BOAS.DEV / VISKA
Status: In Development
‹ §06 Six-Month Plan
§07 · Rules & Ask

The rules are as important as the ship.

Everything below is architectural. Nothing is negotiated per-incident.

§07.1Security Posture
Surface
Pantheon operator
Every session kernel-sandboxed (Seatbelt). Credentials never enter LLM context — env-injected, opaque to agent. Vault in dedicated isolated repo (Hades). No other agent has vault access.
Surface
VPS · n8n
Hostinger VPS. Cloudflare Tunnel for ingress — no public IP exposed. Credentials in Docker env only, rotated on request.
Surface
Dashboard
CF Pages + CF Access. Private URL + email allow-list. No public read. R2 bucket is public-read for JSON artifacts only — no credentials, no PII.
Surface
Data
All Viska data on Viska-designated infrastructure — R2 bucket Viska account · SQLite on Viska VPS · codebase in Viska repo. Operator has operational access, not ownership.

Credential isolation is a fleet-wide law (Pantheon OPS.md §1). Not a per-client policy.

§07.2Risk Governance · Escalation Ladder
L1
Routine alert. Watchdog threshold hit (e.g. single-position drawdown > −2%).
Owner
Operator
Action
Note in session log, surface on Alerts page
Wake
No wake-up
L2
Attention alert. Stack exceeds soft limit (e.g. portfolio DD > −3% · sector > 20% · agent disagreement on open position).
Owner
PM + Operator in-session · Operator off-hours
Action
Decision card generated, PM reviews within session window
Channel
Slack · ntfy
L3
Emergency alert. Hard-rule breach (daily DD ≥ −5% · peak-to-trough ≥ −10% · broker API degraded · credential rotation failure · kill switch triggered).
Owner
PM immediately
Action
ntfy push + Pushover emergency to PM + Operator · session halted pending PM call
Channel
Pushover emergency (bypass silent)
KILL
Kill switch. Operator command halts all agents, voids open proposals, pauses all watchdog writes, marks session as halted in session-log. Single-command, documented, tested.

Escalation ladder is designed to fail loud. Silent failures are the enemy.

§07.3Ownership At Handoff
AssetCodeDataCredentialsHandoff state
Agent repos (Operator · Analyst · Risk · Execution)Viska day 1N/A — no data persistedN/A — env-injectedRepo transfer + runbook
Trading-spoke (n8n)Viska day 1R2 bucket = Viskan8n credential objects in Viska's instancen8n instance access + workflow JSON
Research corpusViska day 1Corpus in Viska infra (VPS or R2)N/ACorpus snapshot + ingest pipeline
Dashboard (React)Viska day 1R2 reads = Viska · dashboard displays onlyViska owns CF Pages projectCF Pages access + build pipeline
Documentation + runbooksViska day 1N/AN/ADoc repo + 3–5 day training

Nothing is licensed. Nothing is SaaS. Viska owns the artifact the day it ships.

§07.4Scope-Change Handling
Step 1
Proposal
Viska (or Boas) raises change with 3 fields: what shifts · what justifies · what it displaces.
Step 2
Impact
Boas returns: which milestone, which deps break, what timing effect. 48h non-urgent · 1 session urgent.
Step 3
Reprioritize
Decide: accept + displace (name the displaced) · defer (return-date) · decline (reason).
Step 4
Commit
Decision written into active STATE.md + next milestone's dispatch. No silent acceptance.
Step 5
Ship
Revised milestone delivers under usual acceptance criteria.

Scope change never silently slips the timeline. Impact is measured before commit.

§07.5What Boas Commits · The Reciprocal Side
Cadence
Weekly working session with Viska tech lead or CIO during active milestones. Session notes to Slack within 24h.
Incident
L3 escalation path includes Boas pager (Pushover emergency) first 90 days. Handed back to Viska ops at M6.
No drift
Scope-change flow (§4) is the only path. No unilateral additions. No silent cuts.
Credentials
No operator-session access to Viska credential stores. Hades is the only path.
Docs
Runbook + architecture doc refreshed at every milestone boundary. Handoff pack ready at M6 start.

Same commitments Boas makes to the rest of the Pantheon fleet, scoped to Viska.

§07.6Questions Back To Viska · The Ask
01
Who is Viska's technical owner?Name.
DecidesM6 handoff path (internal maintain vs contract) + pager on-call during 90-day transition
02
Where does the dashboard live?Private subdomain under Viska domain? Subdomain under boas.dev with CF Access?
DecidesCF account ownership, DNS, cert path
03
Where does compute live for M5?Viska's own infra? Iceland data-centre partnership (Atvinnustefna)? External cloud?
DecidesM5 scope + budget shape + policy alignment story
04
What is Viska's watchlist (M2/M3)?Tickers, jurisdictions, counterparties, macro themes.
DecidesSurveillance + alert + trading-universe scope
05
Which risk framework version is accepted?Default (1/5/20/8 · −5/−10 · enum-locked · no Kelly) or Viska-amended?
DecidesM3 risk rules + M5 signal thresholds
06
Past LP letters (M4 voice capture)?Last 4 quarters.
DecidesEditorial voice model + LP letter pipeline accuracy
07
Alert channel preferences?Slack channel ID · email distribution · SMS · ntfy topic · Pushover account.
DecidesAlert routing for L1/L2/L3
08
Credential deposit path?Designated credential holder at Viska, or Hades provisions and Viska rotates?
DecidesCredential governance during 6 months
09
Session cadence + attendees?Weekly standing? Who joins (CIO, PM, technical owner)?
DecidesSession protocol + notification cadence
10
Scope for the first in-session demo?What does Viska want to see working end-to-end at the first milestone acceptance review?
DecidesM1 acceptance criteria definition

Each answer unlocks a specific scope. Incomplete answers = we start with the answerable subset and loop back.

§07.7What We Will Not Do · The Anti-Scope
Not taking discretionary action on Viska capital. Every order is Viska-signed.
Not holding Viska credentials outside the credential-isolation architecture. No convenience exceptions.
Not shipping work that has not been accepted at a milestone boundary. No silent merges of out-of-scope features.

These are architectural, not negotiated per-project.

§07.8The Closer
"The fund owns the intelligence. The method owns the discipline. Neither is rented."
Everything above — the agents, the pipelines, the dashboard, the risk framework, the research corpus, the compute — lives under Viska's governance umbrella, not a vendor's terms of service.