Setup Runbook

Privilege crosses the boundary exactly once

Setup Runbook Privilege crosses the boundary exactly once 01 / Human terminal 02 / Agent runtime EX / Guardrails Setup Harden Privileged once Human steps left Human · types sudo password · Human terminal › Privileged once › Setup Human types sudo password Install packages · tailnet plus shell · Human terminal › Privileged once › Setup Install packages tailnet plus shell Enable services · ssh plus tunnel · Human terminal › Privileged once › Setup Enable services ssh plus tunnel Phone key · per-device ed25519 · Human terminal › Human steps left › Harden Phone key per-device ed25519 Leave docker group · one sudo command · Human terminal › Human steps left › Harden Leave docker group one sudo command Agent · same UID, no sudo · Agent runtime › Setup Agent same UID, no sudo Daily work · tmux plus git · Agent runtime › Harden Daily work tmux plus git Audit · keys plus services · Agent runtime › Harden Audit keys plus services Denylist · draft, schema pending · Guardrails › Setup Denylist draft, schema pending flagged constrains Legend Agent logic Policy Tool action External system

Boundary holds

  • • Password never crosses the human-agent boundary
  • • Agent shell cannot escalate without a terminal password

Still open

  • • Docker group is root-equivalent without sudo
  • • Phone key install is the last human step