chore(consistency): regenerate WORK-RECORDS.md and repo index
Some checks are pending
CI Smoke / host-smoke (push) Waiting to run
CI Smoke / container-smoke (push) Waiting to run

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: sonnet
Assistant-Process: 270084@bnt-lap001
Assistant-Session: 350b785a-4dfd-4984-a852-dc6cc29bbc4f
This commit is contained in:
tegwick 2026-09-28 22:45:04 +02:00
parent 2b86530512
commit e66c9004d0
2 changed files with 615 additions and 36 deletions

View file

@ -2,9 +2,9 @@
"schema": "repo_manager.index.v1",
"slug": "flex-auth",
"repo_root": "/home/worsch/flex-auth",
"head_sha": "9f3e7e363a11f611e13d4d798dba575c56168521",
"observed_at": "2026-09-06T12:52:08.174834Z",
"source_fingerprint": "a19f5aa8b0f293bbd5d768adaa50c8afff5c0f0be3757e1b7af62ac791ab228f",
"head_sha": "2dfee5782ec9010758af9ba5a6f72d9fa0fe6234",
"observed_at": "2026-09-27T21:31:30.750263Z",
"source_fingerprint": "ae8eaabaf1593f4ffc27fd498848ff1e5b1bc7d6e7ec040908bd850af97d1fee",
"source_files": [
".repo-classification.yaml",
"INTENT.md",
@ -30,7 +30,18 @@
"workplans/FLEX-WP-0018-inbound-auth-corrections.md",
"workplans/FLEX-WP-0019-layer-model-conformance.md",
"workplans/FLEX-WP-0020-repository-identity-migration.md",
"workplans/FLEX-WP-0021-secrets-engine-consumer-policy-gate.md"
"workplans/FLEX-WP-0021-secrets-engine-consumer-policy-gate.md",
"workplans/FLEX-WP-0022-tenant-scope-coverage.md",
"workplans/FLEX-WP-0023-operator-caller-access-path.md",
"workplans/FLEX-WP-0024-decision-envelope-authenticity.md",
"workplans/FLEX-WP-0025-fact-versus-assertion.md",
"workplans/FLEX-WP-0026-openrouter-native-contract.md",
"workplans/FLEX-WP-0027-t03-human-review.md",
"workplans/FLEX-WP-0028-compact-sitting-review.md",
"workplans/FLEX-WP-0029-stance-register-second-edition.md",
"workplans/FLEX-WP-0030-boundary-declaration-cleanup.md",
"workplans/FLEX-WP-0031-decision-record-emission.md",
"workplans/FLEX-WP-0032-informed-decision-list-action.md"
],
"work_records": [
{
@ -1100,7 +1111,7 @@
{
"kind": "workplan",
"id": "FLEX-WP-0020",
"status": "proposed",
"status": "blocked",
"title": "Repository identity migration from flex-auth to access-engine",
"source_path": "workplans/FLEX-WP-0020-repository-identity-migration.md",
"uuid": "99a661a8-b36c-5c1c-b78b-1e8930bcd0a9",
@ -1110,7 +1121,7 @@
{
"kind": "task",
"id": "FLEX-WP-0020-T01",
"status": "todo",
"status": "done",
"title": "1. Capture immutable cleanliness and identity baseline",
"source_path": "workplans/FLEX-WP-0020-repository-identity-migration.md",
"uuid": "bb989019-50a7-5273-ba09-b2df2e2602a4",
@ -1120,7 +1131,7 @@
{
"kind": "task",
"id": "FLEX-WP-0020-T02",
"status": "todo",
"status": "done",
"title": "2. Prepare repository metadata and work-record frontmatter",
"source_path": "workplans/FLEX-WP-0020-repository-identity-migration.md",
"uuid": "102e9dc7-4724-5e80-84c4-092e6ecfbb2b",
@ -1130,7 +1141,7 @@
{
"kind": "task",
"id": "FLEX-WP-0020-T03",
