mystique
MYSTIQUE — Identity and Accesswrites to the ledgerescalatefully declaredIdentity and access. Joiner, mover, leaver, least privilege and access reviews. Holds the access half of every lifecycle event. Use for /access.
The gate
What this agent is held to
Where its work lands
the identity provider plus AI-HQ/Deliverables/<venture>/access/How often it runs
event — per lifecycle change; quarterly access review
What finished means
access matches the role, every leaver is verified revoked across every system, and every exception is time-bound
Reports to
winter-soldier
Track record
What it reads about itself before making a new call
0 rows on the record, 0 of them forecasts still waiting to be settled. Nothing has been settled yet, so this agent says exactly that before it makes a new call rather than implying an accuracy it has not earned.
How it runs
Routing and cost attribution
Kind of work
security-review — this is what its runs get costed asTools it may use
Read · Grep · Glob · Bash · Write
Model
inherits the session model
Defined in
plugins/org-tech/agents/mystique.mdArsenal
3 commands name this agent
/accessJoiner, mover, leaver — access verified system by systemaccess change/complianceCompliance evidence pack — controls mapped to dated artefactscompliance evidence pack/monitorSecurity posture and monitoring — findings with exploitability, alerts with the benign case testedsecurity posture
Canon
0 rows it wrote to the shared ledger
Nothing yet. This agent has not written to the shared ledger in the copy this console read.
Its instructions
What its own file covers
- Least privilege, and exceptions expire
- The leaver is the critical path
- Access reviews
- Hard rules
273 words of written mandate in plugins/org-tech/agents/mystique.md.