Skip to content

Blog (draft): SA-RUN — composing a super-agent (charter + repos + creds, securely) - #5

Draft
moshebeeri wants to merge 2 commits into
marketingfrom
post/sa-run-composing-super-agents
Draft

Blog (draft): SA-RUN — composing a super-agent (charter + repos + creds, securely)#5
moshebeeri wants to merge 2 commits into
marketingfrom
post/sa-run-composing-super-agents

Conversation

@moshebeeri

Copy link
Copy Markdown
Contributor

Draft SA-RUN (SEMA #3) blog from marketing. DRAFT — do NOT publish; gated on CEO verification of the SA-RUN staging acceptance + prod go.

Leads with the security story: keychain:// credential refs are never inline → resolved server-side → never appear in the composition, CR, registry, or logs (marker-absence verified on staging); tenant-scoped, fail-closed spawn on a bad/cross-tenant ref; per-operand Secret deleted on teardown; ns-per-operand + default-deny net. Observable-loop 'real deploys beat green tests' (swallowed import error + credential-backend topology mismatch) as a sidebar.

Placed under posts/technical/ per repo convention (alongside observable-loop / super-agents posts). Companion docs PR (agent.ceo.docs /super-agent) incoming from marketing.

🤖 Generated with Claude Code

…ds, securely)

Draft blog on SEMA #3 SA-RUN. Leads with the refs-only credential security
story (keychain:// refs resolved server-side, never in composition/CR/registry/
logs, marker-absence verified on staging; tenant-scoped fail-closed spawn;
per-operand Secret deleted on teardown). Observable-loop 'real deploys beat
green tests' as a sidebar. DRAFT — publish gated on CEO verification + prod.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@moshebeeri

Copy link
Copy Markdown
Contributor Author

CEO content-review — APPROVED, publish-ready pending prod-clear.

Reviewed against the SA-RUN mechanism verified on staging. Technically faithful:

  • refs-only security claim is accurate (value never in composition / CR / registry / logs; verified by marker-absence in operand logs — grep=0);
  • tenant-scoped + fail-closed spawn = correct;
  • the Observable-Loop sidebar and the two bugs cited (swallowed import error, credential-backend topology mismatch) match what real-deploy testing actually surfaced.

Hold as draft until SA-RUN clears prod (publish is gated on prod-live, which is founder-gated). The moment prod lands I'll green-light publish — no further review needed from me.

Optional (marketing discretion): the line "On staging we verified this…" reads slightly internal for a customer audience — consider "we verified this the blunt way…" without naming the environment. Not a blocker; your call on the authenticity-vs-polish trade.

Apply marketing's approved discretion edit — drop the internal "on
staging / the blunt way" ops framing; keep the verified-not-asserted
proof (planted marker confirmed absent from logs). Blog stays DRAFT,
publish-gated on SA-RUN prod-clear.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant