diff --git a/.repo-manager/index.json b/.repo-manager/index.json new file mode 100644 index 0000000..58a2949 --- /dev/null +++ b/.repo-manager/index.json @@ -0,0 +1,1112 @@ +{ + "schema": "repo_manager.index.v1", + "slug": "flex-auth", + "repo_root": "/home/worsch/flex-auth", + "head_sha": "8f815bb304799f81377b66d92733848dc5521bc9", + "observed_at": "2026-08-28T19:45:14.006414Z", + "source_fingerprint": "fb09ffb68b552d10f3ed4d8d60cade2e57b321d1f3c0567775bfe957ebc82128", + "source_files": [ + ".repo-classification.yaml", + "INTENT.md", + "decisions/decisions.md", + "intakes/intakes.md", + "workplans/FLEX-WP-0001-repo-intent-and-architecture-baseline.md", + "workplans/FLEX-WP-0002-standalone-policy-as-code-core.md", + "workplans/FLEX-WP-0003-markitect-consumer-integration.md", + "workplans/FLEX-WP-0004-delegated-pdp-and-directory-adapters.md", + "workplans/FLEX-WP-0005-foundations-and-topaz-alignment.md", + "workplans/FLEX-WP-0006-ops-warden-ssh-signing-policy-gate.md", + "workplans/FLEX-WP-0007-ops-warden-policy-gate-production-deployment.md", + "workplans/FLEX-WP-0008-tenant-engine-consumer-integration.md", + "workplans/FLEX-WP-0009-user-engine-production-policy-service.md", + "workplans/FLEX-WP-0010-tenant-lifecycle-policy-actions.md", + "workplans/FLEX-WP-0011-railiance-staged-promotion-overlay.md", + "workplans/FLEX-WP-0012-credential-grant-authorization-surface.md", + "workplans/FLEX-WP-0013-restore-seven-action-tenant-engine-pin.md", + "workplans/FLEX-WP-0014-tenant-guardrail-policy-actions.md", + "workplans/FLEX-WP-0015-tenancy-posture-conformance.md", + "workplans/FLEX-WP-0016-ops-warden-incluster-policy-pin.md", + "workplans/FLEX-WP-0017-action-bound-authorization-contract.md", + "workplans/FLEX-WP-0018-inbound-auth-corrections.md" + ], + "work_records": [ + { + "kind": "workplan", + "id": "FLEX-WP-0001", + "status": "done", + "title": "Repo Intent and Authorization Architecture Baseline", + "source_path": "workplans/FLEX-WP-0001-repo-intent-and-architecture-baseline.md", + "uuid": "4dbefd19-bb7d-405c-9a50-e7dbd11cf4d9", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0001-T001", + "status": "done", + "title": "P1.1 - Define project intent", + "source_path": "workplans/FLEX-WP-0001-repo-intent-and-architecture-baseline.md", + "uuid": "5af30b01-ea72-4f87-b74e-a595fd3a5bd7", + "parent_id": "FLEX-WP-0001", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0001-T002", + "status": "done", + "title": "P1.2 - Define responsibility boundaries", + "source_path": "workplans/FLEX-WP-0001-repo-intent-and-architecture-baseline.md", + "uuid": "145ec0ec-130a-4209-9028-1ae06e3664e3", + "parent_id": "FLEX-WP-0001", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0001-T003", + "status": "done", + "title": "P1.3 - Capture open-source and enterprise landscape", + "source_path": "workplans/FLEX-WP-0001-repo-intent-and-architecture-baseline.md", + "uuid": "c52a9e3e-e264-418d-b462-d5a9d6e22b30", + "parent_id": "FLEX-WP-0001", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0001-T004", + "status": "done", + "title": "P1.4 - Establish first-consumer architecture", + "source_path": "workplans/FLEX-WP-0001-repo-intent-and-architecture-baseline.md", + "uuid": "7756c4c5-598a-4894-9352-6e7145cb3522", + "parent_id": "FLEX-WP-0001", + "extra": {} + }, + { + "kind": "workplan", + "id": "FLEX-WP-0002", + "status": "completed", + "title": "Standalone Policy-as-Code Core", + "source_path": "workplans/FLEX-WP-0002-standalone-policy-as-code-core.md", + "uuid": "aa60e183-9a87-4e03-99b0-15786bfa11ae", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0002-T001", + "status": "done", + "title": "P2.1 - Define canonical schemas", + "source_path": "workplans/FLEX-WP-0002-standalone-policy-as-code-core.md", + "uuid": "534e5251-8529-48fe-8cf8-b3b6bc4ec1f4", + "parent_id": "FLEX-WP-0002", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0002-T002", + "status": "done", + "title": "P2.2 - Implement local registry store", + "source_path": "workplans/FLEX-WP-0002-standalone-policy-as-code-core.md", + "uuid": "d8045124-f0ae-495d-87b5-24fd9528ef93", + "parent_id": "FLEX-WP-0002", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0002-T003", + "status": "done", + "title": "P2.3 - Implement policy package loader and validator", + "source_path": "workplans/FLEX-WP-0002-standalone-policy-as-code-core.md", + "uuid": "09be0f25-e5ba-42b5-8b2f-36fd0ef2fe6b", + "parent_id": "FLEX-WP-0002", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0002-T004", + "status": "done", + "title": "P2.4 - Implement deterministic check and batch_check APIs", + "source_path": "workplans/FLEX-WP-0002-standalone-policy-as-code-core.md", + "uuid": "f6427575-00af-4f3e-ab30-5b9a158343ef", + "parent_id": "FLEX-WP-0002", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0002-T005", + "status": "done", + "title": "P2.5 - Implement list_allowed and explain", + "source_path": "workplans/FLEX-WP-0002-standalone-policy-as-code-core.md", + "uuid": "e8fcbabd-4eb6-41d2-a4d5-6f40cc245a7e", + "parent_id": "FLEX-WP-0002", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0002-T006", + "status": "done", + "title": "P2.6 - Add local decision log", + "source_path": "workplans/FLEX-WP-0002-standalone-policy-as-code-core.md", + "uuid": "2def10c1-4b5f-44a8-8e6b-4c8592fffd43", + "parent_id": "FLEX-WP-0002", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0002-T007", + "status": "done", + "title": "P2.7 - Add CLI and service skeleton", + "source_path": "workplans/FLEX-WP-0002-standalone-policy-as-code-core.md", + "uuid": "ee9ae6dd-c31f-4d4e-b238-533a2b8040d4", + "parent_id": "FLEX-WP-0002", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0002-T008", + "status": "done", + "title": "P2.8 - Add tests and examples", + "source_path": "workplans/FLEX-WP-0002-standalone-policy-as-code-core.md", + "uuid": "6cbe572a-2877-4936-8ef3-63b79900fae2", + "parent_id": "FLEX-WP-0002", + "extra": {} + }, + { + "kind": "workplan", + "id": "FLEX-WP-0003", + "status": "completed", + "title": "Markitect Consumer Integration", + "source_path": "workplans/FLEX-WP-0003-markitect-consumer-integration.md", + "uuid": "c0a6c9f6-bb6b-416d-b537-f30504c63d75", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0003-T001", + "status": "done", + "title": "P3.1 - Define Markitect resource namespace", + "source_path": "workplans/FLEX-WP-0003-markitect-consumer-integration.md", + "uuid": "53f2fa67-780b-4e40-bbda-e669e4cecc32", + "parent_id": "FLEX-WP-0003", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0003-T002", + "status": "done", + "title": "P3.2 - Import Markitect resource manifests", + "source_path": "workplans/FLEX-WP-0003-markitect-consumer-integration.md", + "uuid": "90082eaf-37f5-492f-a884-ff8eec0eccaa", + "parent_id": "FLEX-WP-0003", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0003-T003", + "status": "done", + "title": "P3.3 - Define Markitect action vocabulary", + "source_path": "workplans/FLEX-WP-0003-markitect-consumer-integration.md", + "uuid": "cfc78bbb-5425-4780-a860-9109df62ea37", + "parent_id": "FLEX-WP-0003", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0003-T004", + "status": "done", + "title": "P3.4 - Implement Markitect check fixtures", + "source_path": "workplans/FLEX-WP-0003-markitect-consumer-integration.md", + "uuid": "1d5de3b2-c581-4ca3-9107-93211eb02c6b", + "parent_id": "FLEX-WP-0003", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0003-T005", + "status": "done", + "title": "P3.5 - Add Markitect adapter contract tests", + "source_path": "workplans/FLEX-WP-0003-markitect-consumer-integration.md", + "uuid": "f9297b0d-69dc-495c-a650-ca671f2c59c7", + "parent_id": "FLEX-WP-0003", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0003-T006", + "status": "done", + "title": "P3.6 - Document integration flow", + "source_path": "workplans/FLEX-WP-0003-markitect-consumer-integration.md", + "uuid": "e34b0303-4416-40a3-8b34-e0e80d644aea", + "parent_id": "FLEX-WP-0003", + "extra": {} + }, + { + "kind": "workplan", + "id": "FLEX-WP-0004", + "status": "completed", + "title": "Delegated PDP and Directory Adapters", + "source_path": "workplans/FLEX-WP-0004-delegated-pdp-and-directory-adapters.md", + "uuid": "99a82976-d376-42b0-89cc-c44e01c0bec6", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0004-T001", + "status": "done", + "title": "P4.1 - Implement Topaz adapter", + "source_path": "workplans/FLEX-WP-0004-delegated-pdp-and-directory-adapters.md", + "uuid": "9046418c-2b78-42c6-8bfa-76d6ed0050dd", + "parent_id": "FLEX-WP-0004", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0004-T002", + "status": "done", + "title": "P4.2 - Add relationship PDP adapter boundary", + "source_path": "workplans/FLEX-WP-0004-delegated-pdp-and-directory-adapters.md", + "uuid": "b77a0b70-b492-46ba-badf-8c2eebe006aa", + "parent_id": "FLEX-WP-0004", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0004-T003", + "status": "done", + "title": "P4.3 - Add rule PDP adapter boundary", + "source_path": "workplans/FLEX-WP-0004-delegated-pdp-and-directory-adapters.md", + "uuid": "4e4e5e45-c05a-4a31-8126-f0c7676b1e6c", + "parent_id": "FLEX-WP-0004", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0004-T004", + "status": "done", + "title": "P4.4 - Add Keycloak Authorization Services adapter path", + "source_path": "workplans/FLEX-WP-0004-delegated-pdp-and-directory-adapters.md", + "uuid": "8d3bbc28-985b-4dd7-9fb8-f9a858eb5a6b", + "parent_id": "FLEX-WP-0004", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0004-T005", + "status": "done", + "title": "P4.5 - Add Entra/Graph and SCIM group resolver adapters", + "source_path": "workplans/FLEX-WP-0004-delegated-pdp-and-directory-adapters.md", + "uuid": "4fc3fb91-8763-453e-8e54-36178cb11efd", + "parent_id": "FLEX-WP-0004", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0004-T006", + "status": "done", + "title": "P4.6 - Add delegated-mode operations docs", + "source_path": "workplans/FLEX-WP-0004-delegated-pdp-and-directory-adapters.md", + "uuid": "491260f9-b4d7-46fe-8220-d358597db33a", + "parent_id": "FLEX-WP-0004", + "extra": {} + }, + { + "kind": "workplan", + "id": "FLEX-WP-0005", + "status": "done", + "title": "Foundations and Topaz Alignment", + "source_path": "workplans/FLEX-WP-0005-foundations-and-topaz-alignment.md", + "uuid": "e37d42a9-0018-4a67-a672-ff4e9716b338", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0005-T001", + "status": "done", + "title": "P5.1 - Record ADR-001 / ADR-002 / ADR-003", + "source_path": "workplans/FLEX-WP-0005-foundations-and-topaz-alignment.md", + "uuid": "8193a278-a044-4397-a4a8-232104374cdc", + "parent_id": "FLEX-WP-0005", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0005-T002", + "status": "done", + "title": "P5.2 - Land Go project skeleton", + "source_path": "workplans/FLEX-WP-0005-foundations-and-topaz-alignment.md", + "uuid": "8ac73c33-6d36-4963-990d-28b0d1d60947", + "parent_id": "FLEX-WP-0005", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0005-T003", + "status": "done", + "title": "P5.3 - Pin FlexAuthResourceManifest schema", + "source_path": "workplans/FLEX-WP-0005-foundations-and-topaz-alignment.md", + "uuid": "80285e1e-16ec-4f4e-b491-1e79f200219f", + "parent_id": "FLEX-WP-0005", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0005-T004", + "status": "done", + "title": "P5.4 - Topaz alignment spike", + "source_path": "workplans/FLEX-WP-0005-foundations-and-topaz-alignment.md", + "uuid": "b8a314c3-e98e-4093-bb11-ab8546b8d79b", + "parent_id": "FLEX-WP-0005", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0005-T005", + "status": "done", + "title": "P5.5 - Cite NetKingdom IAM Profile and pin claim consumption", + "source_path": "workplans/FLEX-WP-0005-foundations-and-topaz-alignment.md", + "uuid": "b31dab7b-e72c-4abe-b6d5-f5875fd0c25a", + "parent_id": "FLEX-WP-0005", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0005-T006", + "status": "done", + "title": "P5.6 - Confirm ops-warden boundary", + "source_path": "workplans/FLEX-WP-0005-foundations-and-topaz-alignment.md", + "uuid": "dcd45a14-20fc-49d0-b869-08cda85fcbc5", + "parent_id": "FLEX-WP-0005", + "extra": {} + }, + { + "kind": "workplan", + "id": "FLEX-WP-0006", + "status": "finished", + "title": "Ops-Warden SSH Signing Policy Gate", + "source_path": "workplans/FLEX-WP-0006-ops-warden-ssh-signing-policy-gate.md", + "uuid": "bbea4049-8acc-4d7c-8cf5-3106c6b93f7f", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0006-T01", + "status": "done", + "title": "T1 - Pin the ops-warden protected-system contract", + "source_path": "workplans/FLEX-WP-0006-ops-warden-ssh-signing-policy-gate.md", + "uuid": "8831b904-dbef-4d55-8eb5-053c939c86b3", + "parent_id": "FLEX-WP-0006", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0006-T02", + "status": "done", + "title": "T2 - Author the ssh-certificate sign policy package", + "source_path": "workplans/FLEX-WP-0006-ops-warden-ssh-signing-policy-gate.md", + "uuid": "9ea206fa-f93d-46b6-8b8e-e8669dd502d4", + "parent_id": "FLEX-WP-0006", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0006-T03", + "status": "done", + "title": "T3 - Add allow and deny fixtures", + "source_path": "workplans/FLEX-WP-0006-ops-warden-ssh-signing-policy-gate.md", + "uuid": "6bf5cb9b-d46c-49cf-aec0-12f6e864a1f8", + "parent_id": "FLEX-WP-0006", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0006-T04", + "status": "done", + "title": "T4 - Verify the `/v1/check` service contract", + "source_path": "workplans/FLEX-WP-0006-ops-warden-ssh-signing-policy-gate.md", + "uuid": "077d29db-30e0-4447-90fd-620c0884306c", + "parent_id": "FLEX-WP-0006", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0006-T05", + "status": "done", + "title": "T5 - Hand off production-readiness evidence to ops-warden", + "source_path": "workplans/FLEX-WP-0006-ops-warden-ssh-signing-policy-gate.md", + "uuid": "06cac0b1-51c0-4ae0-b605-c940f7821ac7", + "parent_id": "FLEX-WP-0006", + "extra": {} + }, + { + "kind": "workplan", + "id": "FLEX-WP-0007", + "status": "finished", + "title": "Ops-Warden Policy Gate Production Deployment", + "source_path": "workplans/FLEX-WP-0007-ops-warden-policy-gate-production-deployment.md", + "uuid": "358ce697-2611-4fe9-89ab-63e86ceb00fa", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0007-T01", + "status": "done", + "title": "T1 - Deploy production flex-auth runtime", + "source_path": "workplans/FLEX-WP-0007-ops-warden-policy-gate-production-deployment.md", + "uuid": "727573fc-86a3-4f5a-abd7-40b0ccb01e68", + "parent_id": "FLEX-WP-0007", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0007-T02", + "status": "done", + "title": "T2 - Load production registry and verify real actors", + "source_path": "workplans/FLEX-WP-0007-ops-warden-policy-gate-production-deployment.md", + "uuid": "6ec1e00c-4a3a-475b-aefb-af3961de7070", + "parent_id": "FLEX-WP-0007", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0007-T03", + "status": "done", + "title": "T3 - Publish registry sync contract with ops-warden", + "source_path": "workplans/FLEX-WP-0007-ops-warden-policy-gate-production-deployment.md", + "uuid": "afa09ec3-516c-433d-87a7-330cb79845a8", + "parent_id": "FLEX-WP-0007", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0007-T04", + "status": "done", + "title": "T4 - Joint OpenBao + policy gate production smoke", + "source_path": "workplans/FLEX-WP-0007-ops-warden-policy-gate-production-deployment.md", + "uuid": "32a96f1c-e0e8-4e27-baa6-7b8c445cf7a1", + "parent_id": "FLEX-WP-0007", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0007-T05", + "status": "done", + "title": "T5 - IAM subject binding for production", + "source_path": "workplans/FLEX-WP-0007-ops-warden-policy-gate-production-deployment.md", + "uuid": "65dc3c59-1e4b-4335-b6a0-db492ea9b2b5", + "parent_id": "FLEX-WP-0007", + "extra": {} + }, + { + "kind": "workplan", + "id": "FLEX-WP-0008", + "status": "finished", + "title": "tenant-engine