access-engine/.custodian-brief.md
custodian-sync 45bf036ee3
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-09-30:
  - update .custodian-brief.md for flex-auth

Assistant: claude-code
Assistant-Model: sonnet
Assistant-Process: 101414@bnt-lap001
Assistant-Session: 60b5a221-d435-42b9-b778-983c90c7eed6
2026-09-30 17:06:32 +02:00

59 lines
3.1 KiB
Markdown

<!-- custodian-brief: generated by fix-consistency — do not edit manually -->
# Custodian Brief — flex-auth
**Domain:** infotech
**Last synced:** 2026-09-30 15:06 UTC
**State Hub:** http://127.0.0.1:8000 *(adjust if running on a remote machine)*
## Active Workstreams
### The decision record has a declared emission guarantee and nothing that delivers it
Progress: 2/6 done | workplan_id: `84f5d9fe-b4c9-584a-b964-efe3e48af095`
**Open tasks:**
- ! 2. Register flex-auth as an audit-core sender `89661908`
*(wait: audit-core intake: sender registration, evidence_kind and heartbeat classes as cadence.yaml publishes them; gate is a registered sender.)*
- ! 4. Close G2 `423b3090`
*(wait: Closing G2 needs the silence-finding gate, which needs T05's sender and T06's reconciliation.)*
- ! 5. Heartbeat and drain to audit-core `14bd6648`
*(wait: Per-class heartbeat sender and drain need the registered sender from T02.)*
- ! 6. Reconciliation, profile check, and storage `bf92a951`
*(wait: Reconciliation compare needs audit-core GET /v1/reconciliation, which exists only once T02's sender is registered.)*
### Repository identity migration from flex-auth to access-engine
Progress: 4/11 done | workplan_id: `99a661a8-b36c-5c1c-b78b-1e8930bcd0a9`
**Open tasks:**
- ! 5. Renew State Hub preflight and record approval `86fecbb6`
*(wait: Preflight ok 2026-09-30 (operation 82b6e0ba-c25c-4ade-86c0-a6e7e22f6bf9, source 216df1f, private file not committed); needs the founder decision approving operation, commit, window, rollback limits and the confirm string. Rerun preflight if the source commit changes.)*
- ! 6. Execute the Forgejo repository rename `aa7ccd59`
*(wait: Human approval required before applying the Forge phase; preflight (T05) first.)*
- ! 7. Record the State Hub identity rebind `155041ed`
*(wait: state-hub owns the statehub-rebound mutation after the Forge phase (T06).)*
- ! 8. Establish and register a fresh canonical clone `c8afe078`
*(wait: Fresh access-engine clone and registration after the rebind (T07).)*
- ! 9. Verify identity, history, routes, builds, and deployments `fdb50a96`
*(wait: Relationship-checksum verification after T08; each external owner supplies its evidence.)*
- ! 10. Exercise rollback decision points `3dc49eb4`
*(wait: Continue/pause/rollback decision at each phase; needs T09 verification.)*
- ! 11. Soak, hand off residuals, and clean up the old checkout `46d8318b`
*(wait: Soak window after T10; destructive cleanup needs separate human approval.)*
### Admit scoped human review for the three T03 actions
Progress: 2/3 done | workplan_id: `954635b2-8377-5227-ab4f-10607b2a02c6`
**Open tasks:**
- ! Verify actual human review through the native service `9417d64a`
*(wait: Needs the operator's exact signed-in account and actual human acknowledgements; synthetic policy checks are not acceptance.)*
## Inbox Hygiene
**Missing thread_id:** 3 unread message(s) lack supersession chains.
---
## MCP Orientation (when available)
If the state-hub MCP server is reachable, call:
`get_domain_summary("infotech")`
This provides richer cross-domain context.
If the MCP call fails, use this file as your orientation source.