gate-house/decisions
tegwick 16c1d46d5d Rule the tenant-provenance question: bounded gap, and the claim must say which
key-cape has no adapter populating the directory user tenant, so every
human token fell back to the default and approval-engine refused it by
exact match — presenting as a failed approval rather than as a
registration defect. It built a registration-bound resolution, then
declined to ratify its own design because the second option writes a
cross-tenant capability into the issuer. That reading was right and the
question is ours: what may be a source of a principal's identity is a
Core Rule, not a runbook.

Directory-sourced is the terminal state. A registration is a statement
about the actor; a tenant is a property of the principal; sourcing the
second from the first collapses two identities the estate keeps
distinct, in the direction that widens.

The registration-bound shape is admissible anyway, as a declared
bounded gap, and the reason is not that the design is careful. It is
that the case distinguishing it from the correct resolution fails
closed: where registration and directory disagree, issuance is refused
rather than resolved either way. And the same code turns from supplying
the zone into enforcing agreement with it the moment the directory
carries tenants, so it converges by subtraction.

That general property is section 3 and neither request asked for it.
A transitional shape is admissible where it fails closed on exactly the
case that distinguishes it from the correct resolution, and
inadmissible where it fails open there. It is section 8's asymmetry
applied to transitions, and it is what makes this grant and
GH-DEC-2026-011's decline one rule rather than two defensible calls: a
promise that fails open is a permission, a promise that fails closed is
a gap, and only the second is a thing a register can hold.

Two conditions strengthen what key-cape wrote about itself. Refusal on
disagreement is normative, including against a future change that
prefers the directory — picking any winner converts a refusal into a
silent cross-tenant assertion. And lifting the dynamic-registration
exclusion voids the rule rather than reopening it; key-cape wrote "must
be revisited", which implies the answer might survive review, and it
would not.

The finding they did not ask for is section 5. The tenant claim is a
bare string, so a consumer cannot tell a tenant the directory asserted
about the person from one a registration supplied about the client they
came through. approval-engine exact-matches that string and is relying
on the second while its contract reads as the first. That is
GH-DEC-2026-010 one layer down — a sound check whose reader infers a
property it does not carry. The claim must carry its provenance;
the mechanism is key-cape's.

Gap registered at net-kingdom@f9e1611.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012viPor8WJNCbV64ipwewrm

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1754332@bnt-lap001
Assistant-Session: 9c8ac536-ff5e-46a3-8ab1-a548bde25fc0
2026-09-09 23:20:42 +02:00
..
decisions.md Rule the tenant-provenance question: bounded gap, and the claim must say which 2026-09-09 23:20:42 +02:00