Record accepted platform tenant and notify dependency owners
Some checks failed
ci / validate (push) Failing after 3m33s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0726e-5232-73f2-aaca-2c05ceb62efb
This commit is contained in:
tegwick 2026-09-06 21:48:12 +02:00
parent 59b042e637
commit a20b9f3861
5 changed files with 87 additions and 11 deletions

View file

@ -313,3 +313,9 @@ to lack tenant denial at v1; the owner correction v2 is now deployed at Helm
revision 2 and six live Check fixtures pass, including wrong_tenant denial.
Tenant choice, workstation caller access, audit load-bearing schema/admission,
identity/custody and native activation remain gates. T02 remains wait.
Tenant decision update (2026-09-06): operator approved `tenant:platform` for the
approval dependency chain as the platform management/services tenant. See
`docs/platform-tenant-decision.md`. The choice blocker is resolved; exact owner
configuration alignment and verification remain part of T02 before readiness.

View file

@ -98,7 +98,17 @@ consumer Deployment specs unchanged. Receipt file:
docs/evidence/GLAS-WP-0015-policy-v2-2026-09-06.json. Do not roll back to the
known over-permissive v1; if v2 cannot operate, stop this consumer release.
Operator tenant choice is pending. Follow-ups request live tracking of the
Operator tenant choice was pending at rollout and is resolved below. Follow-ups request live tracking of the
workstation caller path, independent Claude packaging, audit T03 then T09,
and correct v2 adoption. T03 remains progress until owner prerequisites are
verified; no real credential or model run has occurred.
## Accepted tenant choice — 2026-09-06
Operator approved exact `tenant:platform`, the platform management,
administration and services tenant (landlord zone). Recorded in
`docs/platform-tenant-decision.md` and State Hub; delivery receipts in
`docs/platform-tenant-decision-receipts.json`. The two proposed service clients,
approval store and lifecycle request must agree exactly. No alias or implicit
cross-tenant authorization. Existing owner threads receive the approved change;
T03 remains progress pending implementation evidence and other dependencies.