Draft unsigned credential and decision sign-off batches.

INFD-WP-0002 T01–T02: eight one-question memos for net-kingdom-admins,
batch contract without approve-all, no live bind (T08 still open).

Assistant: grok
Assistant-Session: 01a09dc1-b21e-77e1-919e-fcad2f82b267
This commit is contained in:
tegwick 2026-09-14 17:08:39 +02:00
parent 79f081850b
commit 27b8e916cc
24 changed files with 765 additions and 3 deletions

View file

@ -0,0 +1,21 @@
# Sitting 2026-09-14 (unsigned drafts)
Review group: `net-kingdom-admins`.
Status: draft-unsigned. Not submitted. Not bound.
Two batches, eight memos, one compact sitting:
| n | Batch | Memo | Blocking workplan |
| --: | --- | --- | --- |
| 1 | credentials | infd-20260914-c01 | SECRETS-WP-0010 native delivery |
| 2 | credentials | infd-20260914-c02 | RPF-WP-0035-T02 JWT login |
| 3 | credentials | infd-20260914-c03 | NK-WP-0032-T03 OpenBao role |
| 4 | credentials | infd-20260914-c04 | WARDEN-WP-0027-T02 attended seal |
| 5 | decisions | infd-20260914-d01 | CUST-WP-0038-T08 WSL2 retirement |
| 6 | decisions | infd-20260914-d02 | HFACT-WP-0001-T03 CCR-2026-0019 |
| 7 | decisions | infd-20260914-d03 | MASON-WP-0005 plan accept |
| 8 | decisions | infd-20260914-d04 | RCLK-WP-0002-T01 clock ownership |
Contract: `docs/specs/CompactSignoffBatches.md`.
Regenerate: `uv run python tools/prepare_compact_batches.py`.
Live bind waits on `INFD-WP-0001-T08`.

View file

@ -0,0 +1,60 @@
{
"kind": "informed-decision-batch",
"id": "infd-batch-2026-09-14-credentials",
"review_group": "net-kingdom-admins",
"status": "draft-unsigned",
"submitted": false,
"one_question_per_memo": true,
"approve_all_forbidden": true,
"agent_disposition_forbidden": true,
"ordinal": [
{
"n": 1,
"memo_id": "infd-20260914-c01",
"workplan": "SECRETS-WP-0010",
"task": "Admit and verify real native delivery",
"hub_task_prefix": "2aa6d2d3",
"question": "Admit real native OpenRouter delivery for intelligence-radar on the existing reviewed lane?",
"memo": "infd-20260914-c01.memo.json",
"packet": "infd-20260914-c01.packet.md",
"packet_hash": "sha256:32081b73066a49097e3564eac937cc34bffe72ff2be1b84b05a0999e578bda99",
"required_highlight": "infd-20260914-c01-h1"
},
{
"n": 2,
"memo_id": "infd-20260914-c02",
"workplan": "RPF-WP-0035",
"task": "RPF-WP-0035-T02",
"hub_task_prefix": "e0c82ea9",
"question": "Accept provisioning of the secrets-engine service JWT login on the reviewed credential lane?",
"memo": "infd-20260914-c02.memo.json",
"packet": "infd-20260914-c02.packet.md",
"packet_hash": "sha256:9a3159c1a8d2f1f8782469e2eb9e04e6cdede40b6bb9cdb872ae1f1bf3b73ee5",
"required_highlight": "infd-20260914-c02-h1"
},
{
"n": 3,
"memo_id": "infd-20260914-c03",
"workplan": "NK-WP-0032",
"task": "NK-WP-0032-T03",
"hub_task_prefix": "73b77110",
"question": "Apply the live OpenBao role addition already specified for the operator-tunneled browser callback?",
"memo": "infd-20260914-c03.memo.json",
"packet": "infd-20260914-c03.packet.md",
"packet_hash": "sha256:3e93888104d59854b8c191a98a46b73fed863df1bc76267b3fc24b070c676d3d",
"required_highlight": "infd-20260914-c03-h1"
},
{
"n": 4,
"memo_id": "infd-20260914-c04",
"workplan": "WARDEN-WP-0027",
"task": "WARDEN-WP-0027-T02",
"hub_task_prefix": "cae498ee",
"question": "Attend the graded lockdown / break-glass seal for ops-warden trust-root work?",
"memo": "infd-20260914-c04.memo.json",
"packet": "infd-20260914-c04.packet.md",
"packet_hash": "sha256:bc6edfa538a6c334a916becf51dc485ad43da49cd08411843aaf1ed56bf25e10",
"required_highlight": "infd-20260914-c04-h1"
}
]
}

View file

@ -0,0 +1 @@
{"approval_binding_digest":null,"approval_id":null,"binding":{"justification":null,"principal":{"display_name":"Named reviewer in net-kingdom-admins","id":"pending-human-session","identifiers":[],"kind":"person","role":"reviewer"},"target":{"environment":"prod","id":"catalog:openrouter-llm-connect","kind":"secret-catalog-lane","label":"Existing llm-connect OpenRouter lane","requires_new_bind":false},"terms":null},"binding_level":"organizational","brief":"SECRETS-WP-0010 native delivery is waiting on a human admit. KeyCape redirects pass. This memo does not display, mint, or rotate a credential. It only asks whether the already-reviewed apply/verify/exec packets may proceed to live native delivery.","highlights":[{"id":"infd-20260914-c01-h1","item_id":"infd-20260914-c01-packet","locator":{"kind":"work_record","task":"Admit and verify real native delivery","workplan":"SECRETS-WP-0010"},"note":"No secret value is in this packet. Admit is not a mint.","required_ack":true,"severity":"critical"}],"id":"infd-20260914-c01","locale":"en","packet":[{"hash":"sha256:32081b73066a49097e3564eac937cc34bffe72ff2be1b84b05a0999e578bda99","item_id":"infd-20260914-c01-packet","label":"infd-20260914-c01-packet"}],"question":"Admit real native OpenRouter delivery for intelligence-radar on the existing reviewed lane?","requested_act":"approve","sealed":false,"step_kind":"approve","ui_release":"informed-decision@0.2.0","version":1}

View file

@ -0,0 +1,16 @@
# SECRETS-WP-0010 — admit native delivery
Blocking workplan: SECRETS-WP-0010
Blocking task: Admit and verify real native delivery (hub prefix 2aa6d2d3)
## Question
Admit real native OpenRouter delivery for intelligence-radar on the existing reviewed lane?
## One act
Authorize the operator in `net-kingdom-admins` to complete the already-prepared
apply / verify / exec packets. This is not a new OpenBao path and not a key mint.
## Must not
- Paste or display credential material
- Call OpenRouter inference
- Treat `ops-warden` as a secret vendor

View file

@ -0,0 +1 @@
{"approval_binding_digest":null,"approval_id":null,"binding":{"justification":null,"principal":{"display_name":"Named reviewer in net-kingdom-admins","id":"pending-human-session","identifiers":[],"kind":"person","role":"reviewer"},"target":{"environment":"prod","id":"rpf-wp-0035-t02","kind":"credential-lane","label":"secrets-engine service JWT login","requires_new_bind":false},"terms":null},"binding_level":"organizational","brief":"RPF-WP-0035-T02 waits on accepting and provisioning secrets-engine service JWT login. This memo is the accept question only. Provisioning remains the platform owner's act after bind.","highlights":[{"id":"infd-20260914-c02-h1","item_id":"infd-20260914-c02-packet","locator":{"kind":"work_record","task":"RPF-WP-0035-T02","workplan":"RPF-WP-0035"},"note":"Accept is not permission to invent a client_secret in this memo.","required_ack":true,"severity":"critical"}],"id":"infd-20260914-c02","locale":"en","packet":[{"hash":"sha256:9a3159c1a8d2f1f8782469e2eb9e04e6cdede40b6bb9cdb872ae1f1bf3b73ee5","item_id":"infd-20260914-c02-packet","label":"infd-20260914-c02-packet"}],"question":"Accept provisioning of the secrets-engine service JWT login on the reviewed credential lane?","requested_act":"approve","sealed":false,"step_kind":"approve","ui_release":"informed-decision@0.2.0","version":1}

View file

@ -0,0 +1,15 @@
# RPF-WP-0035-T02 — accept JWT login lane
Blocking workplan: RPF-WP-0035
Blocking task: RPF-WP-0035-T02 (hub prefix e0c82ea9)
## Question
Accept provisioning of the secrets-engine service JWT login on the reviewed credential lane?
## One act
Organizational accept that this lane may be provisioned by its owner. The memo
does not contain a JWT, client secret, or OpenBao policy body.
## Must not
- Embed a token
- Collapse T02 with T03 Fluid lane or T06 reader admission

