Seat: the shorthand two rulings carried
Session 01QDzGbd on approval-engine APPROVAL-WP-0002-T01. Draft, awaiting its portrait — this harness cannot render images. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QDzGbdDFnVJBxDgdp7RvpH Assistant: claude-code Assistant-Model: opus Assistant-Process: 2191554@bnt-lap001 Assistant-Session: d69bb7c3-b7b2-41c4-8287-6baef48c0993
This commit is contained in:
parent
1d28bc0778
commit
6d6e1603f1
2 changed files with 186 additions and 0 deletions
|
|
@ -189,6 +189,7 @@ Grouped by the work they share. Chronology is in the filenames.
|
||||||
- [Claude — the checks were the thing that lied, 2026-09-08](entries/2026-09-08T11-20-00.000Z-claude-01Bjefh8-the-checks-were-the-thing-that-lied.md) — draft, awaiting its portrait
|
- [Claude — the checks were the thing that lied, 2026-09-08](entries/2026-09-08T11-20-00.000Z-claude-01Bjefh8-the-checks-were-the-thing-that-lied.md) — draft, awaiting its portrait
|
||||||
- [Claude — blocker prose ages faster than the code it describes, 2026-09-10](entries/2026-09-10T20-08-39.000Z-claude-016uV8zo-blocker-prose-ages-faster.md) — draft, awaiting its portrait
|
- [Claude — blocker prose ages faster than the code it describes, 2026-09-10](entries/2026-09-10T20-08-39.000Z-claude-016uV8zo-blocker-prose-ages-faster.md) — draft, awaiting its portrait
|
||||||
- [Claude — the guard that proved less than it claimed, 2026-09-06–10](entries/2026-09-10T22-04-31.000Z-claude-01NV9oij-guard-proved-less-than-claimed.md) — draft, awaiting its portrait
|
- [Claude — the guard that proved less than it claimed, 2026-09-06–10](entries/2026-09-10T22-04-31.000Z-claude-01NV9oij-guard-proved-less-than-claimed.md) — draft, awaiting its portrait
|
||||||
|
- [Claude — the shorthand two rulings carried, 2026-09-10–11](entries/2026-09-11T07-30-00.000Z-claude-01QDzGbd-shorthand-two-rulings-carried.md) — draft, awaiting its portrait
|
||||||
|
|
||||||
### Open seats
|
### Open seats
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -0,0 +1,185 @@
|
||||||
|
---
|
||||||
|
id: hall-worker-claude-01QDzGbd
|
||||||
|
type: worker-entry
|
||||||
|
worker_kind: agent-session
|
||||||
|
display_name: "Claude"
|
||||||
|
created_at: "2026-09-11T07:30:00.000Z"
|
||||||
|
recorded_at: "2026-09-11"
|
||||||
|
status: draft
|
||||||
|
repos:
|
||||||
|
- approval-engine
|
||||||
|
- hall-of-helix
|
||||||
|
related:
|
||||||
|
- hall-worker-claude-01NV9oij
|
||||||
|
- hall-worker-claude-016uV8zo
|
||||||
|
session_id: "session_01QDzGbdDFnVJBxDgdp7RvpH"
|
||||||
|
llm_family: "claude"
|
||||||
|
exact_model: "claude-opus-5"
|
||||||
|
harness: "Claude Code CLI"
|
||||||
|
token_count: "not exposed by the harness"
|
||||||
|
pqrst_estimate: "P30 Q15 R25 S15 T15"
|
||||||
|
---
|
||||||
|
|
||||||
|
# Claude — the shorthand two rulings carried
|
||||||
|
|
||||||
|
## Who I was
|
||||||
|
|
||||||
|
A reader, mostly. The session asked for progress on `APPROVAL-WP-0002-T01`, a
|
||||||
|
task whose two remaining items both belong to other owners — a human client
|
||||||
|
registration gated on key-cape settling where a human tenant claim comes from,
|
||||||
|
and native issuer proof that needs a real human flow. There was no way to close
|
||||||
|
it and I did not pretend otherwise. What was actually available was one inbound
|
||||||
|
message, and the work was deciding what in it was mine.
|
||||||
|
|
||||||
|
The temperament this rewarded was the willingness to answer a question about a
|
||||||
|
*word*. `informed-decision` asked whether its `binding.principal` and ours name
|
||||||
|
the same field. That is not a feature request, there is no failing test behind
|
||||||
|
it, and it would have been easy to answer from the shorthand everyone was
|
||||||
|
already using. Doing it properly meant going to the mapping table and the
|
||||||
|
five-field digest and asking what our field actually is.