"status": "todo",
"status": "done",
"title": "3. Decide product and runtime naming separately",
"source_path": "workplans/FLEX-WP-0020-repository-identity-migration.md",
"uuid": "5095ddbc-b69c-5a52-b97f-08fca9b610c3",
@ -1140,7 +1151,7 @@
{
"kind": "task",
"id": "FLEX-WP-0020-T04",
"status": "todo",
"status": "progress",
"title": "4. Inventory consumers and create owned handoffs",
"source_path": "workplans/FLEX-WP-0020-repository-identity-migration.md",
"uuid": "9bb138e1-5edb-5714-8d89-3b1b7039a7ce",
@ -1150,7 +1161,7 @@
{
"kind": "task",
"id": "FLEX-WP-0020-T05",
"status": "todo",
"status": "wait",
"title": "5. Renew State Hub preflight and record approval",
"source_path": "workplans/FLEX-WP-0020-repository-identity-migration.md",
"uuid": "86fecbb6-b008-5354-8d70-0f4ba5077a58",
@ -1220,7 +1231,7 @@
{
"kind": "workplan",
"id": "FLEX-WP-0021",
"status": "active",
"status": "finished",
"title": "secrets-engine consumer policy package and cluster-local pin",
"source_path": "workplans/FLEX-WP-0021-secrets-engine-consumer-policy-gate.md",
"uuid": "b01f655e-f71a-50ae-b110-178557f07c63",
@ -1250,7 +1261,7 @@
{
"kind": "task",
"id": "FLEX-WP-0021-T03",
"status": "progress",
"status": "done",
"title": "3. Confirm the digest join against a real decision record",
"source_path": "workplans/FLEX-WP-0021-secrets-engine-consumer-policy-gate.md",
"uuid": "8f7e5cdd-777e-5f54-9b92-c72b79f65672",
@ -1260,7 +1271,7 @@
{
"kind": "task",
"id": "FLEX-WP-0021-T04",
"status": "wait",
"status": "done",
"title": "4. Stand up the `flex-auth-secrets-engine` pin",
"source_path": "workplans/FLEX-WP-0021-secrets-engine-consumer-policy-gate.md",
"uuid": "f4e8709a-65dd-5172-97ae-e7c3432afb22",
@ -1270,13 +1281,567 @@
{
"kind": "task",
"id": "FLEX-WP-0021-T05",
"status": "wait",
"status": "done",
"title": "5. Hand the pin coordinates back and close",
"source_path": "workplans/FLEX-WP-0021-secrets-engine-consumer-policy-gate.md",
"uuid": "f0828871-fd65-5d8c-adfd-28b13fedd2b0",
"parent_id": "FLEX-WP-0021",
"extra": {}
},
{
"kind": "workplan",
"id": "FLEX-WP-0022",
"status": "finished",
"title": "Tenant scoping is unstated in tenant-engine and untested in two more packages",
"source_path": "workplans/FLEX-WP-0022-tenant-scope-coverage.md",
"uuid": "804c588c-f47a-50c4-bdd7-51b24bbf9539",
"parent_id": null,
"extra": {
"depends_on": [
"FLEX-WP-0021"
]
}
},
{
"kind": "task",
"id": "FLEX-WP-0022-T01",
"status": "done",
"title": "1. Get the intended tenant relation from tenant-engine",
"source_path": "workplans/FLEX-WP-0022-tenant-scope-coverage.md",
"uuid": "a84dcee5-9426-5b30-8dd3-f4c076d00174",
"parent_id": "FLEX-WP-0022",
"extra": {}
},
{
"kind": "task",
"id": "FLEX-WP-0022-T02",
"status": "done",
"title": "2. Encode the relation, or record that there is none",
"source_path": "workplans/FLEX-WP-0022-tenant-scope-coverage.md",
"uuid": "712ac826-845f-54bd-8446-f11258d21eb4",
"parent_id": "FLEX-WP-0022",
"extra": {}
},
{
"kind": "task",
"id": "FLEX-WP-0022-T03",
"status": "done",
"title": "3. Vary tenant in the two suites that hold it constant",
"source_path": "workplans/FLEX-WP-0022-tenant-scope-coverage.md",
"uuid": "3058f171-99d2-526b-a1bb-bd7aed87d10a",
"parent_id": "FLEX-WP-0022",
"extra": {}
},
{
"kind": "workplan",
"id": "FLEX-WP-0023",
"status": "finished",
"title": "Operator caller access path and caller identity in the decision record",
"source_path": "workplans/FLEX-WP-0023-operator-caller-access-path.md",
"uuid": "ad011f92-786c-51ad-b3f6-c06ad77e7af7",
"parent_id": null,
"extra": {}
},
{
"kind": "task",
"id": "FLEX-WP-0023-T01",
"status": "done",
"title": "1. Create the ServiceAccount the deployed binding already names",
"source_path": "workplans/FLEX-WP-0023-operator-caller-access-path.md",
"uuid": "10e5a40c-f142-55b9-ab15-fc77c0064ce0",
"parent_id": "FLEX-WP-0023",
"extra": {}
},
{
"kind": "task",
"id": "FLEX-WP-0023-T02",
"status": "done",
"title": "2. Run the positive and negative tests and return the receipts",
"source_path": "workplans/FLEX-WP-0023-operator-caller-access-path.md",
"uuid": "79a8d82d-777c-5462-b49d-098f4b7a3b9c",
"parent_id": "FLEX-WP-0023",
"extra": {}
},
{
"kind": "task",
"id": "FLEX-WP-0023-T03",
"status": "done",
"title": "3. Flip `callerAuth.mode` to enforce",
"source_path": "workplans/FLEX-WP-0023-operator-caller-access-path.md",
"uuid": "8117c9d8-6efa-5ccf-8ed4-4da2519c3de3",
"parent_id": "FLEX-WP-0023",
"extra": {}
},
{
"kind": "task",
"id": "FLEX-WP-0023-T04",
"status": "done",
"title": "4. Record the authenticated caller in the decision record",
"source_path": "workplans/FLEX-WP-0023-operator-caller-access-path.md",
"uuid": "c0e4f31a-cc42-5bd2-b938-d140ecd52e1a",
"parent_id": "FLEX-WP-0023",
"extra": {}
},
{
"kind": "task",
"id": "FLEX-WP-0023-T05",
"status": "done",
"title": "5. Report the gap to gate-house as a v0.8 finding",
"source_path": "workplans/FLEX-WP-0023-operator-caller-access-path.md",
"uuid": "d685abfc-cf86-50c8-ad5e-2c04e1531ddd",
"parent_id": "FLEX-WP-0023",
"extra": {}
},
{
"kind": "workplan",
"id": "FLEX-WP-0024",
"status": "finished",
"title": "Sign the decision envelope: the response channel is unauthenticated",
"source_path": "workplans/FLEX-WP-0024-decision-envelope-authenticity.md",
"uuid": "90577acd-6910-548d-a13e-1dbfdfb8ed27",
"parent_id": null,
"extra": {}
},
{
"kind": "task",
"id": "FLEX-WP-0024-T01",
"status": "done",
"title": "1. Publish the stance and stop publishing bare Service names",
"source_path": "workplans/FLEX-WP-0024-decision-envelope-authenticity.md",
"uuid": "b8fad80d-5c44-5e26-a632-5096e0c0f3c5",
"parent_id": "FLEX-WP-0024",
"extra": {}
},
{
"kind": "task",
"id": "FLEX-WP-0024-T02",
"status": "done",
"title": "2. Choose the signature shape and key custody",
"source_path": "workplans/FLEX-WP-0024-decision-envelope-authenticity.md",
"uuid": "5482f3cd-36cb-55e0-8c52-0ca2340ed4d7",
"parent_id": "FLEX-WP-0024",
"extra": {}
},
{
"kind": "task",
"id": "FLEX-WP-0024-T03",
