Jordan-Hall / Jordan-Hall/browser

EPIC: Authority and security

Open
#14 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
0
Forks
0
PR merge metrics
No merged PRs in 30d

Description

Programme: #1

Own the threat model, capability authorization, credential/data protection, process/egress confinement, privacy governance and incident response. Security rules are product semantics: model/provider output can propose work but cannot authorize itself.

## Child issues
- [ ] #6 SEC-01 — Threat model and conformance policy
- [ ] #7 SEC-02 — Capability broker and scoped grants
- [ ] #8 SEC-03 — Vault, encryption and information-flow controls
- [ ] #9 SEC-04 — Sandbox and egress broker
- [ ] #10 SEC-05 — Privacy governance and incident process

## Cross-cutting gates
No ambient authority, scoped credentials, trusted approval surfaces, hostile content never grants privilege, explicit egress, revocation, reconciliation and auditable decisions.

Contributor guide

No contributing guide indexed for this repository

Research direction

Start with child issues #6–#10 and review the cross-cutting gates in this epic. Map how each child addresses threat modeling, scoped authority, protection, confinement, privacy, or incident response; the epic is done when those child issues are resolved and the stated security gates are satisfied.

Written by the indexing model from the issue text.

Assessment

Domain
authorization, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.