This is a source/configuration review plus read-only runtime observation, not
an authenticated platform-root acceptance test. No account, token, role,
policy, public listener, or production workload was changed.
| Boundary | Observed state on 2026-09-28 | Consequence |
| --- | --- | --- |
| Hub Core | `runtime/app.py` mounts `ports.py` without a global authorization dependency; native registration, messaging, events and generic projections lack a verified subject/tenant context | Enforce access in the service and SDK, not only at Ingress |
| Compatibility API | `runtime/compat.py::_protected` accepts a shared configured bearer or an imported consumer key; no resource/tenant decision follows | Replace broad bearer authority with authenticated principal plus action authorization |
| MCP | Separate runtime/transport and reusable host wrapper | Inventory every tool and carry caller identity to the same protected API; no server-wide root token |
| Inbox pilot | Snapshot GET reader uses the shared token and literal `state-hub` recipient | Keep private; caller migration remains HUB-WP-0011, not a completed retirement slice |
| Extension conformance | HUB-WP-0009 finished C2/C7/C9/C10; its explicit tenant-isolation gap has no implementation | This workplan owns the new security profile; 0.1 conformance is insufficient for exposure |
| Identity | Live issuer discovery at `https://kc.coulomb.social` advertises S256, authorization code and client credentials; KeyCape, Authelia, LLDAP and identity-provisioner Deployments Ready | Reuse the issuer; no second identity database or new IdP |
| User and tenant management | User Engine and Tenant Engine Deployments Ready; USER-WP-0030 and NK-WP-0038 finished | Reuse account lifecycle and tenant authority; readiness does not prove this root account's effective grants |
| Policy | Six service-specific flex-auth Deployments Ready; none for Hub Core | Register a protected system and owner-managed policy deployment; don't borrow another consumer's PDP/credentials |
| Hosting | Core Hub legacy/candidate/publisher Ready; revision 28 has Ingress off | Keep private until the new admission gate; the earlier public grant alone does not satisfy this request |
| Current external blockers | Public host presents Traefik default certificate; publisher accepts 113/123 with nine private-source errors and an identity-canon registry mismatch | Existing RAPPCOREHUB-WP-0002/0003 retain these operational obligations |
Source findings use the current checkout. Live hub image remains the September 5
pin, so later source conformance changes are not claimed deployed. The root
account's immutable subject, effective memberships, MFA and revocation behavior
still require an attended, non-secret acceptance receipt.
streaming/MCP and event replay; no cross-tenant existence/count leak. Classify
legacy unlabelled records explicitly as platform-owned or quarantine them;
never infer their tenant from the current viewer. Platform-root may administer
them through its explicit platform grant. Non-root multi-tenant admission waits
for Phase 2 data migration and isolation tests.
## Retirement integration and sequencing
| Existing owner record | Relationship to this work |
| --- | --- |
| HUB-WP-0004/0005, CORE-WP-0010 | Runtime selection/absorption already decided; implement here, retain Core Hub rollback privately; no new feature lane in Core Hub |
| HUB-WP-0009 | Existing contract checks stay finished; this work owns the missing identity/tenant conformance profile |
| HUB-WP-0011 | Reuse the new caller/context seam for T02; inbox freshness, retention, recipient/alias semantics and reader switch stay there |
| STATE-WP-0079 | Authentication does not close its 425-item disposition, single-writer, parity, metering or retirement gates; apply the security gate per slice |
| RMGR-WP-0001/0002/0003 | Git/file authority stays in Repo Manager; Hub Core views and invokes governed owner APIs |
| OPS-WP-0003; ACTIVITY-WP-0029 | Existing extension and event/schedule alignment finished; add security conformance/caller migration without reopening completed tasks |
| FIN-WP-0003; RAIL-FAB-WP-0028 | Fabric authority stays specialized; hosted Fabric is blocked independently; integrate the available owner surface and report missing runtime evidence |
| RAPPCOREHUB-WP-0002/0003/0004 | Packaging/exposure, publisher credential gate and completed private inbox pilot retain their owners |
| NK-WP-0038/0039/0042; USER-WP-0030; TEN-WP-0012 | Reuse delivered identity/admin behavior; respect pending coordinate, step-up and tenant conformance work rather than claim them complete |
Implement shared contracts and platform-root access privately first. Exercise
one extension (ops-hub), actual workload callers and Railiance owner paths, then
complete the platform access matrix. Gate each State Hub reader/writer move on
the same identity checks plus that slice's existing data/freshness gates.
Do not add permanent authentication/tenant authority to retiring State Hub.
Public enablement is a separate final gate under RAPPCOREHUB-WP-0002: authenticated