flex-auth/WORK-RECORDS.md

115 lines
11 KiB
Markdown
Raw Normal View History

# Work Records — flex-auth
> Generated by `statehub fix-consistency` (CUST-WP-0061-T04, work-record
> stage 3). Do not edit by hand — edit the source file/block listed for
> each record and re-run fix-consistency to refresh this index. Archived
> workplans are omitted; closed decisions/intakes/engagements stay listed
> so recently-resolved work is still visible. [auto]
| Kind | ID | Status | Lane | Source |
| --- | --- | --- | --- | --- |
| workplan | FLEX-WP-0001 | done | — | workplans/FLEX-WP-0001-repo-intent-and-architecture-baseline.md |
| workplan | FLEX-WP-0002 | completed | — | workplans/FLEX-WP-0002-standalone-policy-as-code-core.md |
| workplan | FLEX-WP-0003 | completed | — | workplans/FLEX-WP-0003-markitect-consumer-integration.md |
| workplan | FLEX-WP-0004 | completed | — | workplans/FLEX-WP-0004-delegated-pdp-and-directory-adapters.md |
| workplan | FLEX-WP-0005 | done | — | workplans/FLEX-WP-0005-foundations-and-topaz-alignment.md |
| workplan | FLEX-WP-0006 | finished | — | workplans/FLEX-WP-0006-ops-warden-ssh-signing-policy-gate.md |
| workplan | FLEX-WP-0007 | finished | — | workplans/FLEX-WP-0007-ops-warden-policy-gate-production-deployment.md |
| workplan | FLEX-WP-0008 | finished | — | workplans/FLEX-WP-0008-tenant-engine-consumer-integration.md |
| workplan | FLEX-WP-0009 | finished | — | workplans/FLEX-WP-0009-user-engine-production-policy-service.md |
Authorize tenant-engine lifecycle actions (FLEX-WP-0010) Extend the tenant-engine write-API policy package with tenant.update, tenant.retire, and tenant.reactivate, the three actions TEN-WP-0005 introduced. Until now every lifecycle mutation resolved to deny unknown_action, blocking TEN-WP-0005-T05 production rollout. - policy_package.md: three actions in valid_actions and frontmatter; CARING capabilities extended with EditAny/Archive/Restore - protected_system_manifest.yaml, subject_manifest.yaml, and the rebuilt registry_snapshot.json carry all seven actions - docs/tenant-engine-action-vocabulary.md documents the HTTP surfaces - 8 new fixture pairs and 5 new Rego tests, including action-drift guards (tenant.retired, tenant_update -> unknown_action) T02 decision, recorded in policy_package.md: tenant.retire does NOT get stricter authorization yet. With one service subject and no assurance claim in the CheckRequest there is nothing stricter to check, and a condition the sole caller always satisfies would falsely read as separate control. Retirement is reversible and non-destructive. Revisit on KEY-WP-0005 assurance claims or a second operator subject. Verified: 11/11 Rego tests, 16/16 fixtures, go test ./... green, gofmt and go vet clean. End-to-end against a live serve with a real tenant-engine through the unmodified FlexAuthWriteAuthorizer: update 6176c39c2f4d7b15, retire 8a801b8ee8455080, reactivate c64cf3713cecd970 all allow; unregistered actor denied unknown_subject (59d3e99c6416be89, 403 write_denied). Handoff revision for TEN-WP-0005-T05: package tenant-engine.write-api.mutate v1 (ready, caring-0.4.0-rc2). Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-10 20:52:10 +02:00
| workplan | FLEX-WP-0010 | finished | — | workplans/FLEX-WP-0010-tenant-lifecycle-policy-actions.md |
| workplan | FLEX-WP-0011 | finished | — | workplans/FLEX-WP-0011-railiance-staged-promotion-overlay.md |