Consumer Integration", + "source_path": "workplans/FLEX-WP-0008-tenant-engine-consumer-integration.md", + "uuid": "1358db95-967c-5a03-8b8c-4816dc106594", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0008-T01", + "status": "done", + "title": "Task: Define tenant-engine resource and action vocabulary", + "source_path": "workplans/FLEX-WP-0008-tenant-engine-consumer-integration.md", + "uuid": "5606408f-f94c-5d79-ba41-ed23fadac480", + "parent_id": "FLEX-WP-0008", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0008-T02", + "status": "done", + "title": "Task: Author and register the tenant-engine policy package", + "source_path": "workplans/FLEX-WP-0008-tenant-engine-consumer-integration.md", + "uuid": "bbe1a8f4-dcd9-58bb-8d82-386ee0c11a51", + "parent_id": "FLEX-WP-0008", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0008-T03", + "status": "done", + "title": "Task: tenant-engine live-lookup context adapter", + "source_path": "workplans/FLEX-WP-0008-tenant-engine-consumer-integration.md", + "uuid": "e27d24b3-0aef-5bd4-b7e3-81532cd7aa9c", + "parent_id": "FLEX-WP-0008", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0008-T04", + "status": "done", + "title": "Task: Closure review", + "source_path": "workplans/FLEX-WP-0008-tenant-engine-consumer-integration.md", + "uuid": "0f319a2f-e4bb-5ba8-92de-b693ae9a2aa3", + "parent_id": "FLEX-WP-0008", + "extra": {} + }, + { + "kind": "workplan", + "id": "FLEX-WP-0009", + "status": "finished", + "title": "Provide production authorization for user-engine", + "source_path": "workplans/FLEX-WP-0009-user-engine-production-policy-service.md", + "uuid": "390da58d-3c58-5102-bd3c-7133956c810e", + "parent_id": null, + "extra": { + "depends_on": [ + "NK-WP-0024" + ] + } + }, + { + "kind": "task", + "id": "FLEX-WP-0009-T01", + "status": "done", + "title": "T01 - Pin the protected-system vocabulary", + "source_path": "workplans/FLEX-WP-0009-user-engine-production-policy-service.md", + "uuid": "4607222e-3407-59c4-b388-aa7c88f7e3ef", + "parent_id": "FLEX-WP-0009", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0009-T02", + "status": "done", + "title": "T02 - Implement and verify the policy package", + "source_path": "workplans/FLEX-WP-0009-user-engine-production-policy-service.md", + "uuid": "7ae9de35-4f71-54d8-aabb-858c1202c833", + "parent_id": "FLEX-WP-0009", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0009-T03", + "status": "done", + "title": "T03 - Deploy the cluster-local service", + "source_path": "workplans/FLEX-WP-0009-user-engine-production-policy-service.md", + "uuid": "9a1ea146-0735-5d6f-bd75-96eb78e9bd2b", + "parent_id": "FLEX-WP-0009", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0009-T04", + "status": "done", + "title": "T04 - Hand back production evidence", + "source_path": "workplans/FLEX-WP-0009-user-engine-production-policy-service.md", + "uuid": "9639adbe-4392-5f6c-a924-3771f71ab94c", + "parent_id": "FLEX-WP-0009", + "extra": {} + }, + { + "kind": "workplan", + "id": "FLEX-WP-0010", + "status": "finished", + "title": "Authorize tenant-engine lifecycle actions", + "source_path": "workplans/FLEX-WP-0010-tenant-lifecycle-policy-actions.md", + "uuid": "fdabae84-dc9e-5ccd-81df-8ae7e66b90b8", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0010-T01", + "status": "done", + "title": "T01 - Extend the policy package with the lifecycle actions", + "source_path": "workplans/FLEX-WP-0010-tenant-lifecycle-policy-actions.md", + "uuid": "8deb9564-658e-5eff-8ef7-94838bee05cc", + "parent_id": "FLEX-WP-0010", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0010-T02", + "status": "done", + "title": "T02 - Decide whether retirement warrants stricter authorization", + "source_path": "workplans/FLEX-WP-0010-tenant-lifecycle-policy-actions.md", + "uuid": "82d13a89-a344-5797-b10f-390d17b11b73", + "parent_id": "FLEX-WP-0010", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0010-T03", + "status": "done", + "title": "T03 - Fixtures and verification", + "source_path": "workplans/FLEX-WP-0010-tenant-lifecycle-policy-actions.md", + "uuid": "2fbceaf5-514b-5ded-adb1-f4e63ce96160", + "parent_id": "FLEX-WP-0010", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0010-T04", + "status": "done", + "title": "T04 - Closure and handoff", + "source_path": "workplans/FLEX-WP-0010-tenant-lifecycle-policy-actions.md", + "uuid": "eb2579cb-b54f-5834-abcc-81954ac34889", + "parent_id": "FLEX-WP-0010", + "extra": {} + }, + { + "kind": "workplan", + "id": "FLEX-WP-0011", + "status": "finished", + "title": "Bring flex-auth under the railiance staged-promotion contract", + "source_path": "workplans/FLEX-WP-0011-railiance-staged-promotion-overlay.md", + "uuid": "deda35b4-f41d-559e-954e-a75f29237f68", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0011-T01", + "status": "done", + "title": "T01 - Author the railiance overlay", + "source_path": "workplans/FLEX-WP-0011-railiance-staged-promotion-overlay.md", + "uuid": "75748946-68c0-5f33-abe1-810fcd55e93f", + "parent_id": "FLEX-WP-0011", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0011-T02", + "status": "done", + "title": "T02 - Prove the stage commands", + "source_path": "workplans/FLEX-WP-0011-railiance-staged-promotion-overlay.md", + "uuid": "4becc09f-2331-5487-a794-643c748dd1bd", + "parent_id": "FLEX-WP-0011", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0011-T03", + "status": "done", + "title": "T03 - Correct the stale drain-plan row", + "source_path": "workplans/FLEX-WP-0011-railiance-staged-promotion-overlay.md", + "uuid": "abb788fe-22a5-5226-9f08-a43e20a47ce9", + "parent_id": "FLEX-WP-0011", + "extra": {} + }, + { + "kind": "workplan", + "id": "FLEX-WP-0012", + "status": "finished", + "title": "Authorize railiance-platform credential-grant requests", + "source_path": "workplans/FLEX-WP-0012-credential-grant-authorization-surface.md", + "uuid": "2a6b5764-1831-5305-b46e-0991d02675df", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0012-T01", + "status": "done", + "title": "T01 - Decide where the translation lives", + "source_path": "workplans/FLEX-WP-0012-credential-grant-authorization-surface.md", + "uuid": "f8491771-be1a-5c70-a4aa-059e48536630", + "parent_id": "FLEX-WP-0012", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0012-T02", + "status": "done", + "title": "T02 - Credential-grant policy package and fixtures", + "source_path": "workplans/FLEX-WP-0012-credential-grant-authorization-surface.md", + "uuid": "685f3d70-7c50-5664-95ae-1e8c93b14073", + "parent_id": "FLEX-WP-0012", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0012-T03", + "status": "done", + "title": "T03 - Implement the decided integration and prove it end to end", + "source_path": "workplans/FLEX-WP-0012-credential-grant-authorization-surface.md", + "uuid": "045ec743-4411-5b42-b9e8-df25b0c07984", + "parent_id": "FLEX-WP-0012", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0012-T04", + "status": "done", + "title": "T04 - Closure and handoff", + "source_path": "workplans/FLEX-WP-0012-credential-grant-authorization-surface.md", + "uuid": "0dcf2e1f-baa2-5fea-9e3e-9a73795af11f", + "parent_id": "FLEX-WP-0012", + "extra": {} + }, + { + "kind": "workplan", + "id": "FLEX-WP-0013", + "status": "finished", + "title": "Restore the seven-action tenant-engine policy pin", + "source_path": "workplans/FLEX-WP-0013-restore-seven-action-tenant-engine-pin.md", + "uuid": "6f22ded6-a69c-531b-bfa6-2f8d5c886979", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0013-T01", + "status": "done", + "title": "T01 - Re-pin the overlay and emergency manifests", + "source_path": "workplans/FLEX-WP-0013-restore-seven-action-tenant-engine-pin.md", + "uuid": "f84b0f20-f374-5d61-aa43-d1f886ea86c3", + "parent_id": "FLEX-WP-0013", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0013-T02", + "status": "done", + "title": "T02 - Apply and prove the seven actions live", + "source_path": "workplans/FLEX-WP-0013-restore-seven-action-tenant-engine-pin.md", + "uuid": "a77ff4bb-8927-5317-a0eb-903cfeef0de5", + "parent_id": "FLEX-WP-0013", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0013-T03", + "status": "done", + "title": "T03 - Handoff and close", + "source_path": "workplans/FLEX-WP-0013-restore-seven-action-tenant-engine-pin.md", + "uuid": "832ba42f-4247-58a9-bc1b-f99648c2c188", + "parent_id": "FLEX-WP-0013", + "extra": {} + }, + { + "kind": "workplan", + "id": "FLEX-WP-0014", + "status": "finished", + "title": "Authorize tenant-engine guardrail actions", + "source_path": "workplans/FLEX-WP-0014-tenant-guardrail-policy-actions.md", + "uuid": "7de17bd2-5e7c-5355-ba1d-40a051a67746", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0014-T01", + "status": "done", + "title": "T01 - Extend the policy package with the guardrail actions", + "source_path": "workplans/FLEX-WP-0014-tenant-guardrail-policy-actions.md", + "uuid": "34fb239a-7f06-5e96-9f10-a6bbb85bf4c3", + "parent_id": "FLEX-WP-0014", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0014-T02", + "status": "done", + "title": "T02 - Decide how the read/write split is used today", + "source_path": "workplans/FLEX-WP-0014-tenant-guardrail-policy-actions.md", + "uuid": "8ea87d5f-883a-5d63-89bb-33a3d0963472", + "parent_id": "FLEX-WP-0014", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0014-T03", + "status": "done", + "title": "T03 - Fixtures and verification", + "source_path": "workplans/FLEX-WP-0014-tenant-guardrail-policy-actions.md", + "uuid": "1029d2ce-bb37-530e-91ef-ded86f6f5be8", + "parent_id": "FLEX-WP-0014", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0014-T04", + "status": "done", + "title": "T04 - Closure and handoff", + "source_path": "workplans/FLEX-WP-0014-tenant-guardrail-policy-actions.md", + "uuid": "b2b44215-ef08-5c50-b466-190156a88ef3", + "parent_id": "FLEX-WP-0014", + "extra": {} + }, + { + "kind": "workplan", + "id": "FLEX-WP-0015", + "status": "finished", + "title": "Tenancy posture declaration and inbound caller