Skip to content

Agent Enablement Register

Generated by Vera on 2026-06-20. This is a read-only inaugural audit artifact — a dated point-in-time snapshot, imported into the canonical data room 2026-07-04 (dataroom PR-12).

Currency note (2026-07-04): statements below that director-agent holds roles/owner reflect the 2026-06-20 audit date and are now superseded — the root-and-branch review R1/R4/R10 closures de-privileged director-agent to roles/editor with per-secret accessor ACLs and an admin@ break-glass path (verified 2026-07-04; see control-register.md SEC-16 and registers/action-register.md RSK-003). Other rows may have moved since; re-audit is Vera's cadence, not per-PR upkeep.

Verification rule used here: a Full-API-keyless classification is used only where I independently called the relevant API read-only as Vera and verified a keyless operating identity path. Token-backed, portal-backed, unverified, or Vera-inaccessible services are classified as Partial or Manual-CEO.

Register

Service What it does How we access it today Control level Credential & where vaulted Gap Closure action Owner Risk if uncontrolled
GCP project, IAM, and control-plane VM Production substrate and agent control plane for Partile Vera gcloud --configuration=vera read-only calls verified project, IAM, service accounts, org policies, and partile-control; director-agent is attached to the VM and has Owner Full-API-keyless Keyless attached SAs; vera-platform read-only; director-agent attached to partile-control; no user-managed SA keys found; effective org policy disables SA key creation and upload director-agent Owner is reachable from the shared otto host context; Cloud Asset API is disabled; least-priv split for director/executors is incomplete Propose per-agent OS identities and scoped SAs, enable read-only Cloud Asset inventory, and schedule access reviews; requires Otto approval for privilege/IAM changes Executor-PR A shell-agent escape or credential bleed can become Owner-level control; inventory drift can go unseen
Cloud Run API, jobs, Scheduler, Pub/Sub remediation Runs backend API, matching, retention, migration, and shadow self-heal responder GCP APIs verified Cloud Run services/jobs, Scheduler jobs, Pub/Sub topic/subscription; /health and /ready GETs returned OK through Cloudflare and direct run.app Full-API-keyless Runtime SAs and Secret Manager references; no SA keys API Cloud Run ingress is public/direct; remediation is shadow only with ENFORCE=false; protected-service origin policy is not uniformly hardened Propose private ingress or authenticated origin pattern where appropriate; run self-heal game-day before any enforce flip Executor-PR Origin bypass and manual remediation leave operational and access-control risk
Cloud SQL partile-prod-postgres Production Postgres gcloud sql instances list verified private IP, PITR/backups, state RUNNABLE Full-API-keyless GCP IAM plus partile-prod-database-url in Secret Manager Zonal only; deletion protection false; SSL not required; connector enforcement not required Propose SSL/connector enforcement, deletion protection, HA plan, and restore drill before real SLA Executor-PR Data outage, weaker transport posture, and recovery uncertainty
Memorystore Redis partile-prod-redis Rate limiting, OAuth state, worker cache gcloud redis instances list verified private network, state READY Full-API-keyless partile-prod-redis-url in Secret Manager BASIC tier, transit encryption disabled, persistence disabled Propose transit encryption and HA/persistence decision before beta SLA Executor-PR Session/rate-limit state loss and weaker in-VPC transport posture
Secret Manager Vault for app, platform, signing, and vendor credentials gcloud secrets list verified metadata for app, Cloudflare, Sentry, GitHub, Expo, ASC, iOS signing, AeroDataBox, and Grafana secrets; no values read Full-API-keyless GCP Secret Manager in partile-prod; Vera has metadata-only access A Grafana admin password is also present inline in Cloud Run env metadata; rotation cadence and action audit log are not closed Rotate and move inline Grafana password to Secret Manager reference; add rotation inventory and audit trail Executor-PR Secret sprawl and accidental exposure through metadata/logs
GCP Billing and budgets Spend guardrail for the $1k/mo envelope Project billing linkage is visible; Vera budget-list call was denied on billing account 018CC1-43D4A6-862538 Partial Billing account access; no secret Budget claim not independently verified by Vera Ask Otto to approve read-only billing/budget visibility for Vera or a scheduled export CEO-one-time Spend drift or missing alerts may remain invisible to the audit identity
Cloud Monitoring, uptime, alerts, self-heal feed Observability, alerting, and remediation signal GCP APIs verified 4 uptime checks, 6 alert policies, remediation Pub/Sub push, and default logging sinks Full-API-keyless GCP IAM/runtime SAs; notification channel details not fully listed by current GA command set No external SIEM/action audit log; self-heal is shadow; monitoring channel read command unavailable in this SDK surface Propose action audit log, channel inventory, and self-heal enforce plan after reviewed game-day Executor-PR Alerts may not translate to accountable action; remediation remains manual
Artifact Registry and GCS buckets Container images, Terraform state, build sources, iOS ad-hoc artifacts, Plane backups GCP APIs verified repositories and buckets Full-API-keyless GCP IAM; GCS buckets; Artifact Registry Container vulnerability scanning disabled; some buckets inherit public-access-prevention rather than enforce; ad-hoc build artifact lifecycle/access needs review Enable container scanning; review bucket IAM/PAP/lifecycle; keep signed-build delivery documented Executor-PR Vulnerable images and artifact exposure can go unnoticed
Google Workspace and Gmail Domain admin, Gmail send/read for Otto, company email Admin SDK and Gmail APIs are enabled; MX and SPF DNS verified; DWD scripts exist but require director-agent signing, which Vera must not use Partial Keyless DWD via director-agent; no Vera DWD grant verified Vera cannot independently audit Workspace without violating charter constraints; no DMARC record found; Cloudflare email inbox is retired Ask Otto for a Vera-specific read-only DWD path; add DMARC; keep Otto-only comms boundary CEO-one-time Workspace/email control claims remain director-gated; spoofing posture is incomplete without DMARC
