docs: inventory Hub and platform access boundaries for root integration
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e715-b802-70f0-a8fa-590d9ee673a5
This commit is contained in:
parent
e5b67b391d
commit
1182b637c7
5 changed files with 8275 additions and 5 deletions
|
|
@ -4,7 +4,7 @@ type: workplan
|
|||
title: "NetKingdom identity and tenant integration: platform-root first"
|
||||
domain: infotech
|
||||
repo: hub-core
|
||||
status: proposed
|
||||
status: active
|
||||
flavor: implementation
|
||||
owner: codex
|
||||
topic_slug: infotech
|
||||
|
|
@ -43,7 +43,7 @@ existing retirement and rollout plans retain their tasks. Core Hub receives no
|
|||
new product feature work. This planning session does not implement or activate
|
||||
grants, enroll factors, deploy policies, expose services or retire State Hub.
|
||||
|
||||
Status is proposed because cross-owner policy, root identity binding and live
|
||||
Inventory work is active. Cross-owner policy, root identity binding and live
|
||||
acceptance are not yet reviewed. The user has selected the root-first scope;
|
||||
there is no need to reopen that product decision. Dependencies below are
|
||||
per-task sequencing, not a blanket wait for every related workplan to finish.
|
||||
|
|
@ -52,7 +52,7 @@ per-task sequencing, not a blanket wait for every related workplan to finish.
|
|||
|
||||
```task
|
||||
id: HUB-WP-0012-T01
|
||||
status: todo
|
||||
status: progress
|
||||
priority: high
|
||||
state_hub_task_id: "204f4fb0-e240-5558-8790-5985517b85e0"
|
||||
```
|
||||
|
|
@ -70,6 +70,16 @@ Done when no published route/tool or active platform surface lacks a row and
|
|||
owner, contract reviewers' decisions are recorded, and M1 success/deny cases
|
||||
are executable specifications. Unknown/disputed rows remain visible blockers.
|
||||
|
||||
2026-09-28: the [access inventory](../docs/platform-access-inventory.md) now
|
||||
enumerates 161 Hub source surfaces and 48 platform/extension boundaries, covering
|
||||
250 observed cluster objects. Its machine-readable profiles specify owners,
|
||||
audiences, actor/target tenants, enforcement and acceptance cases; the checker
|
||||
detects source drift and incomplete object mappings. Duplicate docs handlers,
|
||||
legacy MCP targets and unresolved native/extension paths are explicit findings.
|
||||
Owner review, effective host/per-service route expansion, policy vocabulary and
|
||||
authenticated acceptance remain open, so T01 is `progress`, not `done`. No
|
||||
platform-root login or enforcement test is claimed by inventory validation.
|
||||
|
||||
## T02 — Bind platform-root identity, login, tenant and revocation
|
||||
|
||||
```task
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue