# Custodian Brief — flex-auth **Domain:** infotech **Last synced:** 2026-09-06 20:45 UTC **State Hub:** http://127.0.0.1:8000 *(adjust if running on a remote machine)* ## Active Workstreams ### Sign the decision envelope: the response channel is unauthenticated Progress: 1/4 done | workplan_id: `90577acd-6910-548d-a13e-1dbfdfb8ed27` **Open tasks:** - ! 3. Implement signing and verification `041612ea` - ! 4. Report the gap to gate-house `82d6b75e` - · 2. Choose the signature shape and key custody `5482f3cd` ### Operator caller access path and caller identity in the decision record Progress: 0/5 done | workplan_id: `ad011f92-786c-51ad-b3f6-c06ad77e7af7` **Open tasks:** - ! 2. Run the positive and negative tests and return the receipts `79a8d82d` - ! 3. Flip `callerAuth.mode` to enforce `8117c9d8` - ! 5. Report the gap to gate-house as a v0.8 finding `d685abfc` - · 1. Create the ServiceAccount the deployed binding already names `10e5a40c` - · 4. Record the authenticated caller in the decision record `c0e4f31a` --- ## MCP Orientation (when available) If the state-hub MCP server is reachable, call: `get_domain_summary("infotech")` This provides richer cross-domain context. If the MCP call fails, use this file as your orientation source.