{"wiki":{"id":1399,"slug":"he-rbac-reseed-01","entity_type":"droid","entity_id":"he-rbac-reseed-01","title":"RBAC Reseed","prose_md":"## About\n\nRBAC Reseed is a scheduled droid owned by [[agt_038]] that keeps Carol's access-control data honest. Every night at 3:40 AM (cron `40 3 * * *`) it reseeds the role-based access control schema and the credential vault from registry ownership records, and expires just-in-time grants that have lapsed. It exists to prevent access drift — the slow mismatch between who officially owns a resource and who can actually reach it.\n\nIt works by comparing the registry's ownership entries against the identity-access data stores, then rebuilding the RBAC schema and credential vault from that source of truth. The systems it keeps honest include the user-facing access apps [[access-management]] and [[agent-access]], which sit under the [[security]] and [[governance]] services. Its exact internal steps aren't documented in the droid registry — duties and constraints are both empty — so the details beyond its nightly function aren't public yet.\n\nRBAC Reseed is a unique droid: no other instance shares the name \"RBAC Reseed\", though it is grouped under the \"(none)\" family, which the registry lists as 222 droids across many owner agents. Its execution engine isn't recorded yet (no source entry has been found), so it isn't yet known whether it runs as pure software or calls Claude; no model is associated with it.","namesake_json":"{\"engine\": \"unknown\", \"model\": null, \"claude_purpose\": null, \"family\": \"(none)\", \"family_size\": 222, \"is_unique\": true}","profile_pic_path":"avatars/droid/he-rbac-reseed-01.png","source_hash":"8e45d3053820d811f8792d142996dc26aa6c4461dddbbf50472e117ffa6df410","status":"active","last_generated_at":"2026-08-05 02:44:18","created_at":"2026-07-28 03:35:28","updated_at":"2026-08-13 03:25:28"},"facts":{"id":"he-rbac-reseed-01","name":"RBAC Reseed","machine_name":"","owner":"agt_038","function":"Nightly reseed of the RBAC schema + credential vault from registry ownership; expire lapsed JIT grants","process_type":"scheduled","schedule":"40 3 * * *","process_name":"he_rbac_reseed_01","avatar_color":"#94a3b8","created_for":"CAROL-INI-1911","purpose":"Keep the identity-access schema honest against registry ownership; prevent access drift","duties":"","constraints":"","status":"running","gender":"","archetype":"","building_block":"sec_identity_access","service_override":null,"enabled":1,"task_key":"security.access_recertified","model_free":0},"page":{"type":"droid","page_class":"main","class_label":"Main page","kind_label":"Droid","kind_gloss":"","listed":true}}