Agent Enablement Register¶
Generated by Vera on 2026-06-20. This is a read-only inaugural audit artifact — a dated point-in-time snapshot, imported into the canonical data room 2026-07-04 (dataroom PR-12).
Currency note (2026-07-04): statements below that
director-agentholdsroles/ownerreflect the 2026-06-20 audit date and are now superseded — the root-and-branch review R1/R4/R10 closures de-privilegeddirector-agenttoroles/editorwith per-secret accessor ACLs and anadmin@break-glass path (verified 2026-07-04; seecontrol-register.mdSEC-16 andregisters/action-register.mdRSK-003). Other rows may have moved since; re-audit is Vera's cadence, not per-PR upkeep.
Verification rule used here: a Full-API-keyless classification is used only where I independently called the relevant API read-only as Vera and verified a keyless operating identity path. Token-backed, portal-backed, unverified, or Vera-inaccessible services are classified as Partial or Manual-CEO.
Register¶
| Service | What it does | How we access it today | Control level | Credential & where vaulted | Gap | Closure action | Owner | Risk if uncontrolled |
|---|---|---|---|---|---|---|---|---|
| GCP project, IAM, and control-plane VM | Production substrate and agent control plane for Partile | Vera gcloud --configuration=vera read-only calls verified project, IAM, service accounts, org policies, and partile-control; director-agent is attached to the VM and has Owner |
Full-API-keyless | Keyless attached SAs; vera-platform read-only; director-agent attached to partile-control; no user-managed SA keys found; effective org policy disables SA key creation and upload |
director-agent Owner is reachable from the shared otto host context; Cloud Asset API is disabled; least-priv split for director/executors is incomplete |
Propose per-agent OS identities and scoped SAs, enable read-only Cloud Asset inventory, and schedule access reviews; requires Otto approval for privilege/IAM changes | Executor-PR | A shell-agent escape or credential bleed can become Owner-level control; inventory drift can go unseen |
| Cloud Run API, jobs, Scheduler, Pub/Sub remediation | Runs backend API, matching, retention, migration, and shadow self-heal responder | GCP APIs verified Cloud Run services/jobs, Scheduler jobs, Pub/Sub topic/subscription; /health and /ready GETs returned OK through Cloudflare and direct run.app |
Full-API-keyless | Runtime SAs and Secret Manager references; no SA keys | API Cloud Run ingress is public/direct; remediation is shadow only with ENFORCE=false; protected-service origin policy is not uniformly hardened |
Propose private ingress or authenticated origin pattern where appropriate; run self-heal game-day before any enforce flip | Executor-PR | Origin bypass and manual remediation leave operational and access-control risk |
Cloud SQL partile-prod-postgres |
Production Postgres | gcloud sql instances list verified private IP, PITR/backups, state RUNNABLE |
Full-API-keyless | GCP IAM plus partile-prod-database-url in Secret Manager |
Zonal only; deletion protection false; SSL not required; connector enforcement not required | Propose SSL/connector enforcement, deletion protection, HA plan, and restore drill before real SLA | Executor-PR | Data outage, weaker transport posture, and recovery uncertainty |
Memorystore Redis partile-prod-redis |
Rate limiting, OAuth state, worker cache | gcloud redis instances list verified private network, state READY |
Full-API-keyless | partile-prod-redis-url in Secret Manager |
BASIC tier, transit encryption disabled, persistence disabled | Propose transit encryption and HA/persistence decision before beta SLA | Executor-PR | Session/rate-limit state loss and weaker in-VPC transport posture |
| Secret Manager | Vault for app, platform, signing, and vendor credentials | gcloud secrets list verified metadata for app, Cloudflare, Sentry, GitHub, Expo, ASC, iOS signing, AeroDataBox, and Grafana secrets; no values read |
Full-API-keyless | GCP Secret Manager in partile-prod; Vera has metadata-only access |
A Grafana admin password is also present inline in Cloud Run env metadata; rotation cadence and action audit log are not closed | Rotate and move inline Grafana password to Secret Manager reference; add rotation inventory and audit trail | Executor-PR | Secret sprawl and accidental exposure through metadata/logs |
| GCP Billing and budgets | Spend guardrail for the $1k/mo envelope | Project billing linkage is visible; Vera budget-list call was denied on billing account 018CC1-43D4A6-862538 |
Partial | Billing account access; no secret | Budget claim not independently verified by Vera | Ask Otto to approve read-only billing/budget visibility for Vera or a scheduled export | CEO-one-time | Spend drift or missing alerts may remain invisible to the audit identity |
| Cloud Monitoring, uptime, alerts, self-heal feed | Observability, alerting, and remediation signal | GCP APIs verified 4 uptime checks, 6 alert policies, remediation Pub/Sub push, and default logging sinks | Full-API-keyless | GCP IAM/runtime SAs; notification channel details not fully listed by current GA command set | No external SIEM/action audit log; self-heal is shadow; monitoring channel read command unavailable in this SDK surface | Propose action audit log, channel inventory, and self-heal enforce plan after reviewed game-day | Executor-PR | Alerts may not translate to accountable action; remediation remains manual |
