From 6a189c8dd55c48d5289e1f3e72d0971909719773 Mon Sep 17 00:00:00 2001 From: codex Date: Mon, 17 Aug 2026 22:01:54 +0200 Subject: [PATCH] =?UTF-8?q?ADAPTIVE-WP-0009=20T05:=20Q2=20decided=20?= =?UTF-8?q?=E2=80=94=20decline=20co-signature,=20bind=20via=20artifact?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Bernd's call: option C without the scoped-veto bridge. A veto would only protect existing claim-bearing tiers and there are none, so not being live is what makes the direct move safe. Records a named revisit trigger. Co-Authored-By: Claude Opus 5 --- ...PTIVE-WP-0009-tenancy-posture-alignment.md | 28 +++++++++++++++---- 1 file changed, 22 insertions(+), 6 deletions(-) diff --git a/workplans/ADAPTIVE-WP-0009-tenancy-posture-alignment.md b/workplans/ADAPTIVE-WP-0009-tenancy-posture-alignment.md index 680e9a7..03ceb63 100644 --- a/workplans/ADAPTIVE-WP-0009-tenancy-posture-alignment.md +++ b/workplans/ADAPTIVE-WP-0009-tenancy-posture-alignment.md @@ -231,12 +231,28 @@ availability** until finding 1 is resolved; say so rather than inventing a level `tenant-engine` owns which plan a tenant holds; this repo owns the terms — state that split when replying so the seam is recorded. -**Q2 — placement co-signature.** Recommend **accepting, scoped**: co-signer means -a veto on placement policy changes that would invalidate an existing tier's -recorded minimum — not a seat in per-workload placement operations. §8.2's -reasoning holds and the stated alternative is real (placement decided purely on -operational grounds then constrains what can be sold), but unscoped co-signature -on an ops decision puts a commercial repo in a ticket queue. Bernd's call. +**Q2 — placement co-signature. Decided 2026-08-17 by Bernd: decline the +signature, bind via artifact instead.** + +adaptive-pricing publishes tier minimums as typed constraints (T02/T03) and asks +railiance-platform to validate placement against them. Ownership stays single; +the check runs every time rather than when someone remembers to route it. §8.2's +concern is right — placement decided purely on operational grounds does constrain +what can be sold — but a signature is the wrong instrument for a constraint that +is machine-checkable, and tier minimums are machine-checkable by construction. + +**No interim veto.** A scoped veto was considered and dropped: its only purpose +would be protecting existing claim-bearing tiers, and there are none. Not being +live is what makes the direct move safe. + +**Named revisit trigger** — if a tier carrying an isolation, availability or +retention claim is drafted before the constraint artifact lands, reopen this +decision rather than assume it. Declining must not be open-ended. + +Accept the P ladder, the triggers and §8.1's monitoring obligation +unconditionally. Caveat to raise: §8.1 says triggers MUST be monitored and never +says by whom; if that defaults to adaptive-pricing it is a standing obligation on +a repo with no on-call. Propose it is railiance-platform's. Reply on the State Hub to message `6d5293ca-4f69-46a6-a78e-b469e626b83d`.