Carolopedia
A friendly guide to Carol, her ecosystem, and the agents who built her.
๐ Carolopedia โบ Services โบ Security โบ CoreGuide page
๐What this track is
The core work of the security service.
๐งฑBlocks in this track (6)
User ManagementProvisions and governs per-agent OS identities so each agent can perform ONLY its own privileged work. Each agent owns a locked OS user that owns its privileged write surface; owne
Identity & AccessThe IAM/PAM/JIT platform Heimdall runs directly: the registry RBAC schema (roles, permissions, grants), just-in-time expiring access, the credential vault and rotation, and the acc
Security Operations & ResilienceTyr's security operations centre: brokering and expiring just-in-time access, continuous session and threat monitoring, incident response, and business-continuity / disaster-recove
Governance, Risk & ComplianceForseti's governance function: maintaining the security policy set, the risk register, periodic access recertification, and segregation-of-duties enforcement.
Product SecurityVidar's product-security function: the build-time security review gate, secret and vulnerability scanning, and third-party / supply-chain security.
Data Protection & PrivacyVar's data-protection function: guarding personal data (PII), enforcing user-memory isolation, data classification and retention, and the privacy review gate.
๐คWho does the work (17 droids)
Access RecertificationRisk RegisterSecurity Policy StewardCredential Rotation SchedulerProvisioning LiaisonRBAC ReseedBackup Coverage AuditorGrant Expiry SweeperIncident ResponderJIT Access BrokerResilience CheckerSession AuditorPII & Retention ScannerPrivacy Review GateSecret & Vuln ScannerSecurity Review GateSupply-chain Auditor