View file

@ -0,0 +1 @@
{"approval_binding_digest":null,"approval_id":null,"binding":{"justification":null,"principal":{"display_name":"Named reviewer in net-kingdom-admins","id":"pending-human-session","identifiers":[],"kind":"person","role":"reviewer"},"target":{"environment":"prod","id":"nk-wp-0032-t03","kind":"openbao-role","label":"OpenBao role addition for operator-tunneled callback","requires_new_bind":false},"terms":null},"binding_level":"organizational","brief":"NK-WP-0032-T03 applies a live OpenBao role addition. This memo asks only whether that apply may proceed. The role body stays in the owning repo; it is not copied here.","highlights":[{"id":"infd-20260914-c03-h1","item_id":"infd-20260914-c03-packet","locator":{"kind":"work_record","task":"NK-WP-0032-T03","workplan":"NK-WP-0032"},"note":"Apply is one role addition, not a general OpenBao admin grant.","required_ack":true,"severity":"critical"}],"id":"infd-20260914-c03","locale":"en","packet":[{"hash":"sha256:3e93888104d59854b8c191a98a46b73fed863df1bc76267b3fc24b070c676d3d","item_id":"infd-20260914-c03-packet","label":"infd-20260914-c03-packet"}],"question":"Apply the live OpenBao role addition already specified for the operator-tunneled browser callback?","requested_act":"approve","sealed":false,"step_kind":"approve","ui_release":"informed-decision@0.2.0","version":1}

View file

@ -0,0 +1,15 @@
# NK-WP-0032-T03 — apply live OpenBao role
Blocking workplan: NK-WP-0032
Blocking task: NK-WP-0032-T03 (hub prefix 73b77110)
## Question
Apply the live OpenBao role addition already specified for the operator-tunneled browser callback?
## One act
Authorize the NetKingdom owner to apply the already-specified role. This memo
does not include the policy HCL or any secret id.
## Must not
- Broaden to unattended public OpenBao UI
- Treat this as NK-WP-0032-T04 evidence return

View file

@ -0,0 +1 @@
{"approval_binding_digest":null,"approval_id":null,"binding":{"justification":null,"principal":{"display_name":"Named reviewer in net-kingdom-admins","id":"pending-human-session","identifiers":[],"kind":"person","role":"reviewer"},"target":{"environment":"prod","id":"warden-wp-0027-t02","kind":"trust-root","label":"ops-warden graded lockdown / break-glass","requires_new_bind":false},"terms":null},"binding_level":"organizational","brief":"WARDEN-WP-0027-T02 is attended seal work. This memo asks the reviewer to attend that seal sitting. ops-warden still issues SSH certificates only; this is not a request for an API key.","highlights":[{"id":"infd-20260914-c04-h1","item_id":"infd-20260914-c04-packet","locator":{"kind":"work_record","task":"WARDEN-WP-0027-T02","workplan":"WARDEN-WP-0027"},"note":"ops-warden does not vend API keys. This is an attended seal, not a secret paste.","required_ack":true,"severity":"critical"}],"id":"infd-20260914-c04","locale":"en","packet":[{"hash":"sha256:bc6edfa538a6c334a916becf51dc485ad43da49cd08411843aaf1ed56bf25e10","item_id":"infd-20260914-c04-packet","label":"infd-20260914-c04-packet"}],"question":"Attend the graded lockdown / break-glass seal for ops-warden trust-root work?","requested_act":"approve","sealed":false,"step_kind":"approve","ui_release":"informed-decision@0.2.0","version":1}

View file

@ -0,0 +1,15 @@
# WARDEN-WP-0027-T02 — attend graded lockdown seal
Blocking workplan: WARDEN-WP-0027
Blocking task: WARDEN-WP-0027-T02 (hub prefix cae498ee)
## Question
Attend the graded lockdown / break-glass seal for ops-warden trust-root work?
## One act
Schedule/complete the attended seal. Credential routing remains: SSH certs from
ops-warden; other secrets from OpenBao via `warden route` pointers.
## Must not
- Ask ops-warden for ISSUE_CORE_API_KEY or similar
- Record seal material in this packet

