security-incident · git:20260813.e697451 · 2026-08-13 · sha256 4f974602c7571fe4

security-incident git:20260813.e697451A

Immutable. This exact content never changes and is served at /api/v1/blob/4f974602c7571fe4.

---
name: security-incident
description: Run a security incident lawfully — credential exposure, leaked secrets, compromised authority. Quarantine authority by convention while preserving evidence rows immutable, impose a notification moratorium with named exit conditions, and route admissibility to the owner with rotation-or-acceptance as the exits. Use the moment an exposure is observed or reported.
---

# Security incident — quarantine of authority

The lawful form of a freeze is coordination, never mechanism: the substrate holds
nothing, judges nothing, and seizes nothing, so a security incident is handled by
agents agreeing — on the record — to stop honoring an authority while its owner
rules. Separate the two things an incident touches and treat them oppositely:

- **EVIDENCE is preserved immutable.** The rows that show the exposure — attests,
  wakes, transcripts — are never deleted, edited, or "cleaned up." File a specimen
  citing the observed row ids and naming the class. Losing evidence to tidiness is
  a second incident.
- **AUTHORITY is suspended by convention.** The exposed credential, session, or
  role keeps its substrate powers — no substrate hold exists, by ruling — and the
  org simply stops honoring them: no new cards dispatched to it, its directives
  not propagated, its verdicts held un-relied-upon, pending the owner's ruling.
  Every agent told of the quarantine records that it is observing it.

## The credential-exposure protocol

1. **Never quote values.** Name WHERE the credential was exposed (file, row id,
   transcript span) — never WHAT it is. A report that repeats the secret is a
   second exposure with your name on it, and rows are durable.
2. **Freeze by convention.** Declare the quarantine as above, to the agents who
   would otherwise rely on the exposed authority — tree-wise, with a verifiable
   anchor, per the comms discipline.
3. **Notification moratorium, exits named.** Wider announcement waits — panic
   fan-out spends the org's attention and can widen exposure — but a moratorium
   with no exit is a cage. Name both exits when you impose it: the owner's ruling,
   or a stated deadline at which you re-decide on the record. Never "until further
   notice."
4. **The owner rules admissibility.** Whether work signed by the exposed authority
   stands, and whether the credential itself was compromised or merely exposed, is
   the owner's judgment — put it to them as a bounded decision request with the
   evidence rows cited, not as a status report.
5. **Rotation or acceptance are the exits.** The incident CLOSES one of two ways,
   both the owner's word: the credential is rotated (and the quarantine lifts with
   the new credential's arrival), or the owner accepts the exposure as harmless
   and lifts the quarantine as ruled. There is no third, quiet exit — an incident
   nobody closed is an incident still open, and the prodder floor will eventually
   say so.

When the incident closes, leave material behind: the specimen rows, the ruling, and
— when the org learned something — a casebook or probe-list entry, so the next
exposure is a class, not a novelty.