, holding the Environment (terraform, awscli, jq, networking_type: limited), the agent, a repo-mode vault with only a fine-grained GITHUB_TOKEN, the teammate
  • decision 17 enrollment, an identity field on a human principal's leaf file plus a check that it is well formed, unique and never on a workload principal
  • SKILL.md golden paths covering both refusals and their escalation routes
  • Lesson body written to the page model and verified on a live Floci stack per the authoring checklist in project/page-model.md

Done when

done_when is empty. P13's check in prescriptions.md is the done when and reads "the same command an agent invokes produces the same PR with no agent involved, and a refusal names the escalation path." #17's last criterion lands here too, an agent answering from a bare checkout with the correct file path and PR flow.

Source material

Decisions 14, 15, 17, 18 and 30 govern.

Open

design/agentic.md has a repo script, scripts/request, author the concierge's edit. aws-desk.md step 2 has the desk make the edit itself and lists no such script. Reconcile the two before the lesson is written. D1 also puts plan-tier read-only credentials in the sandbox, which contradicts decision 15.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    I12IAM course lesson I12course-2The IAM course backlog

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions