Protected command room
Security
Protected command room. Guardian state, holds, access, data protection and approvals.
2 Guardian gate(s) blocked and 4 waiting on an owner decision. All findings below are seeded examples. Pulse renders security state read-only and performs no security actions.
Gates blocked
2
Gates waiting
4
Active findings
4
Critical risks
1
Owner action 4 protected action(s) need your decision.
Guardian · seeded-findings · Stale · 2026-08-06 17:30 UTC · Likely — Findings are seeded. No scanner is connected.
Guardian return paths
Operational home is this Security room. Courtroom may consume GET /api/public/guardian-snapshot — Pulse remains operational Guardian; Judge does not live here.
Guardian remains authoritative. Pulse displays protected actions and never clears, bypasses or self-approves one.
Agent registry · Seeded — not connected
- Provider
- Cursor
- Capability
- Seeded
- Scanners
- Phase 1 not connected
- Workload
- 0
- Connected
- false
- Approvals
- Guardian for protected actions; Audit for close/verify
Guardian spine
Protected actions and their decision state. Pulse can display a hold; only the owner via Guardian can clear one.
Guardian gates
- Blocked 2
- Waiting 4
- Cleared 0
Active findings by severity
- Critical 0
- High 1
- Medium 2
- Low 0
11 recorded security events / day · Guardian gates + security findings
Owner decisions waiting
- Security
Change row-level security policy on the KleinHub AI hub database
An incorrect policy can expose one tenant's data to another, or lock every user out of the hub.
- Security
Publish the Pulse communications/watch rebuild
Publishing before the owner walkthrough would put an unreviewed watch layer in front of operators.
- Security
Attach a live mail provider to the Central Mail Office
Provider authorization grants live sending ability and touches customer-visible mail.
- Security
Apply pending migrations on the App Builder project
Migrations against a dirty worktree can apply unreviewed schema changes.
- Security
Deploy the NewsStand recovery build
Deploying before recovery observation completes could re-introduce the original fault.
- Security
Authorize a read-only BuildCommand feed
Feed authorization exposes run and worker metadata to Pulse.
Auth boundary review required for protected route gate
Seeded example: protected-route gating must be reviewed before any authenticated surface is added to a lane.
- Owner
- Security Specialist (seeded)
- Confidence
- MEDIUM
- Recurrence
- 0
- Last verified
- —
Next: Await Guardian review outcome. Pulse cannot close this finding.
kleinhub-main-build · mightyprophets-rgb/kleinhubai · specialist/reconciliation@7f292359 · PR — (seeded) · Security Specialist (seeded)
Dependency advisory recheck pending
Seeded example: a dependency upgrade was claimed complete and is waiting on independent Audit recheck.
- Owner
- Security Specialist (seeded)
- Confidence
- MEDIUM
- Recurrence
- 1
- Last verified
- —
Next: Audit recheck queue — independent verification required.
app-builder · mightyprophets-rgb/app-builder · main@wip-dirty · Security Specialist (seeded)
Secret-scanning capability seeded (no scanner connected)
Seeded capability marker only. No secret values are stored, displayed, or transmitted by Pulse.
- Owner
- Security Specialist (seeded)
- Confidence
- LOW
- Recurrence
- 0
- Last verified
- —
Next: Hold for Phase 2 — no scanner connection in Phase 1.
all-builds · mightyprophets-rgb/all-builds · main@seeded · Security Specialist (seeded)
Rollback readiness evidence gap
Seeded example: rollback instructions are not yet attached to the release evidence bundle.
- Owner
- Security Specialist (seeded)
- Confidence
- MEDIUM
- Recurrence
- 0
- Last verified
- —
Next: Collect rollback evidence; route to Evidence & Audit.
audit-assurance · mightyprophets-rgb/audit-assurance · docs-ahead@seeded · Security Specialist (seeded)
Guardian · seeded-findings · Stale · 2026-08-06 17:30 UTC · Likely — Findings are seeded. No scanner is connected.