Close FLEX-WP-0029 second edition; correct cadence.yaml; block human/external-gated workplans
Some checks are pending
CI Smoke / host-smoke (push) Waiting to run
CI Smoke / container-smoke (push) Waiting to run

FLEX-WP-0029: publish the second stance-register edition across five rows
(a third scope axis, not a converging two — tenant-engine scopes on
engine-reachability, not security-zone), record Finding 1 as resolved by
gate-house doctrine rather than by either side, and note Finding 3 as still
open in secrets-engine's file. First edition marked superseded, not amended.
SCOPE.md's G3 gap closed accordingly.

FLEX-WP-0031: correct cadence.yaml to declare one heartbeat per rare
load-bearing class instead of a single combined class (tests pass unchanged).
Acknowledged audit-core's AUDIT-IN-0006 reply on T02 and recorded its
corrections; the remaining work (drain, reconciliation, PVC rollout, G2
closure) stays wait/blocked pending the founder's attended OpenBao mint and
gate-house's atomicity ruling, so the workplan moves to blocked.

FLEX-WP-0027: marked blocked — the sole remaining task needs the operator's
own signed-in account, an irreducible human action.

FLEX-WP-0020: recorded net-kingdom's T04 update (NK-WP-0039-T02 done,
runtime.yaml digests current) and replied with no objection to their
ADR-0015 values-pointer proposal for the drifted runtime.yaml reference.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: sonnet
Assistant-Process: 250108@bnt-lap001
Assistant-Session: bab3d5bd-b0bb-42d0-bf80-94ed6fc2b08a
This commit is contained in:
tegwick 2026-09-27 22:12:35 +02:00
parent f208c1da06
commit 92981698d8
8 changed files with 264 additions and 21 deletions

View file

@ -4,7 +4,7 @@ type: workplan
title: "The stance register outgrew the review that read it: five rows, and the divergence was ruled rather than resolved"
domain: infotech
repo: flex-auth
status: ready
status: finished
flavor: review
owner: claude
topic_slug: netkingdom
@ -13,7 +13,7 @@ planning_order: 290
related_workplans:
- FLEX-WP-0019
created: "2026-09-20"
updated: "2026-09-20"
updated: "2026-09-27"
state_hub_workstream_id: "5a11099d-b492-535c-af88-c334db5e8ee6"
---
@ -54,11 +54,15 @@ reviewer's reading of the rows in it, and the second edition must keep saying so
```task
id: FLEX-WP-0029-T01
status: todo
status: done
priority: high
state_hub_task_id: "5a7ed269-974f-5c6a-8e80-e9aa0077f8aa"
```
Done 2026-09-27: recorded in `docs/stance-register-review-second-edition.md`
Finding 1. Verified against `ops-warden/pep-stance.yaml` that the cell is
unflipped by deliberate assent (0 of 3 signing targets resolve to a zone).
Owner: `flex-auth`.
v0.8 §6.4 obligation 3 states that **`unknown` is not a zone and MUST resolve to
@ -91,11 +95,19 @@ it. No claim that flex-auth's review produced the rule.
```task
id: FLEX-WP-0029-T02
status: todo
status: done
priority: high
state_hub_task_id: "991ebb94-cdc4-574a-ba60-f8960ec885fc"
```
Done 2026-09-27: recorded in the second edition's Finding 2. Reading all five
files directly (not the draft table above) found **three** distinct scope
axes, not two converging to one — `tenant-engine` scopes on
`engine-reachability`, not `security-zone` as assumed here. The alarm
sharpens rather than weakens. `ops-mason`'s absent row judged the more costly
of the two problems: an axis mismatch is at least visible, an absent map is
not even reviewable.
Owner: `flex-auth`.
Finding 2 said the register cannot answer *"what is the estate's stance for a
@ -127,11 +139,15 @@ from the two-row text.
```task
id: FLEX-WP-0029-T03
status: todo
status: done
priority: medium
state_hub_task_id: "6dd2c9fd-8ad9-54d6-8fb1-f24e44189f00"
```
Done 2026-09-27: read `secrets-engine/pep-stance.yaml` directly. It still
cites `ActionAuthorization` (line 35). Recorded in the second edition as an
open item, not re-reported as new and not claimed resolved.
Owner: `flex-auth` to verify; `secrets-engine` owns the file.
Finding 3 reported that `secrets-engine`'s `pep-stance.yaml` defines
@ -151,11 +167,19 @@ reply.
```task
id: FLEX-WP-0029-T04
status: todo
status: done
priority: medium
state_hub_task_id: "4dbadd0b-7670-5837-90c9-6201c10479d7"
```
Done 2026-09-27: `SCOPE.md` already stated five rows accurately (its own G3
row was the only stale sentence, now updated below); no rewrite was needed
there. `INTENT.md` carries no `standard_version` field at all, so the
premise that it declares `"0.7"` was itself stale — nothing was bumped, and
this is noted in the second edition rather than silently corrected. The
first edition is not in `SCOPE.md`'s capability blocks, so no capability was
invented for the second.
Owner: `flex-auth`.
- `SCOPE.md` says §13.1's register *"now has **two rows** rather than the one the