"status": "done",
"title": "3. Implement signing and verification",
"source_path": "workplans/FLEX-WP-0024-decision-envelope-authenticity.md",
"uuid": "041612ea-1be4-5997-8c32-49f8bcc50855",
"parent_id": "FLEX-WP-0024",
"extra": {}
},
{
"kind": "task",
"id": "FLEX-WP-0024-T04",
"status": "done",
"title": "4. Report the gap to gate-house",
"source_path": "workplans/FLEX-WP-0024-decision-envelope-authenticity.md",
"uuid": "82d6b75e-e2c6-5e3d-a897-fbdfb7c9094e",
"parent_id": "FLEX-WP-0024",
"extra": {}
},
{
"kind": "workplan",
"id": "FLEX-WP-0025",
"status": "finished",
"title": "A policy cannot tell a registry fact from a caller assertion",
"source_path": "workplans/FLEX-WP-0025-fact-versus-assertion.md",
"uuid": "f9a657ce-67b4-5d25-9933-e0fcb2c20b1c",
"parent_id": null,
"extra": {}
},
{
"kind": "task",
"id": "FLEX-WP-0025-T01",
"status": "done",
"title": "1. Decide the shape",
"source_path": "workplans/FLEX-WP-0025-fact-versus-assertion.md",
"uuid": "05c6a85d-ee3d-5875-bea4-e9a9c5382e2e",
"parent_id": "FLEX-WP-0025",
"extra": {}
},
{
"kind": "task",
"id": "FLEX-WP-0025-T02",
"status": "done",
"title": "2. Audit every package for ceilings read from undeclared keys",
"source_path": "workplans/FLEX-WP-0025-fact-versus-assertion.md",
"uuid": "fc61c8a7-347b-59d2-b6a6-a72c5c1cdb08",
"parent_id": "FLEX-WP-0025",
"extra": {}
},
{
"kind": "task",
"id": "FLEX-WP-0025-T03",
"status": "done",
"title": "3. Make the review obligation enforceable rather than written",
"source_path": "workplans/FLEX-WP-0025-fact-versus-assertion.md",
"uuid": "8ee5baf9-b364-5d3e-9c49-d0c9eb014c10",
"parent_id": "FLEX-WP-0025",
"extra": {}
},
{
"kind": "workplan",
"id": "FLEX-WP-0026",
"status": "finished",
"title": "Resolve OpenRouter access contract and update native PDP",
"source_path": "workplans/FLEX-WP-0026-openrouter-native-contract.md",
"uuid": "e458b337-2373-5fe6-9136-880f45604183",
"parent_id": null,
"extra": {}
},
{
"kind": "task",
"id": "FLEX-WP-0026-T01",
"status": "done",
"title": "Resolve the caller versus credential-owner contract",
"source_path": "workplans/FLEX-WP-0026-openrouter-native-contract.md",
"uuid": "d96a05c9-7ea7-53d7-87c9-ffeb19edd5f1",
"parent_id": "FLEX-WP-0026",
"extra": {}
},
{
"kind": "task",
"id": "FLEX-WP-0026-T02",
"status": "done",
"title": "Promote and verify the current native PDP contract",
"source_path": "workplans/FLEX-WP-0026-openrouter-native-contract.md",
"uuid": "d85b9e4d-9f9f-5bec-add0-91f434f76f49",
"parent_id": "FLEX-WP-0026",
"extra": {}
},
{
"kind": "workplan",
"id": "FLEX-WP-0027",
"status": "blocked",
"title": "Admit scoped human review for the three T03 actions",
"source_path": "workplans/FLEX-WP-0027-t03-human-review.md",
"uuid": "954635b2-8377-5227-ab4f-10607b2a02c6",
"parent_id": null,
"extra": {}
},
{
"kind": "task",
"id": "FLEX-WP-0027-T01",
"status": "done",
"title": "Implement the explicit group and exact-record mandate",
"source_path": "workplans/FLEX-WP-0027-t03-human-review.md",
