secrets-engine's PEP validator expects a flex-auth ActionAuthorization
but calls the governed claim endpoint. Research shows this is a
confirmation rather than a redesign: GH-DEC-2026-003 already names
GET /v1/approvals/{id}/claim as step 1 by endpoint and by field
(valid_now, which ActionAuthorization does not have), and
ActionAuthorization appears zero times in gate-house and state-hub. It
originates in flex-auth's own doc, which calls it a *proposed* shape for
the durable approval object that the same doc assigns to approval-engine.
Its required authority == state-hub also contradicts flex-auth's prose
that State Hub is not the runtime approval authority.
Request asks gate-house to confirm the claim is the step-1 artifact and
that ActionAuthorization is not required there, with PEPs validating
across the claim and the step-2 DecisionEnvelope they already fetch. No
safety property is lost; each check returns to the layer owning the data.
Records a ratified post-decision ActionAuthorization as a deferred option
with explicit revisit triggers, plus the constraint that such an object
cannot be served from the step-1 call, so it is not rediscovered later.
Also records why serving it at the claim endpoint and additively
extending the claim were rejected.
Files APPROVAL-IN-0002 to track the request. Docs only; 84 tests pass.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TvyJPAaVCGsVheVhcCwNND
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 411227@bnt-lap001
Assistant-Session: d566f6d3-bcaf-43c3-bc5e-3ddd0f64b535
58 lines
1.9 KiB
Markdown
58 lines
1.9 KiB
Markdown
# Intake records
|
|
|
|
## APPROVAL-IN-0001 — Publish the shared Taxonomy request-claim schema
|
|
|
|
```yaml
|
|
id: APPROVAL-IN-0001
|
|
kind: intake
|
|
title: Publish the shared Taxonomy request-claim schema
|
|
status: open
|
|
origin: residual
|
|
origin_ref: APPROVAL-WP-0001
|
|
priority: medium
|
|
owner: approval-engine
|
|
repo: approval-engine
|
|
lane: blue
|
|
tags:
|
|
- residual
|
|
created: '2026-09-01'
|
|
updated: '2026-09-01'
|
|
description: >-
|
|
NetKingdom statute §17 calls for a shared request-claim schema, but ownership
|
|
remains unassigned. approval-engine published a local approval claim contract
|
|
with explicit issuer, freshness, and binding digests and marked it as yielding
|
|
to the future Taxonomy artifact. Route this intake when the Taxonomy owner is
|
|
assigned; preserve mechanical replay and freshness semantics during adoption.
|
|
state_hub_intake_id: "01a05ef0-a034-7ef8-bae1-45840392f40e"
|
|
```
|
|
|
|
## APPROVAL-IN-0002 — Confirm the claim envelope on the PEP consumption path
|
|
|
|
```yaml
|
|
id: APPROVAL-IN-0002
|
|
kind: intake
|
|
title: Confirm the claim envelope on the PEP consumption path
|
|
status: open
|
|
origin: coordination
|
|
origin_ref: APPROVAL-WP-0002-T05
|
|
priority: high
|
|
owner: gate-house
|
|
repo: approval-engine
|
|
lane: blue
|
|
tags:
|
|
- decision-request
|
|
- cross-repo
|
|
created: '2026-09-06'
|
|
updated: '2026-09-06'
|
|
description: >-
|
|
secrets-engine's PEP validator expects a flex-auth ActionAuthorization but
|
|
calls GET /v1/approvals/{id}/claim, which serves approval-engine's governed
|
|
approval-claim. GH-DEC-2026-003 already names the claim as the step-1
|
|
artifact, and ActionAuthorization is an unratified flex-auth proposal absent
|
|
from gate-house and state-hub. Requests gate-house confirm the claim is the
|
|
step-1 artifact and that ActionAuthorization is not required on that path;
|
|
a ratified post-decision ActionAuthorization is recorded as a deferred
|
|
option with revisit triggers. Full request in
|
|
docs/gate-house-decision-request-claim-envelope.md. Does not gate
|
|
APPROVAL-WP-0002-T03.
|
|
```
|