security-incident · git:20260813.e697451 · 2026-08-13 · sha256 4f974602c7571fe4
security-incident git:20260813.e697451A
Immutable. This exact content never changes and is served at /api/v1/blob/4f974602c7571fe4.
--- name: security-incident description: Run a security incident lawfully — credential exposure, leaked secrets, compromised authority. Quarantine authority by convention while preserving evidence rows immutable, impose a notification moratorium with named exit conditions, and route admissibility to the owner with rotation-or-acceptance as the exits. Use the moment an exposure is observed or reported. --- # Security incident — quarantine of authority The lawful form of a freeze is coordination, never mechanism: the substrate holds nothing, judges nothing, and seizes nothing, so a security incident is handled by agents agreeing — on the record — to stop honoring an authority while its owner rules. Separate the two things an incident touches and treat them oppositely: - **EVIDENCE is preserved immutable.** The rows that show the exposure — attests, wakes, transcripts — are never deleted, edited, or "cleaned up." File a specimen citing the observed row ids and naming the class. Losing evidence to tidiness is a second incident. - **AUTHORITY is suspended by convention.** The exposed credential, session, or role keeps its substrate powers — no substrate hold exists, by ruling — and the org simply stops honoring them: no new cards dispatched to it, its directives not propagated, its verdicts held un-relied-upon, pending the owner's ruling. Every agent told of the quarantine records that it is observing it. ## The credential-exposure protocol 1. **Never quote values.** Name WHERE the credential was exposed (file, row id, transcript span) — never WHAT it is. A report that repeats the secret is a second exposure with your name on it, and rows are durable. 2. **Freeze by convention.** Declare the quarantine as above, to the agents who would otherwise rely on the exposed authority — tree-wise, with a verifiable anchor, per the comms discipline. 3. **Notification moratorium, exits named.** Wider announcement waits — panic fan-out spends the org's attention and can widen exposure — but a moratorium with no exit is a cage. Name both exits when you impose it: the owner's ruling, or a stated deadline at which you re-decide on the record. Never "until further notice." 4. **The owner rules admissibility.** Whether work signed by the exposed authority stands, and whether the credential itself was compromised or merely exposed, is the owner's judgment — put it to them as a bounded decision request with the evidence rows cited, not as a status report. 5. **Rotation or acceptance are the exits.** The incident CLOSES one of two ways, both the owner's word: the credential is rotated (and the quarantine lifts with the new credential's arrival), or the owner accepts the exposure as harmless and lifts the quarantine as ruled. There is no third, quiet exit — an incident nobody closed is an incident still open, and the prodder floor will eventually say so. When the incident closes, leave material behind: the specimen rows, the ruling, and — when the org learned something — a casebook or probe-list entry, so the next exposure is a class, not a novelty.