| id |
name |
namespace |
version |
status |
package |
allow_ttl |
actions |
owner |
fixtures |
caring |
activation |
| informed-decision.t03-review |
T03 exact OpenRouter lifecycle human review |
informed-decision:decision-memo |
v1 |
ready |
flexauth.informed_decision.t03_review |
30s |
| read |
| acknowledge |
| accept |
| return |
| discuss |
| decline |
|
flex-auth |
|
| profile |
enforce |
| caring-0.4.0-rc2 |
false |
|
|
Operator-admitted T03 review mandate
Operator confirmation on 2026-09-14 grants net-kingdom-admins review/bind
permission for only these three exact T03 records. The authenticated
informed-decision caller imports signed KeyCape groups and MFA facts.
No permission follows from memo content or presentation state. The independent
caller binding must be enforced by TokenReview before this package is served.
Membership tenant provenance may follow the explicitly accepted registration
route; it does not assert directory membership in tenant:platform.
Only a real human uses accept. This package neither issues nor consumes approval.
import rego.v1
records := {
"memo:SECRETS-WP-0010-T03-apply": {
"approval_id": "09592588-ab15-53e7-89b8-c4e9f29aaacf",
"binding_digest": "sha256:03cc5b37437f14e86b686ce4054f976556334eff3fa260b03e8014ed3d9217e5"
},
"memo:SECRETS-WP-0010-T03-verify": {
"approval_id": "9416fa31-fa9e-5603-8289-f35bc9625409",
"binding_digest": "sha256:72d9267d038c17107c880ffc9009793ce9c70defbddfe2219628854b811a04b2"
},
"memo:SECRETS-WP-0010-T03-exec": {
"approval_id": "da678b61-35be-598e-8d95-a7aefa2fdc73",
"binding_digest": "sha256:f2cf0fb53b740900756ccde5587c3578fcff44beef2f1edab17b9a198a4033d8"
}
}
decision := {"effect": "allow", "reason": "operator_admitted_t03_review"} if {
input.tenant == "tenant:platform"
input.subject.tenant == "tenant:platform"
input.subject.type == "human"
is_string(input.subject.id)
input.subject.id != ""
input.subject.attributes.principal_type_source == "authentication-derived"
input.subject.attributes.tenant_source in {"registration-supplied", "directory-asserted"}
"net-kingdom-admins" in input.subject.attributes.groups
assurance := input.subject.attributes.assurance
assurance.level == "aal2"
assurance.mfa == true
assurance.source == "key-cape"
assurance.methods == ["pwd", "otp"]
is_number(assurance.at)
assurance.at > 0
age := time.now_ns() / 1000000000 - assurance.at
age >= -30
age <= 900
input.resource.tenant == "tenant:platform"
input.resource.system == "informed-decision"
input.resource.type == "decision-memo"
record := records[input.resource.id]
input.context.memo_version == 1
input.context.approval_id == record.approval_id
input.context.approval_binding_digest == record.binding_digest
input.action in {"read", "acknowledge", "accept", "return", "discuss", "decline"}
} else := {"effect": "deny", "reason": "t03_review_scope_or_identity_refused"} if {
true
}
package flexauth.informed_decision.t03_review_test
import rego.v1
import data.flexauth.informed_decision.t03_review
test_unknown_request_denied if {
t03_review.decision.effect == "deny" with input as {}
}