Close B2 and finish FLEX-WP-0030; record tenant-engine's and key-cape's answers.
B2: key-cape (Tooling), net-kingdom (Taxonomy) and ops-mason (Staff) now declare in their own files. Verified by the survey rather than taken on report: 14 of 14 counterparts declared, 0 undeclared. ops-mason sent no reply and needed none — under §11 the file is the declaration. Every T04 finding is answered, so FLEX-WP-0030 is finished. B5's residual ping belongs to FLEX-WP-0020. key-cape stated the identity boundary from its side for the first time and cautioned that principal_type must not be read as authentication-derived until GH-DEC-2026-013/-016 §5 is answered. Checked against every published package: only the two informed-decision packages gate on a human subject, and both also require principal_type_source == "authentication-derived", which informed-decision derives from the verified code-flow MFA event rather than from key-cape's claim. No change needed; the assessment and a warning about the legacy "otherwise -> human" fallback are in docs/iam-profile-consumption.md. tenant-engine confirmed FLEX-DEC-2026-016's reading of commitment (b): the fixed-record exclusion is consistent with it. Recorded under point 3; v3 stands. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: opus Assistant-Process: 28468@bnt-lap001 Assistant-Session: c76569b2-6056-4dad-aea4-49cd7a018f5d
This commit is contained in:
parent
882b381af6
commit
39a0034fcc
5 changed files with 607 additions and 2 deletions
|
|
@ -1935,6 +1935,15 @@ reviewer can check rather than as an absence:
|
|||
is reported back to tenant-engine because its commitment (b) reads as
|
||||
literally unconditional.
|
||||
|
||||
**Confirmed by tenant-engine, 2026-09-21** (message `6fdb0180`). (b) as a
|
||||
rule is its first sentence — no action is refused on the relationship
|
||||
between subject and tenant — and the fixed-record exclusion is consistent
|
||||
with it. The looser test sentence will be reworded to *"varying tenant
|
||||
across targets that carry no fixed-record rule"* if the decision is
|
||||
reissued; tenant-engine is not editing the record for this alone. Nothing
|
||||
needs raising with `net-kingdom` or `user-engine`; tenant-engine takes no
|
||||
position on the grant itself. No change to v3.
|
||||
|
||||
**Fixtures.** Every tenant-engine-subject fixture now carries `tenant` equal to
|
||||
`resource.id`, rotated across four tenants; five cross-tenant allow fixtures
|
||||
(three `flex-auth` guardrail reads, two creates) and two `tenant_not_target`
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue