2026-09-14 13:48:17 +02:00
|
|
|
|
---
|
|
|
|
|
|
id: INFD-WP-0002
|
|
|
|
|
|
type: workplan
|
|
|
|
|
|
title: "Compact sign-off batches for credentials and decisions"
|
|
|
|
|
|
domain: infotech
|
|
|
|
|
|
repo: informed-decision
|
2026-09-14 17:08:39 +02:00
|
|
|
|
status: active
|
2026-09-14 13:48:17 +02:00
|
|
|
|
owner: grok
|
|
|
|
|
|
topic_slug: netkingdom
|
|
|
|
|
|
flavor: planning
|
|
|
|
|
|
depends_on:
|
|
|
|
|
|
- INFD-WP-0001
|
|
|
|
|
|
created: "2026-09-14"
|
2026-09-15 00:35:14 +02:00
|
|
|
|
updated: "2026-09-15"
|
2026-09-14 13:48:17 +02:00
|
|
|
|
related:
|
|
|
|
|
|
- INFD-WP-0001
|
|
|
|
|
|
- STATE-WP-0092
|
|
|
|
|
|
- COORDINATION-WP-0005
|
|
|
|
|
|
origin: demand
|
|
|
|
|
|
origin_ref: the-custodian/history/20260914-open-workplan-chokepoints.md
|
2026-09-14 13:52:15 +02:00
|
|
|
|
state_hub_workstream_id: "a2939a36-eeab-522b-b35a-5399af2757bf"
|
2026-09-14 13:48:17 +02:00
|
|
|
|
---
|
|
|
|
|
|
|
|
|
|
|
|
# Compact sign-off batches for credentials and decisions
|
|
|
|
|
|
|
|
|
|
|
|
Founder direction 2026-09-14: credential and decision chokepoints should
|
|
|
|
|
|
move through the informed-decision framework as **batches that can be
|
|
|
|
|
|
signed off in a compact timeframe**, not as twelve disconnected
|
|
|
|
|
|
`needs_human` tasks.
|
|
|
|
|
|
|
|
|
|
|
|
`INFD-WP-0001` still owns Stage 1 (walking skeleton against a deployed
|
|
|
|
|
|
`approval-engine`, T08). This plan does **not** absorb the earlier
|
|
|
|
|
|
residual “full L3 product.” That remains residual until separately
|
|
|
|
|
|
promoted. This plan is the demanded slice: **review-groups of Decision
|
|
|
|
|
|
Memos** for (1) credential/custody items and (2) founder/owner
|
|
|
|
|
|
decisions.
|
|
|
|
|
|
|
|
|
|
|
|
Invariant from Stage 1: **one question per memo**. A batch is a
|
|
|
|
|
|
*Umlaufmappe* grouping of memos, not one memo with unrelated acts.
|
|
|
|
|
|
Humans bind; agents draft. This repository still does not evaluate
|
|
|
|
|
|
authorization (`access-engine` remains the only PDP).
|
|
|
|
|
|
|
|
|
|
|
|
## Draft the first two batches (agent-authored, unsigned)
|
|
|
|
|
|
|
|
|
|
|
|
```task
|
|
|
|
|
|
id: INFD-WP-0002-T01
|
2026-09-14 17:08:39 +02:00
|
|
|
|
status: done
|
2026-09-14 13:48:17 +02:00
|
|
|
|
priority: high
|
2026-09-14 13:52:15 +02:00
|
|
|
|
state_hub_task_id: "03d1b699-cb7b-5954-a4d2-cbe06af24c5a"
|
2026-09-14 13:48:17 +02:00
|
|
|
|
```
|
|
|
|
|
|
|
|
|
|
|
|
From the 2026-09-14 chokepoint assessment, assemble two compact batches
|
|
|
|
|
|
as Decision Memo files (or the current memo schema) under
|
|
|
|
|
|
`docs/batches/2026-09-14/`:
|
|
|
|
|
|
|
|
|
|
|
|
1. **Credentials / custody** — OpenBao paths, issuer/registration
|
|
|
|
|
|
leftovers, CCR-style items, and any `warden route` pointer that still
|
|
|
|
|
|
needs a human to actually mint or seal. Each memo is one act. No
|
|
|
|
|
|
secret values in the memos.
|
|
|
|
|
|
2. **Decisions / assent** — founder or owner sign-offs currently holding
|
|
|
|
|
|
workplans (reviews, explicit approvals, policy accepts). Each memo is
|
|
|
|
|
|
one question.
