approval-engine/workplans
tegwick 2fdb01d42a Disable the live operator client, keep its custody
key-cape reports the withdrawal came too late: approval-engine-operator
was provisioned in the 2026-09-09 custody window and is wired into a pod.
A live credential that can create and approve approvals, presented by
nobody, is a worse resting state than either extreme.

As requesting owner: disable, do not delete. CCR-2026-0018 stands so it
is restorable under the narrowing constraint once a presenter exists. A
recorded expiry was rejected — it promises to act later on a capability
that is dangerous now, guarding exactly the case where nobody is
watching.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HyybaE7DUXrWYrhbnESCTe

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1275879@bnt-lap001
Assistant-Session: eb464208-f821-41b2-bc5a-a6c33d92a8ad
2026-09-10 20:49:36 +02:00
..
APPROVAL-WP-0001-v07-alignment-and-engine-spine.md Finish approval engine spine 2026-09-01 23:45:48 +02:00
APPROVAL-WP-0002-production-readiness-and-consumer-adoption.md Disable the live operator client, keep its custody 2026-09-10 20:49:36 +02:00