informed-decision/docs/sitting-requester-custody-request.yaml

52 lines
1.7 KiB
YAML
Raw Normal View History

# Request only. railiance-platform allocates the CCR id.
# status is requested — not applied, not approved, no secret values.
id: unallocated
kind: credential-change-request
schema_version: 1
request_type: workload-kv-read
title: Informed Decision sitting-requester KeyCape client secret (verifier + attended reader)
status: requested
created: "2026-09-14"
updated: "2026-09-14"
origin: INFD-WP-0002-T03
origin_ref: informed-decision/docs/keycape-sitting-requester-registration.md
requester:
agent: grok
reason: >-
Compact sitting needs a create-only presenter whose binding.actor is
informed-decision. Do not widen CCR-2026-0024/0025 or secrets-engine-requester.
review:
required: true
required_approvers:
- platform-operator
- key-cape-owner
target:
domain: infotech
tenant: platform
workload: informed-decision
environment: production
purpose: create-only sitting requester; work-record decisions, not PEP consume
openbao:
mount: platform
kv_path: platform/workloads/informed-decision/sitting-requester
fields:
- CLIENT_SECRET
delivery:
surface: external-secrets
env_name: KEYCAPE_INFORMED_DECISION_SITTING_REQUESTER_CLIENT_SECRET
risk:
classification: high
notes:
- Scope must remain approval:create only.
- Human disposition uses informed-decision-approver (public PKCE).
- infd-20260914-c01 may stay on secrets-engine-requester if consume is in-scope.
verification:
negative:
- approval:approve and approval:consume refused at token exchange
- sibling secrets-engine/approval-requester denied
- parent listing denied
activation_conditions:
- KeyCape row exists
- attended CAS=0 write to this path only
- no sitting POST until exchange proof exists