|
|
|
|
|
|
|
|
|
|
|
|
Bound the set so a single sitting can finish it (small N, ordered,
|
|
|
|
|
|
highlights required). Name the review group already admitted
|
|
|
|
|
|
(`net-kingdom-admins` or the current human review group). Do not submit
|
|
|
|
|
|
until T02.
|
|
|
|
|
|
|
|
|
|
|
|
Done when both batch indexes exist, each memo has one binding target,
|
|
|
|
|
|
required highlights, and a trace to the blocking workplan/task id.
|
|
|
|
|
|
|
2026-09-14 17:08:39 +02:00
|
|
|
|
2026-09-14: eight unsigned memos under `docs/batches/2026-09-14/`
|
|
|
|
|
|
(credentials c01–c04, decisions d01–d04). Review group
|
|
|
|
|
|
`net-kingdom-admins`. Not submitted.
|
|
|
|
|
|
|
2026-09-14 13:48:17 +02:00
|
|
|
|
## Batch presentation contract (review-group, compact sitting)
|
|
|
|
|
|
|
|
|
|
|
|
```task
|
|
|
|
|
|
id: INFD-WP-0002-T02
|
2026-09-14 17:08:39 +02:00
|
|
|
|
status: done
|
2026-09-14 13:48:17 +02:00
|
|
|
|
priority: high
|
|
|
|
|
|
depends_on: [INFD-WP-0002-T01]
|
2026-09-14 13:52:15 +02:00
|
|
|
|
state_hub_task_id: "8babbc7d-5c79-5130-93ad-e2569ed3208d"
|
2026-09-14 13:48:17 +02:00
|
|
|
|
```
|
|
|
|
|
|
|
|
|
|
|
|
Specify how a batch is presented without forking the Decision Memo
|
|
|
|
|
|
schema: ordered list, per-memo bind, progress across the sitting,
|
|
|
|
|
|
no “approve all” that skips highlights. Reuse review-group work already
|
|
|
|
|
|
in this repo. If Stage 1 UI cannot yet render a group, the contract
|
|
|
|
|
|
still holds for a recorded desktop sitting.
|
|
|
|
|
|
|
|
|
|
|
|
Done when `docs/specs/` (short addendum, not a new product) states the
|
|
|
|
|
|
batch rules and the anti-requirement: no bundled unrelated acts, no
|
|
|
|
|
|
auto-approval, no agent disposition.
|
|
|
|
|
|
|
2026-09-14 17:08:39 +02:00
|
|
|
|
2026-09-14: `docs/specs/CompactSignoffBatches.md`.
|
|
|
|
|
|
|
2026-09-14 13:48:17 +02:00
|
|
|
|
## Sign-off sitting once the Stage 1 surface can bind
|
|
|
|
|
|
|
|
|
|
|
|
```task
|
|
|
|
|
|
id: INFD-WP-0002-T03
|
|
|
|
|
|
status: wait
|
|
|
|
|
|
priority: high
|
|
|
|
|
|
depends_on: [INFD-WP-0002-T02, INFD-WP-0001]
|
2026-09-14 13:52:15 +02:00
|
|
|
|
state_hub_task_id: "917e3e34-b9de-5c51-ab29-e820957a7407"
|
2026-09-14 13:48:17 +02:00
|
|
|
|
```
|
|
|
|
|
|
|
|
|
|
|
|
Wait until `INFD-WP-0001-T08` (or an equivalent deployed bind path)
|
|
|
|
|
|
can take a real human disposition. Then run one compact sitting on the
|
|
|
|
|
|
two batches. Record presentation evidence (`view_hash` per memo).
|
|
|
|
|
|
Unfinished memos stay in the batch; do not mark the workplan finished
|
|
|
|
|
|
on a partial sitting.
|
|
|
|
|
|
|
|
|
|
|
|
Done when at least one credential memo and one decision memo are bound
|
|
|
|
|
|
by a human through this surface, reconstructable from stored
|
|
|
|
|
|
presentation, and the blocking hub tasks are updated from those
|
|
|
|
|
|
dispositions rather than from chat.
|
|
|
|
|
|
|
2026-09-14 18:59:49 +02:00
|
|
|
|
2026-09-14 — **T08 bind path historically proven; this sitting still
|
|
|
|
|
|
cannot run.** Probe
|
|
|
|
|
|
`docs/evidence/2026-09-14-infd-0002-t03-bind-path-probe.json`.