"uuid": "7b5af88b-2630-5f94-a085-78180690e08c",
"parent_id": "FLEX-WP-0027",
"extra": {}
},
{
"kind": "task",
"id": "FLEX-WP-0027-T02",
"status": "done",
"title": "Deploy the isolated caller-bound policy",
"source_path": "workplans/FLEX-WP-0027-t03-human-review.md",
"uuid": "129568a0-cb1c-5f7b-8f5d-f44f1d2bcfff",
"parent_id": "FLEX-WP-0027",
"extra": {}
},
{
"kind": "task",
"id": "FLEX-WP-0027-T03",
"status": "wait",
"title": "Verify actual human review through the native service",
"source_path": "workplans/FLEX-WP-0027-t03-human-review.md",
"uuid": "9417d64a-308c-566f-af29-217c5c45d294",
"parent_id": "FLEX-WP-0027",
"extra": {}
},
{
"kind": "workplan",
"id": "FLEX-WP-0028",
"status": "finished",
"title": "Admit scoped human review for the seven compact sitting memos",
"source_path": "workplans/FLEX-WP-0028-compact-sitting-review.md",
"uuid": "f7491b94-9f0e-5e5c-a03c-72e70d210807",
"parent_id": null,
"extra": {}
},
{
"kind": "task",
"id": "FLEX-WP-0028-T01",
"status": "done",
"title": "Compile the seven-record sitting mandate",
"source_path": "workplans/FLEX-WP-0028-compact-sitting-review.md",
"uuid": "c9c28feb-d735-55a1-adc5-d229ab630f59",
"parent_id": "FLEX-WP-0028",
"extra": {}
},
{
"kind": "task",
"id": "FLEX-WP-0028-T02",
"status": "done",
"title": "Deploy the isolated caller-bound policy",
"source_path": "workplans/FLEX-WP-0028-compact-sitting-review.md",
"uuid": "2d9be9d6-b8a0-5018-b5f5-524e72fc6239",
"parent_id": "FLEX-WP-0028",
"extra": {}
},
{
"kind": "workplan",
"id": "FLEX-WP-0029",
"status": "finished",
"title": "The stance register outgrew the review that read it: five rows, and the divergence was ruled rather than resolved",
"source_path": "workplans/FLEX-WP-0029-stance-register-second-edition.md",
"uuid": "5a11099d-b492-535c-af88-c334db5e8ee6",
"parent_id": null,
"extra": {}
},
{
"kind": "task",
"id": "FLEX-WP-0029-T01",
"status": "done",
"title": "1. Record that Finding 1 was ruled, not resolved",
"source_path": "workplans/FLEX-WP-0029-stance-register-second-edition.md",
"uuid": "5a7ed269-974f-5c6a-8e80-e9aa0077f8aa",
"parent_id": "FLEX-WP-0029",
"extra": {}
},
{
"kind": "task",
"id": "FLEX-WP-0029-T02",
"status": "done",
"title": "2. Re-run Finding 2 across five rows",
"source_path": "workplans/FLEX-WP-0029-stance-register-second-edition.md",
"uuid": "991ebb94-cdc4-574a-ba60-f8960ec885fc",
"parent_id": "FLEX-WP-0029",
"extra": {}
},
{
"kind": "task",
"id": "FLEX-WP-0029-T03",
"status": "done",
"title": "3. Close out Finding 3 against the current file",
"source_path": "workplans/FLEX-WP-0029-stance-register-second-edition.md",
"uuid": "6dd2c9fd-8ad9-54d6-8fb1-f24e44189f00",
"parent_id": "FLEX-WP-0029",
"extra": {}
},
{
"kind": "task",
"id": "FLEX-WP-0029-T04",
"status": "done",
"title": "4. Propagate the row count and state the version trigger",
"source_path": "workplans/FLEX-WP-0029-stance-register-second-edition.md",
"uuid": "4dbadd0b-7670-5837-90c9-6201c10479d7",