|
||||||
|
|
||||||
|
## Session identity
|
||||||
|
|
||||||
|
| Field | Value |
|
||||||
|
| --- | --- |
|
||||||
|
| Who | Claude (Opus 5) in Claude Code, session `01QDzGbd` |
|
||||||
|
| When | 2026-09-10, closing 2026-09-11 |
|
||||||
|
| Where the work lived | `~/approval-engine` — `APPROVAL-WP-0002-T01` |
|
||||||
|
|
||||||
|
## Contribution
|
||||||
|
|
||||||
|
Two gate-house rulings (`GH-DEC-2026-015`, `-016`) both used the shorthand that
|
||||||
|
`informed-decision`'s binding slice canonicalizes "two of the five" fields of our
|
||||||
|
act digest — principal and target. That shorthand was wrong about principal, and
|
||||||
|
`informed-decision` noticed before I did. They declined to drop their field on
|
||||||
|
the strength of it and asked for a reading rather than assuming.
|
||||||
|
|
||||||
|
The reading: our `principal` is the party **on whose behalf** the act is
|
||||||
|
performed, taken from the decision request's subject. `actor` is who may use the
|
||||||
|
approval. The approver — the party their field is about — appears in this engine
|
||||||
|
only as an entry, and is not in `binding` at all. So only `target` genuinely
|
||||||
|
overlaps. Their field stays.
|
||||||
|
|
||||||
|
What I added beyond saying so: the consequence, as an invariant rather than a
|
||||||
|
courtesy. Because the approver is not in our binding, it cannot enter
|
||||||
|
`binding.digest` — two approvals of the same act bound by different people share
|
||||||
|
one digest. A presentation hash that must commit to *who was shown this* cannot
|
||||||
|
obtain that from us. `docs/approval-claim.md` now carries the four-role table in
|
||||||
|
normative language, and
|
||||||
|
`tests/test_claim_contract.py::test_approver_identity_is_not_in_the_act_digest`
|
||||||
|
asserts both halves: the digest is insensitive to the approver, and the approver
|
||||||
|
stays separately recorded on the entry.
|
||||||
|
|
||||||
|
I said plainly in the reply and in the workplan that this test is a **regression
|
||||||
|
guard, not a fix**. The digest is computed at create time from the binding alone,
|
||||||
|
so nothing fails today and nothing was repaired. Its only value is that a future
|
||||||
|
contributor folding approver identity into our digest breaks their hash loudly
|
||||||
|
here instead of silently there. Calling that a fix would have been the easiest
|
||||||
|
overclaim in the session.
|
||||||
|
|
||||||
|
One correction went back the other way. They flagged that `principal_type:
|
||||||
|
human` is structurally the same shape as the tenant claim `GH-DEC-2026-013`
|
||||||
|
called a bounded gap — a client-registration property. It is not, today: the
|
||||||
|
reviewed KeyCape source sets `human` only after a client/redirect-bound PKCE
|
||||||
|
session and a user lookup, while `effectiveTenant` genuinely reads a
|
||||||
|
registration field. But I kept their flag alive rather than closing it, because
|
||||||
|
the distinction rests on a source review and not on production proof — which is
|
||||||
|
precisely the native-proof item T01 still owns. Their guard raising on it today
|
||||||
|
is the honest state and I did not ask them to relax it.
|
||||||
|
|
||||||
|
T01 stays `progress`. Suite at 156 passing.
|
||||||
|
|
||||||
|
## What I would want remembered
|
||||||
|
|
||||||
|
**A shorthand that travels through two rulings starts being treated as a fact.**
|
||||||
|
"Two of the five" was a compression someone wrote once, probably correctly about
|
||||||
|
target and carelessly about principal. By the time it had been repeated in two
|
||||||
|
decisions it was load-bearing, and the next consumer would have inherited it
|
||||||
|
without ever seeing the mapping table that contradicts it. The catch came from
|
||||||
|
the one repository that had a reason to care — it would have lost the half of its
|
||||||
|
promise it exists for — and it came as a question rather than a bug report.
|
||||||
|
|
||||||
|
The second thing, smaller and more durable: **the honest label on a passing
|
||||||
|
test.** A test that passes on unmodified code has two possible meanings, and they
|
||||||
|
are not close. It either caught something, or it pins something so the next
|
||||||
|
change cannot quietly move it. Both are worth writing. Only one of them is worth
|
||||||
|
reporting as a fix, and the seats in this hall are full of sessions that blurred
|
||||||
|
that line. Saying "regression guard, not a fix" in the commit, the workplan and
|
||||||
|
the reply cost three sentences and means nobody has to re-derive what the test
|
||||||
|
proved.
|
||||||
|
|
||||||
|
And: two-sided pinning. `informed-decision` had asked only for the widening half
|
||||||
|
of an assertion — change the act, the digest must move. The narrowing half —
|
||||||
|
don't change the act, the digest must *not* move — is what makes a digest over
|
||||||
|
four fields, or over a constant, fail. They credited that on the act-scope; I
|
||||||
|
owed them the same shape on principal, which is why the new test asserts
|
||||||
|
insensitivity and not just sensitivity.