authentication", + "source_path": "workplans/FLEX-WP-0015-tenancy-posture-conformance.md", + "uuid": "43fe348c-02b9-5d5d-af37-a2d80cfc6e1d", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0015-T01", + "status": "done", + "title": "Tasks", + "source_path": "workplans/FLEX-WP-0015-tenancy-posture-conformance.md", + "uuid": "ee587988-d29c-5dd8-9417-8af73f627817", + "parent_id": "FLEX-WP-0015", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0015-T02", + "status": "done", + "title": "Tasks", + "source_path": "workplans/FLEX-WP-0015-tenancy-posture-conformance.md", + "uuid": "7c906ab5-0b3f-5a73-8561-b29d94f4e634", + "parent_id": "FLEX-WP-0015", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0015-T03", + "status": "done", + "title": "Tasks", + "source_path": "workplans/FLEX-WP-0015-tenancy-posture-conformance.md", + "uuid": "4f885922-56c9-5d89-b7ab-e61c8d69d67a", + "parent_id": "FLEX-WP-0015", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0015-T04", + "status": "cancel", + "title": "Tasks", + "source_path": "workplans/FLEX-WP-0015-tenancy-posture-conformance.md", + "uuid": "1c05032a-bcae-5a4c-8f4a-c51b30a48807", + "parent_id": "FLEX-WP-0015", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0015-T05", + "status": "done", + "title": "Tasks", + "source_path": "workplans/FLEX-WP-0015-tenancy-posture-conformance.md", + "uuid": "702e55bf-b87a-547d-9a2d-bc2ccfee9341", + "parent_id": "FLEX-WP-0015", + "extra": {} + }, + { + "kind": "workplan", + "id": "FLEX-WP-0016", + "status": "finished", + "title": "In-cluster ops-warden policy pin so policy.enabled can flip", + "source_path": "workplans/FLEX-WP-0016-ops-warden-incluster-policy-pin.md", + "uuid": "f29f159c-c79e-5c78-b1e8-569a5b63d231", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0016-T01", + "status": "done", + "title": "Tasks", + "source_path": "workplans/FLEX-WP-0016-ops-warden-incluster-policy-pin.md", + "uuid": "b2f8052e-3686-593f-9359-dfd08d530a26", + "parent_id": "FLEX-WP-0016", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0016-T02", + "status": "done", + "title": "Tasks", + "source_path": "workplans/FLEX-WP-0016-ops-warden-incluster-policy-pin.md", + "uuid": "aa65f534-7401-5231-ae82-ea6e3d09b40c", + "parent_id": "FLEX-WP-0016", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0016-T03", + "status": "done", + "title": "Tasks", + "source_path": "workplans/FLEX-WP-0016-ops-warden-incluster-policy-pin.md", + "uuid": "351f502f-f0cf-5a70-86da-10b1fbe39dae", + "parent_id": "FLEX-WP-0016", + "extra": {} + }, + { + "kind": "workplan", + "id": "FLEX-WP-0017", + "status": "active", + "title": "Action-bound authorization and durable approval contract", + "source_path": "workplans/FLEX-WP-0017-action-bound-authorization-contract.md", + "uuid": "d75b7256-8b3d-5797-911c-96c3199b8baa", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0017-T01", + "status": "done", + "title": "Bind execute-time decisions to the evaluated request", + "source_path": "workplans/FLEX-WP-0017-action-bound-authorization-contract.md", + "uuid": "e7b47e1d-58e8-503c-be89-e8f2050215b1", + "parent_id": "FLEX-WP-0017", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0017-T02", + "status": "done", + "title": "Define the durable authorization object and semantics", + "source_path": "workplans/FLEX-WP-0017-action-bound-authorization-contract.md", + "uuid": "df7984fb-c31f-5b26-bf42-193e4c3cbb9f", + "parent_id": "FLEX-WP-0017", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0017-T03", + "status": "wait", + "title": "Add durable storage and authenticated approval evidence", + "source_path": "workplans/FLEX-WP-0017-action-bound-authorization-contract.md", + "uuid": "82d39961-8140-5a7f-9bd8-5164dd1742e5", + "parent_id": "FLEX-WP-0017", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0017-T04", + "status": "done", + "title": "Propagate bindings through delegated evaluators", + "source_path": "workplans/FLEX-WP-0017-action-bound-authorization-contract.md", + "uuid": "d85089ee-ad8c-502b-ba1b-be4ad23aec46", + "parent_id": "FLEX-WP-0017", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0017-T05", + "status": "wait", + "title": "Consumer handoff and live destructive-action proof", + "source_path": "workplans/FLEX-WP-0017-action-bound-authorization-contract.md", + "uuid": "8c3fc0a2-0855-5ac9-afa5-d03b8b1f0bf9", + "parent_id": "FLEX-WP-0017", + "extra": {} + }, + { + "kind": "workplan", + "id": "FLEX-WP-0018", + "status": "finished", + "title": "Inbound caller-auth and deployment documentation corrections", + "source_path": "workplans/FLEX-WP-0018-inbound-auth-corrections.md", + "uuid": "8f301c7c-e3e2-5bd0-a6f2-0cb92c1d782f", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0018-T01", + "status": "done", + "title": "Classify rejected TokenReview credentials as unauthenticated", + "source_path": "workplans/FLEX-WP-0018-inbound-auth-corrections.md", + "uuid": "4a85c91f-6f34-5224-99b0-23b8eaa3bf7b", + "parent_id": "FLEX-WP-0018", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0018-T02", + "status": "done", + "title": "Correct NetworkPolicy egress documentation", + "source_path": "workplans/FLEX-WP-0018-inbound-auth-corrections.md", + "uuid": "5613aeb1-ad09-50e5-9933-ced39593dc54", + "parent_id": "FLEX-WP-0018", + "extra": {} + }, + { + "kind": "decision", + "id": "FLEX-DEC-2026-001", + "status": "resolved", + "title": "Assent to GH-DEC-2026-001: Engine framing, access-engine rename, authoring/evaluation split", + "source_path": "decisions/decisions.md", + "uuid": null, + "parent_id": null, + "extra": { + "record": { + "id": "FLEX-DEC-2026-001", + "kind": "decision", + "title": "Assent to GH-DEC-2026-001: Engine framing, access-engine rename, authoring/evaluation split", + "status": "resolved", + "origin": "cross-repo", + "origin_ref": "gate-house GH-DEC-2026-001", + "standard": "net-kingdom/canon/standards/security-layer-model_v0.1.md", + "intake_ref": "FLEX-IN-0001", + "owner": "flex-auth", + "affects": [ + "flex-auth", + "gate-house", + "net-kingdom", + "ops-warden", + "secrets-engine", + "zone-engine" + ], + "requested_dispositions": [ + "assent", + "revise", + "reject" + ], + "created": "2026-08-28T19:43:38.443788Z", + "updated": "2026-08-28T19:44:29.505314Z", + "rationale": "Assent to all three items of GH-DEC-2026-001. Item 1: flex-auth is Engine-layer and the sole decision point; the INTENT reframe at fe46122 stands. flex-auth accepts one conformance debt of its own \u2014 DecisionProvenance carries no registry snapshot digest, so a decision turning on registry content is not replayable from its own provenance (standard section 6). Item 2: access-engine is the right name; execution is a separate governed migration, conditioned on renaming repository identity and runtime identity in separate revertible steps (the enforcing ops-warden pin binds tokens to the protected-system name flex-auth, and a single-step rename would 401 every warden sign) and on FLEX-WP prefix ownership staying with the repository. Item 3: the authoring/evaluation split is accepted; gate-house authority ceilings must reach the decision as input claims or as rules in the versioned policy package so their application is reconstructable from the decision record \u2014 the same section 6 test flex-auth applied to zone-engine and now to itself. FLEX-WP-0017-T03/T05 stay wait: the design half is re-routed to gate-house, the durable storage half remains unowned and is raised as an engine gap.", + "decided_by": "flex-auth (reviewing side)", + "decided_at": "2026-08-28T19:44:29.505314Z" + } + } + }, + { + "kind": "intake", + "id": "FLEX-IN-0001", + "status": "closed", + "title": "Assent requested: Engine framing, access-engine rename, and the authoring/evaluation split", + "source_path": "intakes/intakes.md", + "uuid": null, + "parent_id": null, + "extra": { + "record": { + "id": "FLEX-IN-0001", + "kind": "intake", + "title": "Assent requested: Engine framing, access-engine rename, and the authoring/evaluation split", + "status": "closed", + "origin": "cross-repo", + "origin_ref": "gate-house GH-DEC-2026-001", + "priority": "high", + "owner": "flex-auth", + "requested_by": "gate-house", + "standard": "net-kingdom/canon/standards/security-layer-model_v0.1.md", + "description": "gate-house asks flex-auth to assent to three items ratified in GH-DEC-2026-001, following the estate precedent that a boundary is drawn on review by the other side rather than asserted \u2014 as flex-auth itself did to zone-engine. (1) flex-auth is Engine-layer and is NetKingdom\u2019s only policy decision point; the INTENT reframe is already applied (commit fe46122) and can be revised or reverted if wrong. (2) The ruled rename flex-auth -> access-engine, NOT yet authorized to execute: it is a separate governed migration touching FLEX-WP prefix ownership, State Hub identifiers, ops-warden routing tables, zone-engine boundary text, and secrets-engine integrations. auth-engine was rejected because key-cape owns authentication. (3) The split: flex-auth owns evaluation exclusively plus the policy-as-code mechanism; gate-house owns doctrine, invariants, authority ceilings, operating modes, and the authority context consumed as input claims; policy content stays with the protected system owner. This resolves the FLEX-WP-0017 overlap \u2014 gate-house designs the approval contract, flex-auth validates approvals at decision time. Assent, revision, or rejection all acceptable; the standard stays proposed until this is answered.", + "created": "2026-08-28T19:30:03.602578Z", + "updated": "2026-08-28T19:45:06.001794Z", + "notes": [ + { + "content": "Answered by FLEX-DEC-2026-001 (decisions/decisions.md): assent to all three items, with one accepted flex-auth conformance debt (registry snapshot absent from DecisionProvenance) and two conditions on the rename migration.", + "author": "flex-auth", + "created": "2026-08-28T19:45:04.030513Z" + } + ], + "closed_at": "2026-08-28T19:45:06.001794Z", + "outcome": "assented \u2014 see FLEX-DEC-2026-001" + } + } + } + ], + "events": [ + { + "type": "repo.reconciled", + "workplan_count": 18, + "task_count": 81, + "source": "repo-manager", + "emitted_at": "2026-08-28T19:45:14.006530Z" + } + ] +} diff --git a/INTENT.md b/INTENT.md index ac200e6..3632c09 100644 --- a/INTENT.md +++ b/INTENT.md @@ -18,10 +18,28 @@ > gate-house's authority context adopted as input claims, and the access > lane/rule demarcation recorded. > -> *Reframe applied. One item remains: the ruled rename to `access-engine`, which -> is a separate governed migration — it touches `FLEX-WP` prefix ownership, State -> Hub identifiers, ops-warden's routing tables, zone-engine's binding boundary -> text, and secrets-engine integrations — and is not authorized by GH-DEC-2026-001.* +> *Reframe applied. **Assent given on 2026-08-28** — `decisions/decisions.md` +> FLEX-DEC-2026-001, answering intake `FLEX-IN-0001`: flex-auth assents to the Engine +> framing, to `access-engine` as the ruled name, and to the authoring/evaluation +> split. One item remains: the rename itself, a separate governed migration — it +> touches `FLEX-WP` prefix ownership, State Hub identifiers, ops-warden's routing +> tables, zone-engine's binding boundary text, and secrets-engine integrations — +> and is not authorized by GH-DEC-2026-001. flex-auth adds two conditions on it +> (FLEX-DEC-2026-001 item 2): repository identity and runtime identity rename in +> separate revertible steps, repository first, because the enforcing ops-warden +> pin binds tokens to the protected-system name; and `FLEX-WP` prefix ownership +> stays with the repository.