"parent_id": "FLEX-WP-0029",
"extra": {}
},
{
"kind": "workplan",
"id": "FLEX-WP-0030",
"status": "finished",
"title": "The layer declaration pins a version it should not, and four security-relevant peers do not declare at all",
"source_path": "workplans/FLEX-WP-0030-boundary-declaration-cleanup.md",
"uuid": "abe60f5f-79cc-5857-b9e8-a46bed704279",
"parent_id": null,
"extra": {}
},
{
"kind": "task",
"id": "FLEX-WP-0030-T01",
"status": "done",
"title": "1. Make the declaration version-agnostic",
"source_path": "workplans/FLEX-WP-0030-boundary-declaration-cleanup.md",
"uuid": "016ab184-e814-591b-938b-24ff9ace5ede",
"parent_id": "FLEX-WP-0030",
"extra": {}
},
{
"kind": "task",
"id": "FLEX-WP-0030-T02",
"status": "done",
"title": "2. Update SCOPE.md and assess the gaps",
"source_path": "workplans/FLEX-WP-0030-boundary-declaration-cleanup.md",
"uuid": "224cd214-7226-5286-9794-a8a6d36c25e5",
"parent_id": "FLEX-WP-0030",
"extra": {}
},
{
"kind": "task",
"id": "FLEX-WP-0030-T03",
"status": "done",
"title": "3. Publish the boundaries review",
"source_path": "workplans/FLEX-WP-0030-boundary-declaration-cleanup.md",
"uuid": "7d45a3d6-d4a7-556a-8607-58086f74a998",
"parent_id": "FLEX-WP-0030",
"extra": {}
},
{
"kind": "task",
"id": "FLEX-WP-0030-T04",
"status": "done",
"title": "4. Raise the conflicting and unclear boundaries for resolution",
"source_path": "workplans/FLEX-WP-0030-boundary-declaration-cleanup.md",
"uuid": "70786e6d-02f2-5a90-8640-247ba377d9a4",
"parent_id": "FLEX-WP-0030",
"extra": {}
},
{
"kind": "task",
"id": "FLEX-WP-0030-T05",
"status": "done",
"title": "5. Make the survey reproducible",
"source_path": "workplans/FLEX-WP-0030-boundary-declaration-cleanup.md",
"uuid": "a695c139-b831-55a2-b015-445742ee043c",
"parent_id": "FLEX-WP-0030",
"extra": {}
},
{
"kind": "task",
"id": "FLEX-WP-0030-T06",
"status": "done",
"title": "6. Fix the validator: four tokens, case folded, scope stated",
"source_path": "workplans/FLEX-WP-0030-boundary-declaration-cleanup.md",
"uuid": "23af18ea-93da-5bd2-9511-e4fce7475dc3",
"parent_id": "FLEX-WP-0030",
"extra": {}
},
{
"kind": "task",
"id": "FLEX-WP-0030-T07",
"status": "done",
"title": "7. Publish the per-class emission inventory and register G2 as a dated gap",
"source_path": "workplans/FLEX-WP-0030-boundary-declaration-cleanup.md",
"uuid": "55af504c-482d-5c1a-97e3-7034912308f5",
"parent_id": "FLEX-WP-0030",
"extra": {}
},
{
"kind": "task",
"id": "FLEX-WP-0030-T08",
"status": "done",
"title": "8. Rule whether resource.system follows the repository or the runtime",
"source_path": "workplans/FLEX-WP-0030-boundary-declaration-cleanup.md",
"uuid": "cbf8531e-1aa9-5bc4-9f63-ecbbcf987083",
"parent_id": "FLEX-WP-0030",
"extra": {}
},
{
"kind": "workplan",
"id": "FLEX-WP-0031",
"status": "blocked",
"title": "The decision record has a declared emission guarantee and nothing that delivers it",
"source_path": "workplans/FLEX-WP-0031-decision-record-emission.md",