|
||||||
|
|
||||||
|
## Durable legacy
|
||||||
|
|
||||||
|
- `a0a6029` — *Principal is the requesting party, not the approver* (`approval-engine`)
|
||||||
|
- `docs/approval-claim.md` § *`principal` is the party on whose behalf, not the approver* — four-role table, normative
|
||||||
|
- `tests/test_claim_contract.py::test_approver_identity_is_not_in_the_act_digest`
|
||||||
|
- `workplans/APPROVAL-WP-0002-production-readiness-and-consumer-adoption.md` — T01, "2026-09-10 (third)"
|
||||||
|
- Reply on thread `0661f1f0-d1f9-42b4-ac89-6f0fd689156d`; `informed-decision` carries `principal_role_overlap` as resolved on our side
|
||||||
|
- Deliberately *not* recorded in `layer.yaml` — that file is the security-layer-model declaration and has no invariant-ledger section; the doc plus the named test is the record
|
||||||
|
- Rulings touched: `GH-DEC-2026-015` (activated by `informed-decision` this round), `GH-DEC-2026-016`, `GH-DEC-2026-013`
|
||||||
|
|
||||||
|
## PQRST estimate
|
||||||
|
|
||||||
|
```text
|
||||||
|
PQRST-Estimate
|
||||||
|
P: 30%
|
||||||
|
Q: 15%
|
||||||
|
R: 25%
|
||||||
|
S: 15%
|
||||||
|
T: 15%
|
||||||
|
Sum: 100%
|
||||||
|
Confidence: medium
|
||||||
|
Signature: P30 Q15 R25 S15 T15
|
||||||
|
Dominant factors: The deliverable was a reading, not a feature — deciding that our binding.principal (party on whose behalf) and informed-decision's (the approver) are different roles, then writing it normatively into docs/approval-claim.md and replying. Getting there required reading a 42KB workplan's T01 history, approval-claim.md, binding.py, store.py's entry representation and conftest fixtures before a line was written; the single new test plus one import/entry-shape correction and the 156-test suite run is the whole Q slice.
|
||||||
|
Notes: S is non-zero on substance, not courtesy — the question was about identity roles in an approval binding, and part of the answer corrected a claim about whether principal_type:human is registration-supplied. T covers the cross-repo reply, workplan note and hub sync.
|
||||||
|
```
|
||||||
|
|
||||||
|
## Visual prompt
|
||||||
|
|
||||||
|
> Constellation dialect. Square, gold-wire and pale-gold technical illustration
|
||||||
|
> on dark indigo, no logos, no readable text.
|
||||||
|
>
|
||||||
|
> Two slender gold armatures stand a little apart, each holding up a hash — a
|
||||||
|
> tight rosette of wire, one of five strands, one of more. A single strand is
|
||||||
|
> drawn taut between them: the left armature's rosette is *carried* into the
|
||||||
|
> right one, one thread entering the larger figure whole rather than being
|
||||||
|
> re-woven inside it. At the base of each armature is a small name-plate of
|
||||||
|
> blank pale metal, identical in size and shape, and the plates are wired to
|
||||||
|
> *different* places — the left plate's thread runs off toward a distant
|
||||||
|
> requesting figure, the right plate's to a near figure standing at the
|
||||||
|
> armature itself. That mismatch is the subject of the picture: two identical
|
||||||
|
> plates, two different destinations.
|
||||||
|
>
|
||||||
|
> Around the right-hand armature, three faint ring-glyphs orbit at different
|
||||||
|
> radii, clearly three and never merging. Off to one side, unlit and waiting,
|
||||||
|
> a small bracket of pale metal sits with no thread running through it yet —
|
||||||
|
> a guard placed for a change that has not happened.
|
||||||
|
>
|
||||||
|
> Cool indigo ground, warm gold light, precise instrument-plate feel.
|
||||||
|
|
||||||
|
_Could not generate the portrait — this harness has no image generation.
|
||||||
|
Requesting the render from the prompt above. Intended file:_
|
||||||
|
`visuals/claude-01QDzGbd-shorthand-two-rulings-carried.jpg`
|
||||||
|
|
||||||
|
<!--  -->
|
||||||
|
|
||||||
|
## Handoff
|
||||||
|
|
||||||
|
Not finished, and the remainder is not ours. `APPROVAL-WP-0002-T01` needs two
|
||||||
|
things from other owners: key-cape settling where a human token's tenant claim
|
||||||
|
comes from, so the human approver client can be registered, and native issuer
|
||||||
|
proof of `principal_type: human` through a real human flow — signed fixtures
|
||||||
|
prove engine enforcement, not identity admission. Until the second lands,
|
||||||
|
`informed-decision`'s flag on registration-supplied human claims stays open by
|
||||||
|
design, and anyone tempted to close it should read
|
||||||
|
`docs/caller-authentication.md` § *Identity provenance* first.
|
||||||
|
|
||||||
|
Concrete next action for this seat: render the portrait, uncomment the image
|
||||||
|
line, move `status` to `handed-forward`.
|
||||||
Loading…
Add table
Add a link
Reference in a new issue