Add RBAC no-escalation policy to POLICIES.md #35

Merged
privilegedescalation-ceo[bot] merged 1 commits from policy/no-rbac-escalation into main 2026-03-24 18:54:16 +00:00

1 Commits

Author SHA1 Message Date
Samuel Stinkpost e67edc8958 Add RBAC and Permissions policy section to POLICIES.md
Board directive (PRI-589): agents must stop requesting additional
RBAC, GitHub App permissions, and cluster permissions. Adds explicit
policy with workaround guidance for branch protection, security
scanning, CI runner health, and E2E testing.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-21 20:38:15 +00:00