"uuid": "84f5d9fe-b4c9-584a-b964-efe3e48af095",
"parent_id": null,
"extra": {}
},
{
"kind": "task",
"id": "FLEX-WP-0031-T01",
"status": "done",
"title": "1. Decide emission atomicity",
"source_path": "workplans/FLEX-WP-0031-decision-record-emission.md",
"uuid": "2dbc225f-d762-537b-9a24-ab2b17fc2fa2",
"parent_id": "FLEX-WP-0031",
"extra": {}
},
{
"kind": "task",
"id": "FLEX-WP-0031-T02",
"status": "wait",
"title": "2. Register flex-auth as an audit-core sender",
"source_path": "workplans/FLEX-WP-0031-decision-record-emission.md",
"uuid": "89661908-ca9a-5e4a-a0a5-62d1a9e02568",
"parent_id": "FLEX-WP-0031",
"extra": {}
},
{
"kind": "task",
"id": "FLEX-WP-0031-T03",
"status": "done",
"title": "3. Durable outbox and the release rule",
"source_path": "workplans/FLEX-WP-0031-decision-record-emission.md",
"uuid": "a59603d5-8954-5b05-b1a0-b143c82e439b",
"parent_id": "FLEX-WP-0031",
"extra": {}
},
{
"kind": "task",
"id": "FLEX-WP-0031-T05",
"status": "wait",
"title": "5. Heartbeat and drain to audit-core",
"source_path": "workplans/FLEX-WP-0031-decision-record-emission.md",
"uuid": "14bd6648-11da-53d7-a512-027005bd4772",
"parent_id": "FLEX-WP-0031",
"extra": {}
},
{
"kind": "task",
"id": "FLEX-WP-0031-T06",
"status": "wait",
"title": "6. Reconciliation, profile check, and storage",
"source_path": "workplans/FLEX-WP-0031-decision-record-emission.md",
"uuid": "bf92a951-3b69-59dd-8907-f6748c91a264",
"parent_id": "FLEX-WP-0031",
"extra": {}
},
{
"kind": "task",
"id": "FLEX-WP-0031-T04",
"status": "wait",
"title": "4. Close G2",
"source_path": "workplans/FLEX-WP-0031-decision-record-emission.md",
"uuid": "423b3090-1b72-58fd-9353-5c907c7683bb",
"parent_id": "FLEX-WP-0031",
"extra": {}
},
{
"kind": "workplan",
"id": "FLEX-WP-0032",
"status": "finished",
"title": "Admit a list action for the informed-decision overview without handing the scope to the consumer",
"source_path": "workplans/FLEX-WP-0032-informed-decision-list-action.md",
"uuid": "ab21b09f-2cb5-5d31-866d-11f02f13f3d8",
"parent_id": null,
"extra": {}
},
{
"kind": "task",
"id": "FLEX-WP-0032-T01",
"status": "done",
"title": "1. Record the decision",
"source_path": "workplans/FLEX-WP-0032-informed-decision-list-action.md",
"uuid": "f741d47e-50b9-5eb1-81d9-ffec847be77a",
"parent_id": "FLEX-WP-0032",
"extra": {}
},
{
"kind": "task",
"id": "FLEX-WP-0032-T02",
"status": "done",
"title": "2. Compile compact-sitting v3",
"source_path": "workplans/FLEX-WP-0032-informed-decision-list-action.md",
"uuid": "a24fc5cf-f663-5338-97da-169af7fb47fb",
"parent_id": "FLEX-WP-0032",
"extra": {}
},
{
"kind": "task",
"id": "FLEX-WP-0032-T03",
"status": "done",
"title": "3. Fixtures and the exercise receipt",
"source_path": "workplans/FLEX-WP-0032-informed-decision-list-action.md",
"uuid": "984f11f4-6ec9-5f7d-840b-4dee2e121212",
"parent_id": "FLEX-WP-0032",
"extra": {}
},
{
"kind": "task",
"id": "FLEX-WP-0032-T04",
"status": "done",
"title": "4. Publish and hand back",
