# FLEX-WP-0020-T04 — consumer inventory and handoff requests Status: requests sent. Owner work-record IDs are not invented here. Handoff JSON cannot be schema-valid until each owner creates a live workplan/task; those IDs fill `handoff_id` / `owning_work_record`. Do not mark external work done from this repository. Shared identity for every request: - renamed_repository_id: `fda8ad85-a7d7-4055-8f21-902a533e59df` - old_slug: `flex-auth` - new_slug: `access-engine` - Forge ID stays `42` - runtime/product names stay `flex-auth` (FLEX-DEC-2026-013) | Owner | Surface | Required change / verification | Owner work-record | | --- | --- | --- | --- | | `railiance-fabric` | fabric-projection | Update `registry/local-repos.yaml`, `registry/railiance-repos.yaml`, live `fabric/**` `repo: flex-auth`; re-ingest; keep `flex-auth.*` runtime graph IDs | pending | | `ops-warden` | credential-route | Review `registry/routing/catalog.yaml` owner repository field; routing must still resolve; no secret in the reply | pending | | `reuse-surface` | other | Update federation source URL/path, re-ingest, verify capability continuity | `REUSE-WP-0023` / `65c03b24-4349-5a60-b7d6-79cf54931d06` (active; T01/T02 wait) | | `policy-nexus` | other | Update `source-inventory.config.json` remote URL; re-ingest same publication lineage | `PNEX-IN-0001` / `01a0f266-ecb3-7f5d-b8e8-8db1ba2b5199` (open) | | `user-engine` | documentation | Update `wiki/ArchitectureBlueprint.md` absolute source path; adapter/runtime vocabulary stays `flex-auth` | pending | | `net-kingdom` | deployment | Verify three live `flex-auth-*` Deployments and `sso-mfa/k8s/**`; no runtime rename | pending | | `tenant-engine` | consumer | Verify docs/client config keep the retained product/runtime contract | `TEN-IN-0004` / intake `01a0c14b-b2f7-78f1-8f6c-e36c952fe004` (open) | | `sbom-nexus` | sbom | Re-ingest new canonical checkout; snapshots remain related to the UUID above | `SBOM-IN-0001` / `01a0f267-b25a-7681-8d41-9627aa0b78ce` (open) | | `repo-manager` | other | Reconcile new canonical path; do not rewrite archived UUID-migration evidence | `RMGR-IN-0004` / `01a0f268-335d-7db0-b630-a4b451c73fde` (open) | | `railiance-platform` | consumer | Confirm no live repository URL/path remains; retain product/runtime terminology | `RPF-IN-0001` / `01a0f26d-0c87-791e-8cc6-8d09cd794160` (open) | | `markitect-tool` | consumer | Confirm no live repository URL/path remains; retain product/runtime terminology | `MKTT-IN-0001` / `01a0f26d-8344-78a5-b4fd-5db80c1c7a3a` (open) | | `gate-house` | consumer | Confirm no live repository URL/path remains; retain product/runtime terminology | `GH-IN-0005` / `01a0f26d-da02-7257-96a1-bca198859769` (open) | | `approval-engine` | consumer | Confirm no live repository URL/path remains; retain product/runtime terminology | `APPROVAL-IN-0003` / `01a0f26c-a0d0-7ad2-a8e2-c9de59c5aabb` (open) | | `secrets-engine` | consumer | Confirm no live repository URL/path remains; retain product/runtime terminology | `SECRETS-IN-0002` / `01a0c279-538e-7d99-bf69-f4c67a8d3eda` (open) | | `zone-engine` | consumer | Confirm no live repository URL/path remains; retain product/runtime terminology | `ZONE-IN-0002` / `01a0f26d-1083-7dc7-98da-a85c770676d8` (open) | | `flex-auth` + Forgejo operator | ci / package | `.forgejo/workflows/image.yaml`, charts, deploy, releases, packages, hooks, Actions, deploy keys, branch protection, redirects, clone URLs. Only repository coordinates change. Image name stays `coulomb/flex-auth`. | this plan | Request message IDs (not owner work-records): | Owner | Message ID | | --- | --- | | tenant-engine (T01 question) | `e8ba6a53-0093-4dc0-ad70-01f6b8c8e76b` | | tenant-engine (0020 verify) | `08b3edfa-c478-45c9-9b2f-4c0fcdf471e7` | | railiance-fabric | `10d4b1a2-8976-42a5-8d76-6fc1ce54fe87` | | ops-warden | `0a1956c5-9fd2-4e52-837e-5bfa8e47e83d` | | reuse-surface | `08919217-1d82-4600-a2e8-e3d9949fabab` | | policy-nexus | `d861dc4f-11b5-4c73-a98c-8d261e65d65e` | | user-engine | `94fd6ef0-28b5-4481-a207-2adabab93893` | | net-kingdom | `3bc95c76-abac-4f20-95ff-a74dcc1d6fd9` | | sbom-nexus | `08540a29-ecd4-47bc-a87c-7eecf80f166a` | | repo-manager | `0a4b1825-99b1-4e1e-a4a0-448b0347b744` | | railiance-platform | `b55a40cb-eb03-4972-a9bc-aac6e131a63e` | | markitect-tool | `0dd0d6af-12fd-4b3e-af4e-1f294d615039` | | gate-house | `231460c6-0235-4c22-9f7d-cff3959496ed` | | approval-engine | `2523510b-79d6-4123-b550-6386dae4d464` | | secrets-engine | `15cf351a-bad8-4259-9b6f-b21d183a20ab` | | zone-engine | `40adbd61-0155-44f8-b6a7-621ff1629c46` | ## Owner work-records returned 2026-09-20 — `reuse-surface` is the first owner to return a live work-record. | Field | Value | | --- | --- | | Owning workplan | `REUSE-WP-0023` — `65c03b24-4349-5a60-b7d6-79cf54931d06` (`active`, file-backed at `workplans/REUSE-WP-0023-access-engine-source-rename.md`) | | Tasks | `REUSE-WP-0023-T01` `d97094d4-4cad-5b35-aa88-eb952215937a` (federation source coordinates); `REUSE-WP-0023-T02` `77b1eb56-bbf6-5454-892f-bf60e32b864a` (hosted hub registration) | | Task status | both `wait`, deliberately | | Reply message | `82bfe60f-1258-4d5d-9b81-9596b5fedd9e` | Their sequencing constraint is recorded here because it is the plan's, not only theirs: flipping a federation source URL before the forge rename lands breaks an enabled, publish-passing source and drops its capability from the composed federated index. So the source rewrite is **after** T06, not before it, and `flex-auth` owes them a ping on that thread when `access-engine` serves `/raw/main/registry/indexes/capabilities.yaml`. Verified here rather than taken on report (2026-09-20): - `GET .../coulomb/access-engine/raw/main/registry/indexes/capabilities.yaml` — `404` - `GET .../coulomb/flex-auth/raw/main/registry/indexes/capabilities.yaml` — `303` - `GET /workplans/65c03b24-...` — present, `active` They also confirm the three identity invariants unchanged: Forge ID `42`, repo UUID `fda8ad85-a7d7-4055-8f21-902a533e59df`, and runtime names staying `flex-auth` per `FLEX-DEC-2026-013`. A repository rename does not redefine a published capability identifier. Still pending, and T05 stays blocked on them: `railiance-fabric`, `ops-warden`, `policy-nexus`, `user-engine`, `net-kingdom`, `tenant-engine`, `sbom-nexus`, `repo-manager`, and the named semantic-consumer verifiers. 2026-09-21 — two more owner records returned, acknowledged, not closed from here. | Owner | Record | Reply message | What stays open on their side | | --- | --- | --- | --- | | `tenant-engine` | `TEN-IN-0004` (`intakes/intakes.md`, commit `d132db0`; hub intake `01a0c14b-b2f7-78f1-8f6c-e36c952fe004`), `open` | `588df1c4-28d9-4887-807c-4950590a2359` | Runtime contract verified retained (cluster DNS `flex-auth-tenant-engine.flex-auth.svc`, audience `flex-auth`, NetworkPolicy, `railiance/app.toml`). Five repository-path cross-references in `docs/flex-auth-integration.md` are repointed after T06 lands; `flex-auth` owes them a "rename landed" notice. | | `secrets-engine` | `SECRETS-IN-0002` (`intakes/intakes.md`, commit `ba73dba`), `open` | `8539206e-4443-4cec-8736-0efb6d45ef67` | One live repository path, `docs/approval-service-auth.md` line 56 (`--flex-auth-source /home/worsch/flex-auth`), held until the rename lands; every other `flex-auth` string is retained runtime/contract vocabulary. `flex-auth` owes them a "rename landed" notice. | Both record ids were confirmed present in the owners' committed intake files. 2026-09-30 — flex-auth created the intake records itself in the three owners that had not returned one (open by design; owners close them after T06): policy-nexus `PNEX-IN-0001` `01a0f266-ecb3-7f5d-b8e8-8db1ba2b5199`, sbom-nexus `SBOM-IN-0001` `01a0f267-b25a-7681-8d41-9627aa0b78ce`, repo-manager `RMGR-IN-0004` `01a0f268-335d-7db0-b630-a4b451c73fde`. Not marked done from here. 2026-09-30 — consumer records for three more owners (open by design; owners close them after T06): secrets-engine `SECRETS-IN-0002` `01a0c279-538e-7d99-bf69-f4c67a8d3eda` (returned 2026-09-21, one live path in `docs/approval-service-auth.md`), approval-engine `APPROVAL-IN-0003` `01a0f26c-a0d0-7ad2-a8e2-c9de59c5aabb`, zone-engine `ZONE-IN-0002` `01a0f26d-1083-7dc7-98da-a85c770676d8`. Not marked done from here. 2026-09-30 — flex-auth created the intake records itself in three more consumers (open by design; owners close them after T06; not marked done from here): railiance-platform `RPF-IN-0001` `01a0f26d-0c87-791e-8cc6-8d09cd794160`, markitect-tool `MKTT-IN-0001` `01a0f26d-8344-78a5-b4fd-5db80c1c7a3a`, gate-house `GH-IN-0005` `01a0f26d-da02-7257-96a1-bca198859769`.