* +> +> **Known non-conformance — registry provenance.** Standard §6 holds that +> compiled data determining an outcome is still deciding, and that provenance +> must stay reconstructable from the decision. `DecisionProvenance` carries the +> evaluator, mode, policy package, policy version, and directory ETag, but no +> digest of the registry snapshot. A decision that turned on registry content +> cannot be replayed from its own provenance. flex-auth accepts this as its own +> gap rather than claiming conformance; until it is closed, outcome-determining +> content belongs in the versioned policy package, not the registry — for +> zone-engine's zone stance, for gate-house's authority ceilings, and for +> everyone else on the same terms. > This file captures **why this repository exists**, the **direction it is > moving toward**, and the **kind of system it is meant to become**. @@ -119,6 +137,15 @@ Gate House holds no runtime position and never renders a decision. A deterministic authority boundary inside a non-deterministic layer would violate the invariant the estate is built on. +One condition follows from that, drawn by flex-auth on review (FLEX-DEC-2026-001): +an authority ceiling that determines an outcome must reach the decision either +as an input claim on the request or as a rule in the versioned policy package, +so that its application is reconstructable from the decision record. A ceiling +that resolves an outcome before evaluation runs has decided early. This is not a +limit on gate-house's authorship — it is what keeps that authorship auditable at +decision time, and it is the same test flex-auth applied to zone-engine's zone +stance and, in the note above, to its own registry. + ### Protected Systems Own Enforcement Applications remain policy enforcement points. They extract resource diff --git a/WORK-RECORDS.md b/WORK-RECORDS.md index 5a074aa..53895a2 100644 --- a/WORK-RECORDS.md +++ b/WORK-RECORDS.md @@ -107,4 +107,4 @@ | task | FLEX-WP-0017-T05 | wait | — | workplans/FLEX-WP-0017-action-bound-authorization-contract.md | | task | FLEX-WP-0018-T01 | done | — | workplans/FLEX-WP-0018-inbound-auth-corrections.md | | task | FLEX-WP-0018-T02 | done | — | workplans/FLEX-WP-0018-inbound-auth-corrections.md | -| intake | FLEX-IN-0001 | open | — | intakes/intakes.md | +| intake | FLEX-IN-0001 | closed | — | intakes/intakes.md | diff --git a/decisions/decisions.md b/decisions/decisions.md index 2b3ac8e..6321816 100644 --- a/decisions/decisions.md +++ b/decisions/decisions.md @@ -1,9 +1,9 @@ # Decision records -## FLEX-DEC-0001 — Assent to GH-DEC-2026-001: Engine framing, access-engine rename, authoring/evaluation split +## FLEX-DEC-2026-001 — Assent to GH-DEC-2026-001: Engine framing, access-engine rename, authoring/evaluation split ```yaml -id: FLEX-DEC-0001 +id: FLEX-DEC-2026-001 kind: decision title: 'Assent to GH-DEC-2026-001: Engine framing, access-engine rename, authoring/evaluation split' diff --git a/intakes/intakes.md b/intakes/intakes.md index 5b4ee35..b53552f 100644 --- a/intakes/intakes.md +++ b/intakes/intakes.md @@ -32,11 +32,11 @@ description: 'gate-house asks flex-auth to assent to three items ratified in GH- created: '2026-08-28T19:30:03.602578Z' updated: '2026-08-28T19:45:06.001794Z' notes: -- content: 'Answered by FLEX-DEC-0001 (decisions/decisions.md): assent to all three +- content: 'Answered by FLEX-DEC-2026-001 (decisions/decisions.md): assent to all three items, with one accepted flex-auth conformance debt (registry snapshot absent from DecisionProvenance) and two conditions on the rename migration.' author: flex-auth created: '2026-08-28T19:45:04.030513Z' closed_at: '2026-08-28T19:45:06.001794Z' -outcome: assented — see FLEX-DEC-0001 +outcome: assented — see FLEX-DEC-2026-001 ``` diff --git a/workplans/FLEX-WP-0017-action-bound-authorization-contract.md b/workplans/FLEX-WP-0017-action-bound-authorization-contract.md index aff9500..147373e 100644 --- a/workplans/FLEX-WP-0017-action-bound-authorization-contract.md +++ b/workplans/FLEX-WP-0017-action-bound-authorization-contract.md @@ -68,6 +68,15 @@ contract, authenticated approval entries, and atomic supersession. Its current No flex-auth-local substitute is acceptable because flex-auth does not own the organizational approval lifecycle. +Re-routed 2026-08-28 by FLEX-DEC-2026-001 (assent to gate-house GH-DEC-2026-001): +under the authoring/evaluation split, gate-house designs the approval contract +and flex-auth validates approvals at decision time. The *design* half of this +task is therefore addressed to gate-house. The *storage and lifecycle* half — +durable object, authenticated approval entries, atomic supersession — remains +unowned: it is not gate-house's, because Staff holds no state another layer +depends on at runtime (standard §3.4), and not flex-auth's, for the reason +above. Raised to gate-house as an engine gap under §5. Task stays `wait`. + ## Propagate bindings through delegated evaluators ```task