approval-engine/intakes/intakes.md
tegwick 564534dbcb Record GH-DEC-2026-005; strike the spent G3 revisit trigger
Gate House confirmed all three requested dispositions as GH-DEC-2026-005
(GH-IN-0002, closed); flex-auth accepted as FLEX-DEC-2026-006. The
approval-claim is the step-1 artifact, ActionAuthorization is not
required and MUST NOT be served from the claim endpoint, and a PEP
validates across the claim and the step-2 DecisionEnvelope. Gate House
recorded the split as doctrine rather than convenience -- a PIP must not
republish the PDP's decision -- and struck the provenance.authority ==
state-hub requirement explicitly. This engine's claim schema is
unchanged.

Correct the deferred option D trigger list. The G3 trigger was written
conditional on G3 being settled by composition; flex-auth reports
FLEX-WP-0019 closed it by adding a lifetime field to DecisionEnvelope on
2026-09-02, so a decision now states its own end without borrowing
ActionAuthorizationValidity. That was the one structural thing the bundle
did that the split does not, so the trigger is not merely spent -- it
resolved against ratification. Struck with reasons; a future revisit
needs a fresh argument. The trigger came from a stale row in a dated
2026-08-29 review record that flex-auth does not rewrite.

Also record the root cause of the bad authority constant: it came from a
flex-auth fixture, not prose. A contract whose examples contradict its
prose will be implemented as its examples.

Close APPROVAL-IN-0002. Docs only; 84 tests pass.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TvyJPAaVCGsVheVhcCwNND

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 411227@bnt-lap001
Assistant-Session: d566f6d3-bcaf-43c3-bc5e-3ddd0f64b535
2026-09-06 01:36:03 +02:00

2.6 KiB

Intake records

APPROVAL-IN-0001 — Publish the shared Taxonomy request-claim schema

id: APPROVAL-IN-0001
kind: intake
title: Publish the shared Taxonomy request-claim schema
status: open
origin: residual
origin_ref: APPROVAL-WP-0001
priority: medium
owner: approval-engine
repo: approval-engine
lane: blue
tags:
- residual
created: '2026-09-01'
updated: '2026-09-01'
description: >-
  NetKingdom statute §17 calls for a shared request-claim schema, but ownership
  remains unassigned. approval-engine published a local approval claim contract
  with explicit issuer, freshness, and binding digests and marked it as yielding
  to the future Taxonomy artifact. Route this intake when the Taxonomy owner is
  assigned; preserve mechanical replay and freshness semantics during adoption.
state_hub_intake_id: "01a05ef0-a034-7ef8-bae1-45840392f40e"

APPROVAL-IN-0002 — Confirm the claim envelope on the PEP consumption path

id: APPROVAL-IN-0002
kind: intake
title: Confirm the claim envelope on the PEP consumption path
status: closed
origin: coordination
origin_ref: APPROVAL-WP-0002-T05
priority: high
owner: gate-house
repo: approval-engine
lane: blue
tags:
- decision-request
- cross-repo
created: '2026-09-06'
updated: '2026-09-06'
resolution: >-
  Resolved 2026-09-06. Confirmed in full as GH-DEC-2026-005 (recorded at
  gate-house as GH-IN-0002 and closed) and accepted as FLEX-DEC-2026-006. The
  approval-claim is the step-1 artifact; ActionAuthorization is not required
  and MUST NOT be served from the claim endpoint; PEPs validate across the
  claim and the step-2 DecisionEnvelope. The provenance.authority ==
  state-hub requirement was struck explicitly. approval-engine's claim schema
  is unchanged. The deferred option D G3 revisit trigger is spent: G3 closed
  by adding a lifetime field, not by composition.
description: >-
  secrets-engine's PEP validator expects a flex-auth ActionAuthorization but
  calls GET /v1/approvals/{id}/claim, which serves approval-engine's governed
  approval-claim. GH-DEC-2026-003 already names the claim as the step-1
  artifact, and ActionAuthorization is an unratified flex-auth proposal absent
  from gate-house and state-hub. Requests gate-house confirm the claim is the
  step-1 artifact and that ActionAuthorization is not required on that path;
  a ratified post-decision ActionAuthorization is recorded as a deferred
  option with revisit triggers. Full request in
  docs/gate-house-decision-request-claim-envelope.md. Does not gate
  APPROVAL-WP-0002-T03.
state_hub_intake_id: "01a073e3-2338-7168-b69d-0f699769550f"