Reference

Key Ceremony — Loop Review Checklist (Automation)

Version: 1.0 Date: 2026-06-22 Companion to: KEY-MANAGEMENT-LIFECYCLE.md (§8 rotation, §9 ceremony, §10 glossary, §12 ownership) Run mode: recurring automated review (e.g. Claude Code /loop), non-custodial — verify only


0. Purpose & guardrail

A recurring agent loop that continuously attests the key-management posture of the stack without ever touching a secret. It is the automation embodiment of the QA/Compliance verify lane in the Interactive Key Ceremony (KEY-MANAGEMENT-LIFECYCLE.md §9.7).

Non-custodial guardrail (hard rule). This loop verifies by side-effect — HTTP status, masked previews, fingerprints, file presence. It never reads, prints, or stores a secret value. Any check that would require seeing a key is out of scope and must be handed to the Deployment Officer (human). A finding is reported, never remediated by the loop (remediation = a privileged write = human-only, §9.1).

Cadence: daily lightweight scan; full review weekly; mandatory run after any deploy, scope change, or incident. Cadence triggers map to PMO ownership (§12.2).

Escalation routing (RACI, §12): WARN/FAIL → Compliance Officer (attest) + PMO (schedule remediation ceremony). PII-plane findings → DPO. Execution → Deployment Officer. A for residual risk → CISO.


1. Rotation cadence compliance (§8.1)

2. Audit-trail integrity (§9.4)

3. Exposure scan — .env / CLI / git (§9.6)

4. Least privilege & scope of compromise (§10, §11)

5. Roles, SoD & ownership (§9.7, §12)

6. Migration-specific health (§11)


7. Loop output contract

Each run emits a single fingerprint-only summary (safe to publish):

date:        <UTC>
run_by:      agent:loop-review
scope:       [cadence, audit, exposure, least-priv, roles, migration]
result:      PASS | WARN | FAIL
findings:    <count> ( <n> WARN, <n> FAIL )
escalated_to: [compliance?, pmo?, dpo?, deployment-officer?]
secrets_seen: 0            # MUST always be 0 — non-custodial invariant
next_run:    <UTC>

Stop conditions: any FAIL halts the loop and pages the routed owner (§12). The loop never attempts remediation — it opens a ceremony request and exits.


8. Example /loop invocation

/loop 1d Review docs/KEY-CEREMONY-LOOP-REVIEW.md against the live stack.
Verify by side-effect only — never read or print a secret. Emit the §7 output
contract; on any FAIL, stop and route per §12. secrets_seen must be 0.