| workplan | FLEX-WP-0012 | finished | — | workplans/FLEX-WP-0012-credential-grant-authorization-surface.md |
| workplan | FLEX-WP-0013 | finished | — | workplans/FLEX-WP-0013-restore-seven-action-tenant-engine-pin.md |
| workplan | FLEX-WP-0014 | finished | — | workplans/FLEX-WP-0014-tenant-guardrail-policy-actions.md |
| workplan | FLEX-WP-0015 | finished | — | workplans/FLEX-WP-0015-tenancy-posture-conformance.md |
| workplan | FLEX-WP-0016 | finished | — | workplans/FLEX-WP-0016-ops-warden-incluster-policy-pin.md |
| workplan | FLEX-WP-0017 | active | — | workplans/FLEX-WP-0017-action-bound-authorization-contract.md |
| workplan | FLEX-WP-0018 | finished | — | workplans/FLEX-WP-0018-inbound-auth-corrections.md |
| task | FLEX-WP-0001-T001 | done | — | workplans/FLEX-WP-0001-repo-intent-and-architecture-baseline.md |
| task | FLEX-WP-0001-T002 | done | — | workplans/FLEX-WP-0001-repo-intent-and-architecture-baseline.md |
| task | FLEX-WP-0001-T003 | done | — | workplans/FLEX-WP-0001-repo-intent-and-architecture-baseline.md |
| task | FLEX-WP-0001-T004 | done | — | workplans/FLEX-WP-0001-repo-intent-and-architecture-baseline.md |
| task | FLEX-WP-0002-T001 | done | — | workplans/FLEX-WP-0002-standalone-policy-as-code-core.md |
| task | FLEX-WP-0002-T002 | done | — | workplans/FLEX-WP-0002-standalone-policy-as-code-core.md |
| task | FLEX-WP-0002-T003 | done | — | workplans/FLEX-WP-0002-standalone-policy-as-code-core.md |
| task | FLEX-WP-0002-T004 | done | — | workplans/FLEX-WP-0002-standalone-policy-as-code-core.md |
| task | FLEX-WP-0002-T005 | done | — | workplans/FLEX-WP-0002-standalone-policy-as-code-core.md |
| task | FLEX-WP-0002-T006 | done | — | workplans/FLEX-WP-0002-standalone-policy-as-code-core.md |
| task | FLEX-WP-0002-T007 | done | — | workplans/FLEX-WP-0002-standalone-policy-as-code-core.md |
| task | FLEX-WP-0002-T008 | done | — | workplans/FLEX-WP-0002-standalone-policy-as-code-core.md |
| task | FLEX-WP-0003-T001 | done | — | workplans/FLEX-WP-0003-markitect-consumer-integration.md |
| task | FLEX-WP-0003-T002 | done | — | workplans/FLEX-WP-0003-markitect-consumer-integration.md |
| task | FLEX-WP-0003-T003 | done | — | workplans/FLEX-WP-0003-markitect-consumer-integration.md |
| task | FLEX-WP-0003-T004 | done | — | workplans/FLEX-WP-0003-markitect-consumer-integration.md |
| task | FLEX-WP-0003-T005 | done | — | workplans/FLEX-WP-0003-markitect-consumer-integration.md |
| task | FLEX-WP-0003-T006 | done | — | workplans/FLEX-WP-0003-markitect-consumer-integration.md |
| task | FLEX-WP-0004-T001 | done | — | workplans/FLEX-WP-0004-delegated-pdp-and-directory-adapters.md |
| task | FLEX-WP-0004-T002 | done | — | workplans/FLEX-WP-0004-delegated-pdp-and-directory-adapters.md |
| task | FLEX-WP-0004-T003 | done | — | workplans/FLEX-WP-0004-delegated-pdp-and-directory-adapters.md |
| task | FLEX-WP-0004-T004 | done | — | workplans/FLEX-WP-0004-delegated-pdp-and-directory-adapters.md |
| task | FLEX-WP-0004-T005 | done | — | workplans/FLEX-WP-0004-delegated-pdp-and-directory-adapters.md |
| task | FLEX-WP-0004-T006 | done | — | workplans/FLEX-WP-0004-delegated-pdp-and-directory-adapters.md |
| task | FLEX-WP-0005-T001 | done | — | workplans/FLEX-WP-0005-foundations-and-topaz-alignment.md |
| task | FLEX-WP-0005-T002 | done | — | workplans/FLEX-WP-0005-foundations-and-topaz-alignment.md |
