docs: reconcile Claude readiness with authorization chain proof
All checks were successful
ci / validate (push) Successful in 1m32s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0726e-5232-73f2-aaca-2c05ceb62efb
This commit is contained in:
tegwick 2026-09-06 19:21:56 +02:00
parent 27a72537b2
commit c67a22dbe2
3 changed files with 42 additions and 2 deletions

View file

@ -258,3 +258,24 @@ record an unresolved approval/native action-vocabulary and embedded-claim
digest mismatch for dual-control requests. This is owner integration evidence,
not successful live activation; SECRETS-WP-0009-T03 remains wait. No new
activation receipt was found in the Glas inbox. T02 remains waiting.
## 2026-09-06 authorization-chain owner return
Reviewed secrets-engine `f62d3fe` / `64aeec9`. Owner reports claim → Check →
consume → backend integration against a throwaway OpenBao, including denial,
unreachable service, invalid claim, missing digest, consume conflict and action
mismatch refusal before backend access. Authorization transport is stubbed;
wire shapes use published flex-auth fixtures. Do not describe this as a live
production service or Anthropic delivery proof.
Owner now identifies deployment/configuration as the remaining live gate:
consumer PDP service and approval-engine rollout, production service
credentials, deployed policy pin and per-lane authorization id.
SECRETS-WP-0009-T03 remains wait. Earlier digest-defect notes are historical;
use this latest owner return for the integration status. Native lane positive/
negative access checks, pinned Claude startup, provider scope/budget inputs and
combined Glas acceptance remain outstanding. T02T05 stay wait.
Review found no pending local changes or new inbox messages. Corrected stale
README wording that still called owner execution missing; the implemented
mechanism and its separate proofs do not change profile readiness.