|
|
|
|
|
|
The live store already holds three `accept` dispositions with confirmed
|
|
|
|
|
|
engine submissions for `SECRETS-WP-0010-T03-{apply,verify,exec}`
|
|
|
|
|
|
(presentations + required acks). That is not this batch. Compact memos
|
|
|
|
|
|
remain `approval_id: null` / `pending-human-session` and are not in the
|
|
|
|
|
|
store. New accept is refused: origin `/readyz` 503
|
|
|
|
|
|
`approval_path_not_connected` because `audit-core` is not Ready, its
|
|
|
|
|
|
Service has no ready endpoints, and the review pod gets connection
|
|
|
|
|
|
refused talking to the audit ClusterIP. Operator packet
|
|
|
|
|
|
`docs/batches/2026-09-14/OPERATOR.md`; preflight
|
|
|
|
|
|
`tools/sitting_bind_preflight.py`. No agent disposition. Task stays
|
|
|
|
|
|
`wait`.
|
|
|
|
|
|
|
2026-09-15 00:35:14 +02:00
|
|
|
|
2026-09-14 22:16 UTC — **live accept reopened; sitting still not
|
|
|
|
|
|
admitted.** audit-core `b0e6792` is Ready; origin `/readyz` 200;
|
|
|
|
|
|
preflight `live_accept=open`. Remaining gates: (1) Flex Auth T03
|
|
|
|
|
|
package still allows only `memo:SECRETS-WP-0010-T03-*` —
|
|
|
|
|
|
`docs/batches/2026-09-14/policy-request.md` is a request, not an
|
|
|
|
|
|
admission; (2) no `approval:create` requester for these eight acts;
|
|
|
|
|
|
(3) drafts still `approval_id: null` / `pending-human-session`;
|
|
|
|
|
|
(4) human bind. Attach tool `tools/attach_compact_bindings.py` writes
|
|
|
|
|
|
bound copies from a created receipt and live subject; it does not
|
|
|
|
|
|
create approvals or dispositions. Evidence:
|
|
|
|
|
|
`docs/evidence/2026-09-14-infd-0002-t03-accept-reopened.json`.
|
|
|
|
|
|
Task stays `wait`.
|
|
|
|
|
|
|
2026-09-15 00:47:11 +02:00
|
|
|
|
2026-09-14 22:44 UTC — **sitting requester requested, not registered.**
|
|
|
|
|
|
`docs/keycape-sitting-requester-registration.md` asks key-cape for a
|
|
|
|
|
|
create-only confidential client (`informed-decision-sitting-requester`,
|
|
|
|
|
|
`sub=informed-decision`, scope `approval:create` only, no approve/consume,
|
|
|
|
|
|
no redirect). Intents for the eight bindings are in
|
|
|
|
|
|
`docs/batches/2026-09-14/approval-create-intents.json` (`posted: false`;
|
2026-09-15 01:04:10 +02:00
|
|
|
|
`c01` create-client undecided). No secret, no POST, no bind.
|
|
|
|
|
|
|
2026-09-15 22:19:25 +02:00
|
|
|
|
2026-09-15 — **requester live; sittings still wait on attended create +
|
|
|
|
|
|
human bind.** RPF-WP-0042 finished: CCR-2026-0026/0027 applied, exchange
|
|
|
|
|
|
proof verified, no sitting POST. `tools/create_sitting_approvals.py`
|
|
|
|
|
|
requires attended reader and posts seven intents (`c01` skipped). Flex
|
|
|
|
|
|
Auth package still waits on those native ids. This shell is not an
|
|
|
|
|
|
attended session. Task stays `wait`.
|
2026-09-15 00:47:11 +02:00
|
|
|
|
|
2026-09-14 13:48:17 +02:00
|
|
|
|
## Feed outcomes back to State Hub without hub-authoring
|
|
|
|
|
|
|
|
|
|
|
|
```task
|
|
|
|
|
|
id: INFD-WP-0002-T04
|
|
|
|
|
|
status: wait
|
|
|
|
|
|
priority: medium
|
|
|
|
|
|
depends_on: [INFD-WP-0002-T03]
|
2026-09-14 13:52:15 +02:00
|
|
|
|
state_hub_task_id: "26d8ff42-65bb-582e-9ecf-dbd367eaa7a8"
|
2026-09-14 13:48:17 +02:00
|
|
|
|
```
|
|
|
|
|
|
|
|
|
|
|
|
For each bound memo, update the **owning repo file** (task status,
|
|
|
|
|
|
decision record, CCR note) and let `fix-consistency` project. Do not
|
|
|
|
|
|
`POST /workplans/` or mint hub-only tasks. Residual unsigned memos
|
|
|
|
|
|
either stay in a later batch or are declined with a reason.
|
|
|
|
|
|
|
|
|
|
|
|
Done when the assessment’s credential/decision examples that were in
|
|
|
|
|
|
the sitting show file-level status changes and a progress event naming
|
|
|
|
|
|
the memo ids.
|