Create a private policy document
The verified course job was deleted after capture, returning the shared cron roster to thirteen. Keep your personal review job.
Turn inventory into policy
Your page must tell another operator what runs, who triggers it, what it reaches, what it costs, and how to stop it.
Run the six-part inventory
armaraos agent list --json
armaraos cron list --json
armaraos channel list
armaraos vault list
armaraos skill list
armaraos config show
Answer three questions per item
| Question | Policy answer |
|---|---|
| Who triggers it? | Human, clock, channel, another agent, or device. |
| What can it reach? | Files, shell, network, credentials, contacts, or other agents. |
| What does it cost? | Measured provider cost, free-tier use, or explicitly unknown. |
Record accepted caveats
- Budget cap fields are not relied upon; provider limits are the ceiling.
- The audit chain is invalid at sequence 513.
- Broad agent profiles require procedural controls.
- Pairing is disabled and cannot return a device roster.
Copy the emergency section
Include the five-rung containment ladder and the mission, cron, Hand, channel, and agent identifier lookup commands.
Run the human handover test
Ask what runs without you, what stops unexpected spending first, and where a provider key is revoked. Rewrite any missing answer.
Schedule the review and verify JSON
armaraos cron create <AGENT_UUID> "0 10 1 * *" "Remind me to re-run my six inventory commands and re-read my operating policy." --name policy-review
armaraos cron list --json
Create may print Failed: ? even when the row exists. Inspect before retrying.
Check it / hand the page to someone else
Can they answer all three questions?
Your personal install should retain its monthly policy-review job. The shared course job was removed after proof.
The policy is a map of your credentials and attack surface. Keep it private and review storage permissions.