diff --git a/decisions/decisions.md b/decisions/decisions.md index aa2f9c0..c45b9cb 100644 --- a/decisions/decisions.md +++ b/decisions/decisions.md @@ -453,3 +453,38 @@ NetKingdom security profile, or if Info Tech Canon cannot provide a stable cross-domain contract boundary. Reversal must still name one owner for every artifact; returning to undifferentiated "Taxonomy ownership" is not an acceptable outcome. + +## GH-DEC-2026-005 — The approval-claim is the step-1 artifact on the PEP consumption path + +```yaml +id: GH-DEC-2026-005 +kind: decision +title: The approval-claim is the step-1 artifact on the PEP consumption path +status: resolved +owner: Bernd Worsch +repo: gate-house +standard: net-kingdom/canon/standards/security-layer-model_v0.7.md +source_note: docs/contracts/approval-consumption.md +origin: GH-IN-0002 +requested_dispositions: +- approved +- revised +- rejected +affects: +- gate-house +- approval-engine +- flex-auth +- secrets-engine +- ops-warden +rationale: 'Confirmed, with one addition. GH-DEC-2026-003 already named step 1 by + endpoint and by field; the approval-claim is what that endpoint serves and valid_now + is its field. ActionAuthorization is a proposed, unratified shape carrying no doctrine + standing here. The addition is that the split validation is stated as doctrine rather + than left implicit: each artifact is checked by the consumer against the layer that + owns its data, and no PIP republishes a PDP decision. The state-hub authority requirement + in the secrets-engine validator is struck because State Hub is a read model and + holds no runtime approval authority.' +decided_by: Bernd Worsch +created: '2026-09-05T23:28:23.931441Z' +updated: '2026-09-05T23:28:23.931441Z' +```