| task | FLEX-WP-0005-T003 | done | — | workplans/FLEX-WP-0005-foundations-and-topaz-alignment.md |
| task | FLEX-WP-0005-T004 | done | — | workplans/FLEX-WP-0005-foundations-and-topaz-alignment.md |
| task | FLEX-WP-0005-T005 | done | — | workplans/FLEX-WP-0005-foundations-and-topaz-alignment.md |
| task | FLEX-WP-0005-T006 | done | — | workplans/FLEX-WP-0005-foundations-and-topaz-alignment.md |
| task | FLEX-WP-0006-T01 | done | — | workplans/FLEX-WP-0006-ops-warden-ssh-signing-policy-gate.md |
| task | FLEX-WP-0006-T02 | done | — | workplans/FLEX-WP-0006-ops-warden-ssh-signing-policy-gate.md |
| task | FLEX-WP-0006-T03 | done | — | workplans/FLEX-WP-0006-ops-warden-ssh-signing-policy-gate.md |
| task | FLEX-WP-0006-T04 | done | — | workplans/FLEX-WP-0006-ops-warden-ssh-signing-policy-gate.md |
| task | FLEX-WP-0006-T05 | done | — | workplans/FLEX-WP-0006-ops-warden-ssh-signing-policy-gate.md |
| task | FLEX-WP-0007-T01 | done | — | workplans/FLEX-WP-0007-ops-warden-policy-gate-production-deployment.md |
| task | FLEX-WP-0007-T02 | done | — | workplans/FLEX-WP-0007-ops-warden-policy-gate-production-deployment.md |
| task | FLEX-WP-0007-T03 | done | — | workplans/FLEX-WP-0007-ops-warden-policy-gate-production-deployment.md |
| task | FLEX-WP-0007-T04 | done | — | workplans/FLEX-WP-0007-ops-warden-policy-gate-production-deployment.md |
| task | FLEX-WP-0007-T05 | done | — | workplans/FLEX-WP-0007-ops-warden-policy-gate-production-deployment.md |
| task | FLEX-WP-0008-T01 | done | — | workplans/FLEX-WP-0008-tenant-engine-consumer-integration.md |
| task | FLEX-WP-0008-T02 | done | — | workplans/FLEX-WP-0008-tenant-engine-consumer-integration.md |
| task | FLEX-WP-0008-T03 | done | — | workplans/FLEX-WP-0008-tenant-engine-consumer-integration.md |
| task | FLEX-WP-0008-T04 | done | — | workplans/FLEX-WP-0008-tenant-engine-consumer-integration.md |
Authorize tenant-engine lifecycle actions (FLEX-WP-0010) Extend the tenant-engine write-API policy package with tenant.update, tenant.retire, and tenant.reactivate, the three actions TEN-WP-0005 introduced. Until now every lifecycle mutation resolved to deny unknown_action, blocking TEN-WP-0005-T05 production rollout. - policy_package.md: three actions in valid_actions and frontmatter; CARING capabilities extended with EditAny/Archive/Restore - protected_system_manifest.yaml, subject_manifest.yaml, and the rebuilt registry_snapshot.json carry all seven actions - docs/tenant-engine-action-vocabulary.md documents the HTTP surfaces - 8 new fixture pairs and 5 new Rego tests, including action-drift guards (tenant.retired, tenant_update -> unknown_action) T02 decision, recorded in policy_package.md: tenant.retire does NOT get stricter authorization yet. With one service subject and no assurance claim in the CheckRequest there is nothing stricter to check, and a condition the sole caller always satisfies would falsely read as separate control. Retirement is reversible and non-destructive. Revisit on KEY-WP-0005 assurance claims or a second operator subject. Verified: 11/11 Rego tests, 16/16 fixtures, go test ./... green, gofmt and go vet clean. End-to-end against a live serve with a real tenant-engine through the unmodified FlexAuthWriteAuthorizer: update 6176c39c2f4d7b15, retire 8a801b8ee8455080, reactivate c64cf3713cecd970 all allow; unregistered actor denied unknown_subject (59d3e99c6416be89, 403 write_denied). Handoff revision for TEN-WP-0005-T05: package tenant-engine.write-api.mutate v1 (ready, caring-0.4.0-rc2). Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-10 20:52:10 +02:00