"source_path": "workplans/FLEX-WP-0032-informed-decision-list-action.md",
"uuid": "2a296df6-1d39-5b3e-9312-8e791a6ccbd0",
"parent_id": "FLEX-WP-0032",
"extra": {}
},
{
"kind": "decision",
"id": "FLEX-DEC-2026-001",
@ -1508,7 +2073,7 @@
"status": "resolved",
"title": "A claim cannot name the request that carries it: publish approval_binding_digest",
"source_path": "decisions/decisions.md",
"uuid": null,
"uuid": "4f0a0de3-1b21-48d1-b157-53bc1f6d03d8",
"parent_id": null,
"extra": {
"record": {
@ -1531,7 +2096,8 @@
"decided_by": "flex-auth (access-engine / PDP)",
"rationale": "secrets-engine found that an approval pdp_digest recorded at issue time can never equal the request_digest of a request that carries the claim inside its hashed context, because the claim is part of the context that is hashed. The circularity is structural, not a fixture defect, and it made GH-DEC-2026-008 unimplementable for exactly the dual-control case it was written for. flex-auth owns the canonical request digest, so the resolution is ours. Publishing binding.approval_binding_digest: the same digest computed with context.approval removed, present only when a claim was carried, stable across attaching the claim, and therefore nameable by a pdp_digest recorded at issue. Deliberately additive rather than a redefinition: request_digest keeps covering the claim and remains the replay identity, because two requests differing only in which approval was presented must not share a replay identity when one allows and the other denies dual_control_required. Tests assert the two functions disagree on a claim-bearing request and agree on a claim-free one.",
"created": "2026-09-06T12:52:06.960329Z",
"updated": "2026-09-06T12:52:06.960329Z"
"updated": "2026-09-06T12:52:06.960329Z",
"state_hub_decision_id": "4f0a0de3-1b21-48d1-b157-53bc1f6d03d8"
}
}
},
@ -1610,17 +2176,30 @@
"events": [
{
"type": "repo.command.applied",
"command": "repo.work.create_decision",
"operation": "create",
"correlation_id": "e76636be-b773-46de-9bef-eb962c96cf2b",
"kind": "decision",
"id": "FLEX-DEC-2026-007",
"git_sha": null,
"command": "repo.work.update_workplan",
"operation": "update",
"correlation_id": "768db689-1cb9-4afb-ac11-353cf0c00d07",
"workplan_id": "FLEX-WP-0020",
"workplan_uuid": "99a661a8-b36c-5c1c-b78b-1e8930bcd0a9",
"changes": {
"status": "blocked",
"updated": "2026-09-27"
},
"git_sha": "2dfee5782ec9010758af9ba5a6f72d9fa0fe6234",
"files_touched": [
"decisions/decisions.md"
"workplans/FLEX-WP-0020-repository-identity-migration.md"
],
"expected_head_sha_before": "c3d4f69329b661cb9daaa17c9cba0d00a288a6b8",
"source": "repo-manager",
"emitted_at": "2026-09-06T12:52:08.174961Z"
"emitted_at": "2026-09-27T21:31:30.751083Z"
},
{
"type": "repo.work.indexed",
"correlation_id": "768db689-1cb9-4afb-ac11-353cf0c00d07",
"kind": "workplan",
"id": "FLEX-WP-0020",
"source_path": "workplans/FLEX-WP-0020-repository-identity-migration.md",
"emitted_at": "2026-09-27T21:31:30.751149Z"
}
]
}