diff --git a/workplans/HUB-WP-0012-netkingdom-platform-root-access.md b/workplans/HUB-WP-0012-netkingdom-platform-root-access.md index 5d347c7..7d1d450 100644 --- a/workplans/HUB-WP-0012-netkingdom-platform-root-access.md +++ b/workplans/HUB-WP-0012-netkingdom-platform-root-access.md @@ -55,9 +55,10 @@ per-task sequencing, not a blanket wait for every related workplan to finish. ```task id: HUB-WP-0012-T01 status: wait +blocked_on: message-from:net-kingdom priority: high state_hub_task_id: "204f4fb0-e240-5558-8790-5985517b85e0" -blocked_on: "Contract reviewers' (NetKingdom, user-engine, tenant-engine, flex-auth) sign-off on the inventory and disputed rows" +blocking_reason: "Contract reviewers' (NetKingdom, user-engine, tenant-engine, flex-auth) sign-off on the inventory and disputed rows" ``` Owner: hub-core; contract reviewers: NetKingdom, user-engine, tenant-engine, @@ -88,9 +89,11 @@ platform-root login or enforcement test is claimed by inventory validation. ```task id: HUB-WP-0012-T02 status: wait +depends_on: [HUB-WP-0012-T01] +blocked_on: message-from:net-kingdom priority: high state_hub_task_id: "9a955fbf-f289-51b7-9682-bbe471694595" -blocked_on: "NetKingdom/KeyCape live root login, AAL2 enrollment acceptance, and User/Tenant Engine authenticated HTTP readers (contract published in docs/owner-facts-contract.md, no owner endpoint admitted yet)" +blocking_reason: "NetKingdom/KeyCape live root login, AAL2 enrollment acceptance, and User/Tenant Engine authenticated HTTP readers (contract published in docs/owner-facts-contract.md, no owner endpoint admitted yet)" ``` Live admission depends on T01; independently testable source may proceed. Owners: NetKingdom/KeyCape, user-engine and tenant-engine; @@ -114,9 +117,11 @@ step-up implementation is actually required. ```task id: HUB-WP-0012-T03 status: wait +depends_on: [HUB-WP-0012-T01] +blocked_on: message-from:flex-auth priority: high state_hub_task_id: "feea8f20-aad4-583b-958a-a8efeb9c133c" -blocked_on: "flex-auth production PDP deployment and signing-key delivery from platform owners (audit-core-senders routing entry to ops-mason/OpenBao is unresolved; no Hub sender credential minted)" +blocking_reason: "flex-auth production PDP deployment and signing-key delivery from platform owners (audit-core-senders routing entry to ops-mason/OpenBao is unresolved; no Hub sender credential minted)" ``` Depends on T01; live acceptance also needs T02. flex-auth owns the protected @@ -139,9 +144,10 @@ substituted for evidence of production custody and delivery. ```task id: HUB-WP-0012-T04 status: wait +depends_on: [HUB-WP-0012-T02, HUB-WP-0012-T03] priority: high state_hub_task_id: "15bc3cae-4575-56c9-afd2-e1e348109ca9" -blocked_on: "T02/T03 live admission; private full-root browser/API/MCP journeys need a real root login and PDP, which do not exist yet" +blocking_reason: "T02/T03 live admission; private full-root browser/API/MCP journeys need a real root login and PDP, which do not exist yet" ``` Live admission depends on T02/T03; the default-deny source seam may proceed. Add the reusable verified actor/tenant context and local @@ -163,9 +169,10 @@ bounded migration/rollback paths without a public bypass. ```task id: HUB-WP-0012-T05 status: wait +depends_on: [HUB-WP-0012-T04] priority: high state_hub_task_id: "6d29854e-e894-5340-9e13-8866e80246f4" -blocked_on: "T04 live admission" +blocking_reason: "T04 live admission" ``` Depends on T04. Publish the versioned extension security profile and harness. @@ -186,9 +193,11 @@ parity, retention and zero-traffic gates. This task does not claim retirement. ```task id: HUB-WP-0012-T06 status: wait +needs_human: true +depends_on: [HUB-WP-0012-T04, HUB-WP-0012-T05] priority: high state_hub_task_id: "97b0b242-e9a7-53cd-941f-a1822fcf93a5" -blocked_on: "T04/T05 live admission and Railiance/platform owners' attended receipts" +blocking_reason: "T04/T05 live admission and Railiance/platform owners' attended receipts" ``` Depends on T04/T05 and the external owners for each T01 row. Integrate the same @@ -209,9 +218,10 @@ another service. Any missing backend integration keeps M1 open. ```task id: HUB-WP-0012-T07 status: wait +depends_on: [RAPPCOREHUB-WP-0002-T05] priority: high state_hub_task_id: "0c15cb82-7c59-5a44-8bf0-857ea4438642" -blocked_on: "M1 acceptance; owner: rapp-core-hub via RAPPCOREHUB-WP-0002-T05" +blocking_reason: "M1 acceptance; owner: rapp-core-hub via RAPPCOREHUB-WP-0002-T05" ``` Depends on M1. Owner: rapp-core-hub through existing RAPPCOREHUB-WP-0002-T05,