informed-decision/docs/batches/2026-09-14/policy-request.md

38 lines
1.6 KiB
Markdown
Raw Normal View History

# Flex Auth policy request — compact sitting
Not admitted. Not a local allow. Not an expansion of the T03 three-record
mandate (`FLEX-WP-0027`, `examples/informed-decision-t03`).
`net-kingdom-admins` may review these eight Decision Memos **only after**
the operator admits a new package that pins exact `memo_id`, `approval_id`
and native `binding.digest`. Until those approval objects exist, this file
is a request shape, not a compilable package.
## Intended allow (same identity bar as T03)
- caller: `system:serviceaccount:informed-decision:review` via TokenReview
- subject: verified human, `tenant:platform`, group `net-kingdom-admins`,
KeyCape AAL2 MFA facts as in the T03 package
- actions: `read`, `acknowledge`, `accept`, `return`, `discuss`, `decline`
- deny every other resource id
- no consume, no approval create, no presentation claim as policy input
## Exact resource ids (approval ids still unknown)
| resource.id | Blocking record |
| --- | --- |
| `memo:infd-20260914-c01` | SECRETS-WP-0010 native delivery |
| `memo:infd-20260914-c02` | RPF-WP-0035-T02 |
| `memo:infd-20260914-c03` | NK-WP-0032-T03 |
| `memo:infd-20260914-c04` | WARDEN-WP-0027-T02 |
| `memo:infd-20260914-d01` | CUST-WP-0038-T08 |
| `memo:infd-20260914-d02` | HFACT-WP-0001-T03 |
| `memo:infd-20260914-d03` | MASON-WP-0005 plan |
| `memo:infd-20260914-d04` | RCLK-WP-0002-T01 |
Do not copy T03 approval ids into this table. Do not serve this list as
policy until a created-receipt supplies `approval_id` and `binding.digest`
for every row.
Owner: flex-auth. This repository drafts; it does not evaluate authorization.