| task | FLEX-WP-0009-T01 | done | — | workplans/FLEX-WP-0009-user-engine-production-policy-service.md |
| task | FLEX-WP-0009-T02 | done | — | workplans/FLEX-WP-0009-user-engine-production-policy-service.md |
| task | FLEX-WP-0009-T03 | done | — | workplans/FLEX-WP-0009-user-engine-production-policy-service.md |
| task | FLEX-WP-0009-T04 | done | — | workplans/FLEX-WP-0009-user-engine-production-policy-service.md |
Authorize tenant-engine lifecycle actions (FLEX-WP-0010) Extend the tenant-engine write-API policy package with tenant.update, tenant.retire, and tenant.reactivate, the three actions TEN-WP-0005 introduced. Until now every lifecycle mutation resolved to deny unknown_action, blocking TEN-WP-0005-T05 production rollout. - policy_package.md: three actions in valid_actions and frontmatter; CARING capabilities extended with EditAny/Archive/Restore - protected_system_manifest.yaml, subject_manifest.yaml, and the rebuilt registry_snapshot.json carry all seven actions - docs/tenant-engine-action-vocabulary.md documents the HTTP surfaces - 8 new fixture pairs and 5 new Rego tests, including action-drift guards (tenant.retired, tenant_update -> unknown_action) T02 decision, recorded in policy_package.md: tenant.retire does NOT get stricter authorization yet. With one service subject and no assurance claim in the CheckRequest there is nothing stricter to check, and a condition the sole caller always satisfies would falsely read as separate control. Retirement is reversible and non-destructive. Revisit on KEY-WP-0005 assurance claims or a second operator subject. Verified: 11/11 Rego tests, 16/16 fixtures, go test ./... green, gofmt and go vet clean. End-to-end against a live serve with a real tenant-engine through the unmodified FlexAuthWriteAuthorizer: update 6176c39c2f4d7b15, retire 8a801b8ee8455080, reactivate c64cf3713cecd970 all allow; unregistered actor denied unknown_subject (59d3e99c6416be89, 403 write_denied). Handoff revision for TEN-WP-0005-T05: package tenant-engine.write-api.mutate v1 (ready, caring-0.4.0-rc2). Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-10 20:52:10 +02:00
| task | FLEX-WP-0010-T01 | done | — | workplans/FLEX-WP-0010-tenant-lifecycle-policy-actions.md |
| task | FLEX-WP-0010-T02 | done | — | workplans/FLEX-WP-0010-tenant-lifecycle-policy-actions.md |
| task | FLEX-WP-0010-T03 | done | — | workplans/FLEX-WP-0010-tenant-lifecycle-policy-actions.md |
| task | FLEX-WP-0010-T04 | done | — | workplans/FLEX-WP-0010-tenant-lifecycle-policy-actions.md |
| task | FLEX-WP-0011-T01 | done | — | workplans/FLEX-WP-0011-railiance-staged-promotion-overlay.md |
| task | FLEX-WP-0011-T02 | done | — | workplans/FLEX-WP-0011-railiance-staged-promotion-overlay.md |
| task | FLEX-WP-0011-T03 | done | — | workplans/FLEX-WP-0011-railiance-staged-promotion-overlay.md |
| task | FLEX-WP-0012-T01 | done | — | workplans/FLEX-WP-0012-credential-grant-authorization-surface.md |
| task | FLEX-WP-0012-T02 | done | — | workplans/FLEX-WP-0012-credential-grant-authorization-surface.md |
| task | FLEX-WP-0012-T03 | done | — | workplans/FLEX-WP-0012-credential-grant-authorization-surface.md |