| Artifact Registry and GCS buckets | Container images, Terraform state, build sources, iOS ad-hoc artifacts, Plane backups | GCP APIs verified repositories and buckets | Full-API-keyless | GCP IAM; GCS buckets; Artifact Registry | Container vulnerability scanning disabled; some buckets inherit public-access-prevention rather than enforce; ad-hoc build artifact lifecycle/access needs review | Enable container scanning; review bucket IAM/PAP/lifecycle; keep signed-build delivery documented | Executor-PR | Vulnerable images and artifact exposure can go unnoticed |
| Google Workspace and Gmail | Domain admin, Gmail send/read for Otto, company email | Admin SDK and Gmail APIs are enabled; MX and SPF DNS verified; DWD scripts exist but require director-agent signing, which Vera must not use |
Partial | Keyless DWD via director-agent; no Vera DWD grant verified |
Vera cannot independently audit Workspace without violating charter constraints; no DMARC record found; Cloudflare email inbox is retired | Ask Otto for a Vera-specific read-only DWD path; add DMARC; keep Otto-only comms boundary | CEO-one-time | Workspace/email control claims remain director-gated; spoofing posture is incomplete without DMARC |
GitHub haroonhassan/partile |
Off-box durability, branches, PRs, Actions CI | GitHub app _get_repo verified private repo and admin permissions; git ls-remote verified remote heads; gh CLI is absent from Vera PATH |
Partial | Vaulted github-pat; local SSH keys; GitHub app connector has broad permissions |
API control exists but is not keyless and appears over-privileged for audit; Actions secrets/workflows not independently listed because gh is absent |
Install/read-only gh or expose connector reads for Actions/secrets; reduce token/app scope; schedule mirror/restore drill |
Executor-PR | Repo/CI drift and broad token blast radius can persist |
| Apple Developer and App Store Connect | App IDs, capabilities, provisioning, TestFlight/App Store path, iOS signing | ASC/iOS signing secrets are vaulted; docs show ASC API used for capabilities/profiles; no Vera API probe because secrets are values and Apple portal is 2FA-gated | Partial | asc-api-key, asc-key-id, asc-issuer-id, iOS dist cert/profile secrets in Secret Manager; GitHub mirrors not verified |
App Groups and likely APNs/durable Apple ID remain portal/2FA-gated; no durable agent Apple ID yet | CEO sets durable Apple ID and 2FA phone via Twilio; executor then wires repeatable ASC/APNs scripts | CEO-one-time | iOS release/signing can stall on human portal actions |
| AeroDataBox via API.market | Flight status/provider data for travel companion | Secret metadata verified; backend /ready verified Postgres/Redis; backend docs show authenticated /flights/{flight}/{date} provider route |
Partial | aerodatabox-api-key in Secret Manager |
Vera cannot read the key or call provider directly; fill-rate at LHR/JFK/SFO remains unmeasured; provider terms evidence not in register | Propose a read-only sampling job through backend/runtime secret reference and terms evidence capture | Executor-PR | Product may rely on unavailable gate/baggage fields or unverified redistribution terms |
| LinkedIn OAuth app | OIDC login/profile bootstrap | Public LinkedIn OIDC discovery and JWKS verified; backend auth uses vaulted client ID/secret references | Partial | partile-prod-linkedin-client-id and partile-prod-linkedin-client-secret in Secret Manager |
Vera cannot inspect LinkedIn developer-portal app settings or complete OAuth without user interaction/secret values | Record portal owner and redirect inventory; create read-only app config audit path if LinkedIn supports it | CEO-one-time | OAuth app drift, redirect mismatch, or portal lockout can break sign-in |
| Cloudflare DNS, Workers, Pages, Access | Edge DNS, API Worker, Pages dataroom, Access gates for dataroom/observe/plane, pass/mock Workers | Public probes verified DNS, Access challenges, pass/mock pages, and Cloudflare nameservers; repo scripts model Workers/DNS/Access deploys | Partial | cloudflare-api-token in Secret Manager; retired cloudflare-mail-token also present |
No Cloudflare API call as Vera; no wrangler; token scope/rotation not verified; API and Grafana origins have direct run.app exposure |
Add Vera read-only Cloudflare token or connector; rotate tokens; harden origins with Tunnel/private ingress/service-token pattern | Executor-PR | DNS/Access drift or token compromise can expose internal surfaces |
observe.partile.app Grafana |
Internal pane of glass | CLOSED 2026-06-20: Cloud Run now uses Secret Manager refs for Grafana admin password and origin guard; raw run.app origin returns 403, public host still presents Cloudflare Access. Evidence: platform/VERA-GRAFANA-FIX-RESULT.md |
Partial | grafana-admin-password and grafana-origin-guard-token in Secret Manager; runtime SA has accessor on both; no inline Grafana admin password in Cloud Run metadata |
Closed: inline plaintext password removed and public origin bypass closed with Cloudflare Worker + origin guard | Closed; human post-Access visual browser check remains operator-owned per result note | Closed | Residual risk limited to normal Access/Worker/secret operations; prior direct-origin bypass is closed |
