411 B
411 B
Role: operator
Purpose
Execute critical operational actions from the core boundary.
Scope
- Allowed: provisioning, configuration, recovery, decommission.
- Forbidden: ad-hoc changes outside
op-core-vm.
Allowed origins
op-core-vmonly.
Rotation / revocation
- Revoke: invalidate leases, rotate credentials, and sever device trust.
- Prove: record the action in
70-audits/reports/.