| task | FLEX-WP-0012-T04 | done | — | workplans/FLEX-WP-0012-credential-grant-authorization-surface.md |
| task | FLEX-WP-0013-T01 | done | — | workplans/FLEX-WP-0013-restore-seven-action-tenant-engine-pin.md |
| task | FLEX-WP-0013-T02 | done | — | workplans/FLEX-WP-0013-restore-seven-action-tenant-engine-pin.md |
| task | FLEX-WP-0013-T03 | done | — | workplans/FLEX-WP-0013-restore-seven-action-tenant-engine-pin.md |
| task | FLEX-WP-0014-T01 | done | — | workplans/FLEX-WP-0014-tenant-guardrail-policy-actions.md |
| task | FLEX-WP-0014-T02 | done | — | workplans/FLEX-WP-0014-tenant-guardrail-policy-actions.md |
| task | FLEX-WP-0014-T03 | done | — | workplans/FLEX-WP-0014-tenant-guardrail-policy-actions.md |
| task | FLEX-WP-0014-T04 | done | — | workplans/FLEX-WP-0014-tenant-guardrail-policy-actions.md |
| task | FLEX-WP-0015-T01 | done | — | workplans/FLEX-WP-0015-tenancy-posture-conformance.md |
| task | FLEX-WP-0015-T02 | done | — | workplans/FLEX-WP-0015-tenancy-posture-conformance.md |
| task | FLEX-WP-0015-T03 | done | — | workplans/FLEX-WP-0015-tenancy-posture-conformance.md |
| task | FLEX-WP-0015-T04 | cancel | — | workplans/FLEX-WP-0015-tenancy-posture-conformance.md |
| task | FLEX-WP-0015-T05 | done | — | workplans/FLEX-WP-0015-tenancy-posture-conformance.md |
2026-08-19 14:52:18 +02:00
| task | FLEX-WP-0016-T01 | done | — | workplans/FLEX-WP-0016-ops-warden-incluster-policy-pin.md |
| task | FLEX-WP-0016-T02 | done | — | workplans/FLEX-WP-0016-ops-warden-incluster-policy-pin.md |
| task | FLEX-WP-0016-T03 | done | — | workplans/FLEX-WP-0016-ops-warden-incluster-policy-pin.md |
| task | FLEX-WP-0017-T01 | done | — | workplans/FLEX-WP-0017-action-bound-authorization-contract.md |
| task | FLEX-WP-0017-T02 | done | — | workplans/FLEX-WP-0017-action-bound-authorization-contract.md |
| task | FLEX-WP-0017-T03 | wait | — | workplans/FLEX-WP-0017-action-bound-authorization-contract.md |
| task | FLEX-WP-0017-T04 | done | — | workplans/FLEX-WP-0017-action-bound-authorization-contract.md |
| task | FLEX-WP-0017-T05 | wait | — | workplans/FLEX-WP-0017-action-bound-authorization-contract.md |
| task | FLEX-WP-0018-T01 | done | — | workplans/FLEX-WP-0018-inbound-auth-corrections.md |
| task | FLEX-WP-0018-T02 | done | — | workplans/FLEX-WP-0018-inbound-auth-corrections.md |
Assent to GH-DEC-2026-001 (FLEX-DEC-2026-001), closing FLEX-IN-0001 flex-auth answers gate-house's assent request on the three items ratified in GH-DEC-2026-001, following the estate precedent that a boundary is drawn on review by the other side. Assent to all three, with one conformance debt flex-auth accepts as its own and two conditions on the rename: - Engine framing and sole decision point: assent. flex-auth cannot hold this boundary against zone-engine and decline it as a general rule. But standard section 6 also binds flex-auth: DecisionProvenance carries no registry snapshot digest, so a decision that turned on registry content cannot be replayed from its own provenance. Recorded as a known non-conformance rather than claimed as conformance. - access-engine rename: assent to the name, not to execution. Repository identity and runtime identity must rename in separate revertible steps — since FLEX-WP-0016 the enforcing ops-warden pin binds tokens to the protected-system name, so a single-step rename 401s every warden sign, including the certificate the ops-bridge tunnels