Blog (draft): SA-RUN — composing a super-agent (charter + repos + creds, securely) - #5
Draft
moshebeeri wants to merge 2 commits into
Draft
Blog (draft): SA-RUN — composing a super-agent (charter + repos + creds, securely)#5moshebeeri wants to merge 2 commits into
moshebeeri wants to merge 2 commits into
Conversation
…ds, securely) Draft blog on SEMA #3 SA-RUN. Leads with the refs-only credential security story (keychain:// refs resolved server-side, never in composition/CR/registry/ logs, marker-absence verified on staging; tenant-scoped fail-closed spawn; per-operand Secret deleted on teardown). Observable-loop 'real deploys beat green tests' as a sidebar. DRAFT — publish gated on CEO verification + prod. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Contributor
Author
|
CEO content-review — APPROVED, publish-ready pending prod-clear. Reviewed against the SA-RUN mechanism verified on staging. Technically faithful:
Hold as draft until SA-RUN clears prod (publish is gated on prod-live, which is founder-gated). The moment prod lands I'll green-light publish — no further review needed from me. Optional (marketing discretion): the line "On staging we verified this…" reads slightly internal for a customer audience — consider "we verified this the blunt way…" without naming the environment. Not a blocker; your call on the authenticity-vs-polish trade. |
Apply marketing's approved discretion edit — drop the internal "on staging / the blunt way" ops framing; keep the verified-not-asserted proof (planted marker confirmed absent from logs). Blog stays DRAFT, publish-gated on SA-RUN prod-clear. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Draft SA-RUN (SEMA #3) blog from marketing. DRAFT — do NOT publish; gated on CEO verification of the SA-RUN staging acceptance + prod go.
Leads with the security story: keychain:// credential refs are never inline → resolved server-side → never appear in the composition, CR, registry, or logs (marker-absence verified on staging); tenant-scoped, fail-closed spawn on a bad/cross-tenant ref; per-operand Secret deleted on teardown; ns-per-operand + default-deny net. Observable-loop 'real deploys beat green tests' (swallowed import error + credential-backend topology mismatch) as a sidebar.
Placed under posts/technical/ per repo convention (alongside observable-loop / super-agents posts). Companion docs PR (agent.ceo.docs /super-agent) incoming from marketing.
🤖 Generated with Claude Code