flex-auth/workplans/FLEX-WP-0027-t03-human-review.md
tegwick 92981698d8
Some checks are pending
CI Smoke / host-smoke (push) Waiting to run
CI Smoke / container-smoke (push) Waiting to run
Close FLEX-WP-0029 second edition; correct cadence.yaml; block human/external-gated workplans
FLEX-WP-0029: publish the second stance-register edition across five rows
(a third scope axis, not a converging two — tenant-engine scopes on
engine-reachability, not security-zone), record Finding 1 as resolved by
gate-house doctrine rather than by either side, and note Finding 3 as still
open in secrets-engine's file. First edition marked superseded, not amended.
SCOPE.md's G3 gap closed accordingly.

FLEX-WP-0031: correct cadence.yaml to declare one heartbeat per rare
load-bearing class instead of a single combined class (tests pass unchanged).
Acknowledged audit-core's AUDIT-IN-0006 reply on T02 and recorded its
corrections; the remaining work (drain, reconciliation, PVC rollout, G2
closure) stays wait/blocked pending the founder's attended OpenBao mint and
gate-house's atomicity ruling, so the workplan moves to blocked.

FLEX-WP-0027: marked blocked — the sole remaining task needs the operator's
own signed-in account, an irreducible human action.

FLEX-WP-0020: recorded net-kingdom's T04 update (NK-WP-0039-T02 done,
runtime.yaml digests current) and replied with no objection to their
ADR-0015 values-pointer proposal for the drifted runtime.yaml reference.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: sonnet
Assistant-Process: 250108@bnt-lap001
Assistant-Session: bab3d5bd-b0bb-42d0-bf80-94ed6fc2b08a
2026-09-27 22:12:35 +02:00

59 lines
1.9 KiB
Markdown

---
id: FLEX-WP-0027
type: workplan
title: "Admit scoped human review for the three T03 actions"
domain: infotech
repo: flex-auth
status: blocked
flavor: implementation
owner: codex
topic_slug: netkingdom
created: "2026-09-14"
updated: "2026-09-27"
state_hub_workstream_id: "954635b2-8377-5227-ab4f-10607b2a02c6"
---
## Implement the explicit group and exact-record mandate
```task
id: FLEX-WP-0027-T01
status: done
priority: high
state_hub_task_id: "7b5af88b-2630-5f94-a085-78180690e08c"
```
The operator admitted net-kingdom-admins for the three T03 reviews only.
`examples/informed-decision-t03` pins record IDs, versions and native bindings.
Fresh verified KeyCape MFA and groups are mandatory. 57 evaluator checks pass.
Reproduce with `python3 tools/exercise_t03_review_policy.py --binary /path/to/flex-auth --receipt /tmp/t03-checks.json`.
## Deploy the isolated caller-bound policy
```task
id: FLEX-WP-0027-T02
status: done
priority: high
state_hub_task_id: "129568a0-cb1c-5f7b-8f5d-f44f1d2bcfff"
```
`values/informed-decision-t03.yaml` pins the live image and policy. TokenReview
admits only system:serviceaccount:informed-decision:review. Six native caller
checks pass with synthetic identities; evidence is retained in docs/evidence.
## Verify actual human review through the native service
```task
id: FLEX-WP-0027-T03
status: wait
priority: high
state_hub_task_id: "9417d64a-308c-566f-af29-217c5c45d294"
```
Wait for the operator's exact signed-in account, then address the three memos
and verify actual human acknowledgements/entries. Synthetic policy checks are
not acceptance evidence. SECRETS-WP-0010-T03 retains live consume and execution.
2026-09-27: no operator sign-in has occurred yet. This is the only remaining
task and it is irreducibly a human action (the operator's own signed-in
account exercising the review), so the workplan is marked `blocked` rather
than `active` until that happens.