# Custodian Brief — flex-auth **Domain:** infotech **Last synced:** 2026-08-29 12:53 UTC **State Hub:** http://127.0.0.1:8000 *(adjust if running on a remote machine)* ## Active Workstreams ### Layer model v0.7 conformance: provenance, lifetimes, deadlines, and the decision contract Progress: 0/6 done | workplan_id: `84b9dc5a-71f2-5c70-ace6-78242b13d0f1` **Open tasks:** - · Assert the layer declaration mechanically `f72b1305` - · Add the registry-snapshot digest to decision provenance `7a980074` - · Give every allow an explicit lifetime `9d9c0e7a` - · State revocation visibility deadlines per input class `d5917b24` - · Publish the decision-record schema as flex-auth's contract `f7f501d7` - · Publish the request digest as the replay test `bc109ee3` ### Action-bound authorization and durable approval contract Progress: 3/5 done | workplan_id: `d75b7256-8b3d-5797-911c-96c3199b8baa` **Open tasks:** - ! Add durable storage and authenticated approval evidence `82d39961` - ! Consumer handoff and live destructive-action proof `8c3fc0a2` --- ## MCP Orientation (when available) If the state-hub MCP server is reachable, call: `get_domain_summary("infotech")` This provides richer cross-domain context. If the MCP call fails, use this file as your orientation source.