diff --git a/docs/owner-facts-contract.md b/docs/owner-facts-contract.md index e9beb70..654270e 100644 --- a/docs/owner-facts-contract.md +++ b/docs/owner-facts-contract.md @@ -20,8 +20,18 @@ composition; **no admitted HTTP adapter or production authority source**. An admitted authenticating gateway could supply that boundary, but no such composition is established by these sources. -These are source findings, not probes of deployed configurations. No owner -repository, database, grant or credential was modified. +These are source findings, not probes of deployed configurations. The follow-up +User Engine commit `686da7c` adds `UserEngineService.lookup_account_authority`: +an authorized exact issuer/subject/tenant lookup that never provisions a missing +identity, returns current global and scoped account status (missing scoped state +is explicit), and separates caller from target. The new policy action is +`account.authority.read`; existing generic read grants are not assumed sufficient. +Its result includes source observation time, identity/account references and the +policy decision reference, but no root entitlement or profile data. + +This closes the read-only **service primitive**, not the wire contract or admitted +Hub workload. USER-WP-0037 owns root-grant/mapping disposition and authenticated +HTTP exposure/private acceptance. No database, live grant or credential changed. ## Contract for owner disposition diff --git a/workplans/HUB-WP-0012-netkingdom-platform-root-access.md b/workplans/HUB-WP-0012-netkingdom-platform-root-access.md index 6ae10ac..76f560a 100644 --- a/workplans/HUB-WP-0012-netkingdom-platform-root-access.md +++ b/workplans/HUB-WP-0012-netkingdom-platform-root-access.md @@ -497,6 +497,22 @@ Validation: **433 ordinary tests** and **six disposable PostgreSQL tests** pass; full `make ci-check` inventory/build/isolated-wheel checks pass. The facts module is included in the distribution. +## User Engine lookup implementation — 2026-09-28 + +Implemented and committed User Engine `686da7c`: an independently authorized +`lookup_account_authority` service operation for exact issuer/subject/tenant. +It never provisions unknown identities, returns current global/scoped state, +keeps caller separate from lookup target, and exposes no root grant or profile +PII. Unknown, disabled, missing-scoped-account and denied lookups have tests. +User Engine `make test` ran **270 tests** successfully with eight optional skips; +layer conformance passed. The six new checks use local fixtures. + +USER-WP-0037-T01 is done. Its T02 tracks root-entitlement/mapping disposition; +T03 tracks authenticated workload HTTP exposure and private acceptance. Hub's +[owner contract](../docs/owner-facts-contract.md) records this service primitive +without treating it as a connected HTTP adapter. T01/T02 here remain `progress`. +No Tenant Engine source, live credential/grant or deployment was changed. + ## Acceptance checkpoints - [x] Architecture/source/runtime review captured; new implementation owner is hub-core