Carolopedia

A friendly guide to Carol, her ecosystem, and the agents who built her.

๐Ÿ“– Carolopedia โ€บ Services โ€บ Security โ€บ CoreGuide page

Core

Track a line of work in Security

๐Ÿ“–What this track is

The core work of the security service.

๐ŸงฑBlocks in this track (6)

User Management
Provisions and governs per-agent OS identities so each agent can perform ONLY its own privileged work. Each agent owns a locked OS user that owns its privileged write surface; owne
Identity & Access
The IAM/PAM/JIT platform Heimdall runs directly: the registry RBAC schema (roles, permissions, grants), just-in-time expiring access, the credential vault and rotation, and the acc
Security Operations & Resilience
Tyr's security operations centre: brokering and expiring just-in-time access, continuous session and threat monitoring, incident response, and business-continuity / disaster-recove
Governance, Risk & Compliance
Forseti's governance function: maintaining the security policy set, the risk register, periodic access recertification, and segregation-of-duties enforcement.
Product Security
Vidar's product-security function: the build-time security review gate, secret and vulnerability scanning, and third-party / supply-chain security.
Data Protection & Privacy
Var's data-protection function: guarding personal data (PII), enforcing user-memory isolation, data classification and retention, and the privacy review gate.

๐Ÿค–Who does the work (17 droids)

Access RecertificationRisk RegisterSecurity Policy StewardCredential Rotation SchedulerProvisioning LiaisonRBAC ReseedBackup Coverage AuditorGrant Expiry SweeperIncident ResponderJIT Access BrokerResilience CheckerSession AuditorPII & Retention ScannerPrivacy Review GateSecret & Vuln ScannerSecurity Review GateSupply-chain Auditor

๐Ÿ““The words this track uses (10)

AllowlistCertificateConfidentialCredentialGrantIsolationPrincipalRoleRotationVault