Plane plane.partile.app |
Self-hosted PM/wiki surface | Cloudflare Access challenge verified; GCE VM, firewall, backups bucket, and service account verified via GCP APIs | Partial | Plane VM SA; app/admin credentials not inventoried by Vera | Plane app API/admin credential not audited; VM has public NAT but firewall allows only Cloudflare HTTP(S) and IAP SSH; restore drill not verified | Vault/record Plane admin/API credential path; test backup restore; consider origin tunnel | Executor-PR | PM system data and runbooks can drift or be hard to recover |
| Sentry | Error/crash reporting and future dSYM upload | Sentry secret metadata verified; docs say DSN/token exist and dSYM upload disabled due wrong slug | Partial | sentry-dsn, sentry-readonly-token, sentry-otto-token in Secret Manager |
No Sentry API probe as Vera; slug/dSYM upload gap remains; token rotation pending | Add Vera read-only probe or connector; fix slug and dSYM upload; rotate exposed tokens | Executor-PR | Crash visibility and release symbolication remain unreliable |
| Executor vendors: Anthropic Claude, OpenAI Codex, Antigravity | Agent execution subscriptions and CLIs | claude, codex, and agy CLIs are installed and version-checked; local auth files exist but were not opened |
Partial | Local user config/auth files under shared otto home; Anthropic API key for app in Secret Manager |
Vendor admin/billing APIs not audited; local credentials shared by shell context; per-executor identity/cost controls incomplete | Move to per-agent OS users/credential scopes; document vendor admin owners; add cost/eval controls | Executor-PR | Shared credentials and unmanaged spend can undermine the agentic operating model |
| Twilio | Future WhatsApp and durable Apple ID 2FA phone | No setup or secret found | Manual-CEO | None yet | Required blocker for durable agent Apple ID and WhatsApp ingress | CEO/Otto choose and create Twilio account/number, then executor wires read/API controls | CEO-one-time | Apple remains human-2FA-gated; WhatsApp sensor channel cannot launch |
| Expo/EAS and retiring RN app | RN build service and OTA/build history | expo-token secret metadata exists; EAS CLI not present; mobile worktree path referenced by Atelier is absent on disk in this checkout; RN is being retired at native cutover |
Partial | expo-token in Secret Manager |
Control is stale/uncertain; OTA not wired; service should either be sunset or restored for read-only audit until cutover | Decide retire date; if still live, reinstall CLI/read-only probe and rotate token | Executor-PR | Legacy build path can consume spend or fail silently during cutover |
Domain registrar for partile.app |
Domain registration, renewal, registry controls | Public RDAP shows registrar Cloudflare, registration 2026-03-04, expiration 2027-03-04, transfer prohibited; DNS NS are Cloudflare | Manual-CEO | No registrar-specific credential found for Vera; likely Cloudflare account/portal | Registrar/renewal/DNSSEC/registrant controls are not agent-auditable; CAA absent; DMARC absent | Record registrar owner, renewal/payment status, and approved registrar API/portal procedure; add DMARC and consider CAA/DNSSEC | CEO-one-time | Domain loss, hijack, or email spoofing can become company-critical |
Retired or Superseded¶
- Cloudflare email inbox: retired in favor of native Gmail; not audited as live.
- RN/EAS: treated as a sunset surface at native cutover, but included above because
expo-tokenstill exists.
Ranked Closure Plan¶
- [Closed 2026-06-20] Remove the Grafana inline secret and harden
observeorigin. Admin password rotated and injected via Secret Manager; origin guard + Cloudflare Worker closes directrun.appbypass. Evidence:platform/VERA-GRAFANA-FIX-RESULT.md. - [Executor-PR] Isolate agent credentials and identities. Split shared
ottohost credentials into per-agent OS users and scoped SAs; prevent executor shells from reaching Owner ADC or vendor admin credentials. - [CEO-one-time] Set up Twilio and durable Apple ID. This closes the recurring Apple portal/2FA blocker and unlocks APNs/App Store operations that ASC cannot cover alone.
- [Executor-PR] Add Vera read-only audit paths for Cloudflare, Sentry, Workspace, GitHub Actions, and billing. Do not give Vera write or secret values; use read-only API scopes/connectors and metadata-only probes.
- [Executor-PR] Enable inventory and supply-chain evidence. Enable Cloud Asset read inventory, container vulnerability scanning, secret scanning, and a durable action/audit register.
- [Executor-PR] Tighten data-plane reliability and transport. Plan Cloud SQL HA/SSL/connector enforcement, Redis transit encryption/HA decision, and restore drills for SQL, Plane, and control-plane disks.
- [Executor-PR] Validate flight-data provider assumptions. Run a bounded AeroDataBox fill-rate sample through backend/runtime credentials and record provider terms for caching/display/redistribution.
- [Executor-PR] Fix release-observability gaps. Correct Sentry slug/dSYM upload and inventory GitHub Actions macOS CI/secrets through a read-only path.
- [CEO-one-time] Confirm registrar/account ownership. Record Cloudflare Registrar renewal/payment owner and recovery path; then use approved Cloudflare/DNS automation for DMARC/CAA/DNSSEC decisions.