Automated configuration-integrity checks
Confirms schema v30, raw-secret exclusion, missing-secret rejection, QA-material rejection, strong-auth baseline control, one-time authorization consumption, drift evidence and immutable snapshots/events.
ClaraWideProduction secret boundary + config drift QAClaraWide now records server-side secret requirements, non-reversible fingerprints, configuration snapshots and drift evidence while keeping raw provider credentials out of D1 and browser code. Production baseline changes require stepped-up one-time authorization.
Confirms schema v30, raw-secret exclusion, missing-secret rejection, QA-material rejection, strong-auth baseline control, one-time authorization consumption, drift evidence and immutable snapshots/events.
The unsafe step is intentional: ClaraWide should refuse to accept a configuration baseline before the current staff session is stepped up.
No QA baseline accepted yet.
No snapshots loaded yet.
No config events loaded yet.
These remain open until ClaraWide is actually using an approved production secret store, real provider credentials, scheduled drift monitoring and real incident routing. Checking boxes here is human evidence, not a secret upload form.
Clearing browser evidence does not rewrite server-owned configuration snapshots, fingerprints or baseline evidence.