Commit graph

3 commits

Author SHA1 Message Date
39a0034fcc Close B2 and finish FLEX-WP-0030; record tenant-engine's and key-cape's answers.
B2: key-cape (Tooling), net-kingdom (Taxonomy) and ops-mason (Staff) now declare
in their own files. Verified by the survey rather than taken on report: 14 of 14
counterparts declared, 0 undeclared. ops-mason sent no reply and needed none —
under §11 the file is the declaration. Every T04 finding is answered, so
FLEX-WP-0030 is finished. B5's residual ping belongs to FLEX-WP-0020.

key-cape stated the identity boundary from its side for the first time and
cautioned that principal_type must not be read as authentication-derived until
GH-DEC-2026-013/-016 §5 is answered. Checked against every published package:
only the two informed-decision packages gate on a human subject, and both also
require principal_type_source == "authentication-derived", which informed-decision
derives from the verified code-flow MFA event rather than from key-cape's claim.
No change needed; the assessment and a warning about the legacy "otherwise ->
human" fallback are in docs/iam-profile-consumption.md.

tenant-engine confirmed FLEX-DEC-2026-016's reading of commitment (b): the
fixed-record exclusion is consistent with it. Recorded under point 3; v3 stands.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 28468@bnt-lap001
Assistant-Session: c76569b2-6056-4dad-aea4-49cd7a018f5d
2026-09-21 22:57:56 +02:00
aa8e3a4e34 Align IAM Profile consumption with v0.2 2026-05-22 14:35:30 +02:00
f930e96568 IAM Profile consumption doc + claim fixtures; close FLEX-WP-0005
Completes FLEX-WP-0005 T05 and closes the Foundations and Topaz
Alignment workstream.

docs/iam-profile-consumption.md captures flex-auth's input surface
against NetKingdom IAM Profile v0.1:
- boundary (flex-auth consumes verified claims; upstream layer
  validates signatures and audiences)
- normalized input envelope (matches Markitect's EnterpriseIdentity)
- required, recommended, and tolerated claim variations
- role-claim location union (top-level / realm_access / resource_access)
- scope encoding (string vs array)
- principal-type detection (human / service / emergency)
- group-overage and freshness expectations
- production vs local-development handling

examples/claims/ ships five contract fixtures:
- key-cape-lightweight.yaml (profile minimum)
- keycloak-heavy.yaml (full variation set + MFA)
- service-account.yaml (svc-* hub-to-hub)
- emergency.yaml (break-glass with incident metadata)
- keycloak-group-overage.yaml (Entra-style hasgroups: true)

All fixtures parse as valid YAML. They become contract tests for the
standalone evaluator (FLEX-WP-0002 P2.4) and the Topaz adapter
(FLEX-WP-0004 T01); both code paths must produce identical normalized
envelopes for the same fixture.

FLEX-WP-0005 workstream marked status=done in this file and completed
in the State Hub. FLEX-WP-0002 is now fully unblocked.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-05-16 09:09:36 +02:00