GitHub haroonhassan/partile Off-box durability, branches, PRs, Actions CI GitHub app _get_repo verified private repo and admin permissions; git ls-remote verified remote heads; gh CLI is absent from Vera PATH Partial Vaulted github-pat; local SSH keys; GitHub app connector has broad permissions API control exists but is not keyless and appears over-privileged for audit; Actions secrets/workflows not independently listed because gh is absent Install/read-only gh or expose connector reads for Actions/secrets; reduce token/app scope; schedule mirror/restore drill Executor-PR Repo/CI drift and broad token blast radius can persist
Apple Developer and App Store Connect App IDs, capabilities, provisioning, TestFlight/App Store path, iOS signing ASC/iOS signing secrets are vaulted; docs show ASC API used for capabilities/profiles; no Vera API probe because secrets are values and Apple portal is 2FA-gated Partial asc-api-key, asc-key-id, asc-issuer-id, iOS dist cert/profile secrets in Secret Manager; GitHub mirrors not verified App Groups and likely APNs/durable Apple ID remain portal/2FA-gated; no durable agent Apple ID yet CEO sets durable Apple ID and 2FA phone via Twilio; executor then wires repeatable ASC/APNs scripts CEO-one-time iOS release/signing can stall on human portal actions
AeroDataBox via API.market Flight status/provider data for travel companion Secret metadata verified; backend /ready verified Postgres/Redis; backend docs show authenticated /flights/{flight}/{date} provider route Partial aerodatabox-api-key in Secret Manager Vera cannot read the key or call provider directly; fill-rate at LHR/JFK/SFO remains unmeasured; provider terms evidence not in register Propose a read-only sampling job through backend/runtime secret reference and terms evidence capture Executor-PR Product may rely on unavailable gate/baggage fields or unverified redistribution terms
LinkedIn OAuth app OIDC login/profile bootstrap Public LinkedIn OIDC discovery and JWKS verified; backend auth uses vaulted client ID/secret references Partial partile-prod-linkedin-client-id and partile-prod-linkedin-client-secret in Secret Manager Vera cannot inspect LinkedIn developer-portal app settings or complete OAuth without user interaction/secret values Record portal owner and redirect inventory; create read-only app config audit path if LinkedIn supports it CEO-one-time OAuth app drift, redirect mismatch, or portal lockout can break sign-in
Cloudflare DNS, Workers, Pages, Access Edge DNS, API Worker, Pages dataroom, Access gates for dataroom/observe/plane, pass/mock Workers Public probes verified DNS, Access challenges, pass/mock pages, and Cloudflare nameservers; repo scripts model Workers/DNS/Access deploys Partial cloudflare-api-token in Secret Manager; retired cloudflare-mail-token also present No Cloudflare API call as Vera; no wrangler; token scope/rotation not verified; API and Grafana origins have direct run.app exposure Add Vera read-only Cloudflare token or connector; rotate tokens; harden origins with Tunnel/private ingress/service-token pattern Executor-PR DNS/Access drift or token compromise can expose internal surfaces
observe.partile.app Grafana Internal pane of glass CLOSED 2026-06-20: Cloud Run now uses Secret Manager refs for Grafana admin password and origin guard; raw run.app origin returns 403, public host still presents Cloudflare Access. Evidence: platform/VERA-GRAFANA-FIX-RESULT.md Partial grafana-admin-password and grafana-origin-guard-token in Secret Manager; runtime SA has accessor on both; no inline Grafana admin password in Cloud Run metadata Closed: inline plaintext password removed and public origin bypass closed with Cloudflare Worker + origin guard Closed; human post-Access visual browser check remains operator-owned per result note Closed Residual risk limited to normal Access/Worker/secret operations; prior direct-origin bypass is closed
Plane plane.partile.app Self-hosted PM/wiki surface Cloudflare Access challenge verified; GCE VM, firewall, backups bucket, and service account verified via GCP APIs Partial Plane VM SA; app/admin credentials not inventoried by Vera Plane app API/admin credential not audited; VM has public NAT but firewall allows only Cloudflare HTTP(S) and IAP SSH; restore drill not verified Vault/record Plane admin/API credential path; test backup restore; consider origin tunnel Executor-PR PM system data and runbooks can drift or be hard to recover
Sentry Error/crash reporting and future dSYM upload Sentry secret metadata verified; docs say DSN/token exist and dSYM upload disabled due wrong slug Partial sentry-dsn, sentry-readonly-token, sentry-otto-token in Secret Manager No Sentry API probe as Vera; slug/dSYM upload gap remains; token rotation pending Add Vera read-only probe or connector; fix slug and dSYM upload; rotate exposed tokens Executor-PR Crash visibility and release symbolication remain unreliable
Executor vendors: Anthropic Claude, OpenAI Codex, Antigravity Agent execution subscriptions and CLIs claude, codex, and agy CLIs are installed and version-checked; local auth files exist but were not opened Partial Local user config/auth files under shared otto home; Anthropic API key for app in Secret Manager Vendor admin/billing APIs not audited; local credentials shared by shell context; per-executor identity/cost controls incomplete Move to per-agent OS users/credential scopes; document vendor admin owners; add cost/eval controls Executor-PR Shared credentials and unmanaged spend can undermine the agentic operating model
Twilio Future WhatsApp and durable Apple ID 2FA phone No setup or secret found Manual-CEO None yet Required blocker for durable agent Apple ID and WhatsApp ingress CEO/Otto choose and create Twilio account/number, then executor wires read/API controls CEO-one-time Apple remains human-2FA-gated; WhatsApp sensor channel cannot launch
Expo/EAS and retiring RN app RN build service and OTA/build history expo-token secret metadata exists; EAS CLI not present; mobile worktree path referenced by Atelier is absent on disk in this checkout; RN is being retired at native cutover Partial expo-token in Secret Manager Control is stale/uncertain; OTA not wired; service should either be sunset or restored for read-only audit until cutover Decide retire date; if still live, reinstall CLI/read-only probe and rotate token Executor-PR Legacy build path can consume spend or fail silently during cutover
Domain registrar for partile.app Domain registration, renewal, registry controls Public RDAP shows registrar Cloudflare, registration 2026-03-04, expiration 2027-03-04, transfer prohibited; DNS NS are Cloudflare Manual-CEO No registrar-specific credential found for Vera; likely Cloudflare account/portal Registrar/renewal/DNSSEC/registrant controls are not agent-auditable; CAA absent; DMARC absent Record registrar owner, renewal/payment status, and approved registrar API/portal procedure; add DMARC and consider CAA/DNSSEC CEO-one-time Domain loss, hijack, or email spoofing can become company-critical

