flex-auth/.custodian-brief.md
custodian-sync 61e24b0f40
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-09-06:
  - update .custodian-brief.md for flex-auth

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 715613@bnt-lap001
Assistant-Session: fabd95c1-4c9e-4080-8849-8707ae025f80
2026-09-06 22:45:50 +02:00

1.3 KiB

Custodian Brief — flex-auth

Domain: infotech
Last synced: 2026-09-06 20:45 UTC
State Hub: http://127.0.0.1:8000 (adjust if running on a remote machine)

Active Workstreams

Sign the decision envelope: the response channel is unauthenticated

Progress: 1/4 done | workplan_id: 90577acd-6910-548d-a13e-1dbfdfb8ed27

Open tasks:

  • ! 3. Implement signing and verification 041612ea
  • ! 4. Report the gap to gate-house 82d6b75e
  • · 2. Choose the signature shape and key custody 5482f3cd

Operator caller access path and caller identity in the decision record

Progress: 0/5 done | workplan_id: ad011f92-786c-51ad-b3f6-c06ad77e7af7

Open tasks:

  • ! 2. Run the positive and negative tests and return the receipts 79a8d82d
  • ! 3. Flip callerAuth.mode to enforce 8117c9d8
  • ! 5. Report the gap to gate-house as a v0.8 finding d685abfc
  • · 1. Create the ServiceAccount the deployed binding already names 10e5a40c
  • · 4. Record the authenticated caller in the decision record c0e4f31a

MCP Orientation (when available)

If the state-hub MCP server is reachable, call: get_domain_summary("infotech") This provides richer cross-domain context. If the MCP call fails, use this file as your orientation source.