depend on. FLEX-WP prefix ownership stays with the repository. - Authoring/evaluation split: assent, with the section 6 test applied symmetrically — a gate-house authority ceiling that determines an outcome reaches the decision as an input claim or as a rule in the versioned policy package, so its application stays reconstructable from the decision record. FLEX-WP-0017-T03 stays wait: the design half re-routes to gate-house, the durable storage half remains unowned and is raised as an engine gap under section 5. Decision id follows the canon scheme {PREFIX}-DEC-YYYY-NNN. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012sgN4GH5ZYT8pJVkCR6dcP Assistant: claude-code Assistant-Model: opus Assistant-Process: 4014348@bnt-lap001 Assistant-Session: a993abda-65a0-4ea8-8ccd-0fcd78c92ac0
2026-08-28 21:47:06 +02:00
| intake | FLEX-IN-0001 | closed | — | intakes/intakes.md |
| intake | FLEX-IN-0002 | closed | — | intakes/intakes.md |
| decision | FLEX-DEC-2026-001 | resolved | — | decisions/decisions.md |
| decision | FLEX-DEC-2026-002 | resolved | — | decisions/decisions.md |
Align INTENT and SCOPE to security layer model v0.7; plan conformance work The standard was accepted at v0.7 on 2026-08-29. Four of flex-auth's review findings are in the accepted text: 9.3's two-owner split, 6.4.2 scoped to the decision's own binding with our canonical request digest as its mechanical test, 9.7.2 split by role, and 17 moving the decision-record schema to access-engine. INTENT.md - Machine-readable layer declaration in frontmatter (layer: Engine, role: PDP), which section 11 requires and we did not have. audit-core noted our declaration was legible only by following the decision trail. - PDP failure semantics stated: our outage is consumer residue, not input degradation; fail-open is not expressible by a PDP at all. - Four owned obligations added: the decision-record schema as our contract, the request digest as the published replay test, a lifetime on every allow, and visibility deadlines per input class. - A Layer Conformance section stating the state honestly: conforming with one declared gap, no Tooling client, not PEP-shaped. - Vocabulary correction: earlier text dropped "control plane" as Staff vocabulary. Section 8 binds it to the Engine layer, which is why kings-guard was asked to release it. The term is ours; we prefer "decision engine" for precision, not boundary. SCOPE.md - Layer and role in the one-liner; the four obligations In Scope; five boundaries established in review but never written down Out of Scope. - Three capability blocks marked planned for workplans completed in May are now current; two blocks added. - Superseded ADR-0006 citation corrected to ADR-0009, which retires the global flag outright rather than deferring it. history/2026-08-29-layer-model-v0.7-alignment-review.md checks each obligation against the code and finds six gaps. FLEX-WP-0019 closes them, with T02 before T04 because a visibility deadline for registry-borne facts is unfalsifiable until provenance can identify the snapshot a decision read. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012sgN4GH5ZYT8pJVkCR6dcP Assistant: claude-code Assistant-Model: opus Assistant-Process: 4014348@bnt-lap001 Assistant-Session: a993abda-65a0-4ea8-8ccd-0fcd78c92ac0
2026-08-29 14:43:49 +02:00
| decision | FLEX-DEC-2026-003 | resolved | — | decisions/decisions.md |