Retired or Superseded

  • Cloudflare email inbox: retired in favor of native Gmail; not audited as live.
  • RN/EAS: treated as a sunset surface at native cutover, but included above because expo-token still exists.

Ranked Closure Plan

  1. [Closed 2026-06-20] Remove the Grafana inline secret and harden observe origin. Admin password rotated and injected via Secret Manager; origin guard + Cloudflare Worker closes direct run.app bypass. Evidence: platform/VERA-GRAFANA-FIX-RESULT.md.
  2. [Executor-PR] Isolate agent credentials and identities. Split shared otto host credentials into per-agent OS users and scoped SAs; prevent executor shells from reaching Owner ADC or vendor admin credentials.
  3. [CEO-one-time] Set up Twilio and durable Apple ID. This closes the recurring Apple portal/2FA blocker and unlocks APNs/App Store operations that ASC cannot cover alone.
  4. [Executor-PR] Add Vera read-only audit paths for Cloudflare, Sentry, Workspace, GitHub Actions, and billing. Do not give Vera write or secret values; use read-only API scopes/connectors and metadata-only probes.
  5. [Executor-PR] Enable inventory and supply-chain evidence. Enable Cloud Asset read inventory, container vulnerability scanning, secret scanning, and a durable action/audit register.
  6. [Executor-PR] Tighten data-plane reliability and transport. Plan Cloud SQL HA/SSL/connector enforcement, Redis transit encryption/HA decision, and restore drills for SQL, Plane, and control-plane disks.
  7. [Executor-PR] Validate flight-data provider assumptions. Run a bounded AeroDataBox fill-rate sample through backend/runtime credentials and record provider terms for caching/display/redistribution.
  8. [Executor-PR] Fix release-observability gaps. Correct Sentry slug/dSYM upload and inventory GitHub Actions macOS CI/secrets through a read-only path.
  9. [CEO-one-time] Confirm registrar/account ownership. Record Cloudflare Registrar renewal/payment owner and recovery path; then use approved Cloudflare/DNS automation for DMARC/CAA/DNSSEC decisions.