View file

@ -0,0 +1,60 @@
{
"kind": "informed-decision-batch",
"id": "infd-batch-2026-09-14-decisions",
"review_group": "net-kingdom-admins",
"status": "draft-unsigned",
"submitted": false,
"one_question_per_memo": true,
"approve_all_forbidden": true,
"agent_disposition_forbidden": true,
"ordinal": [
{
"n": 1,
"memo_id": "infd-20260914-d01",
"workplan": "CUST-WP-0038",
"task": "CUST-WP-0038-T08",
"hub_task_prefix": "57412aef",
"question": "After HA failover and restore drills pass, retire WSL2 as a State Hub fallback?",
"memo": "infd-20260914-d01.memo.json",
"packet": "infd-20260914-d01.packet.md",
"packet_hash": "sha256:29fe7445e1f6794402bda2f9c4cab4258021d892515e1922819d8b67cb9e6b46",
"required_highlight": "infd-20260914-d01-h1"
},
{
"n": 2,
"memo_id": "infd-20260914-d02",
"workplan": "HFACT-WP-0001",
"task": "HFACT-WP-0001-T03",
"hub_task_prefix": "67c80db1",
"question": "Confirm the existing operator-group claim for CCR-2026-0019 as required by the factory identity/audit/approval path?",
"memo": "infd-20260914-d02.memo.json",
"packet": "infd-20260914-d02.packet.md",
"packet_hash": "sha256:dffe006442779e3076526d72bd481a163b32b3bfe84c51952e1f2dcd53174e72",
"required_highlight": "infd-20260914-d02-h1"
},
{
"n": 3,
"memo_id": "infd-20260914-d03",
"workplan": "MASON-WP-0005",
"task": "Review the plan and obtain the decision",
"hub_task_prefix": "48a2b4ec",
"question": "Accept the fluid-telegram operator credential lane plan so construction may proceed?",
"memo": "infd-20260914-d03.memo.json",
"packet": "infd-20260914-d03.packet.md",
"packet_hash": "sha256:d44745e5a6281e3f21cfbe5ac9c758cd06b5c7ddb49fd4b468aebcbeb2d301a0",
"required_highlight": "infd-20260914-d03-h1"
},
{
"n": 4,
"memo_id": "infd-20260914-d04",
"workplan": "RCLK-WP-0002",
"task": "RCLK-WP-0002-T01",
"hub_task_prefix": "437734bd",
"question": "Confirm ecosystem ownership and the security role for Railiance Clock as specified?",
"memo": "infd-20260914-d04.memo.json",
"packet": "infd-20260914-d04.packet.md",
"packet_hash": "sha256:d7814954d261031ed61627e340d6beadecd8c559fb1a24c9fecb752b30cdbc53",
"required_highlight": "infd-20260914-d04-h1"
}
]
}

View file

@ -0,0 +1 @@
{"approval_binding_digest":null,"approval_id":null,"binding":{"justification":null,"principal":{"display_name":"Named reviewer in net-kingdom-admins","id":"pending-human-session","identifiers":[],"kind":"person","role":"reviewer"},"target":{"environment":"prod","id":"cust-wp-0038-t08","kind":"operating-model","label":"Retire WSL2 State Hub fallback","requires_new_bind":false},"terms":null},"binding_level":"organizational","brief":"CUST-WP-0038-T08 requires explicit approval after drills. This memo is that approval question. It does not assert that the drills have already passed.","highlights":[{"id":"infd-20260914-d01-h1","item_id":"infd-20260914-d01-packet","locator":{"kind":"work_record","task":"CUST-WP-0038-T08","workplan":"CUST-WP-0038"},"note":"Approve only if you accept that WSL2 leaves both normal and fallback operating models.","required_ack":true,"severity":"critical"}],"id":"infd-20260914-d01","locale":"en","packet":[{"hash":"sha256:29fe7445e1f6794402bda2f9c4cab4258021d892515e1922819d8b67cb9e6b46","item_id":"infd-20260914-d01-packet","label":"infd-20260914-d01-packet"}],"question":"After HA failover and restore drills pass, retire WSL2 as a State Hub fallback?","requested_act":"approve","sealed":false,"step_kind":"approve","ui_release":"informed-decision@0.2.0","version":1}

View file

@ -0,0 +1,15 @@
# CUST-WP-0038-T08 — retire WSL2 fallback
Blocking workplan: CUST-WP-0038
Blocking task: CUST-WP-0038-T08 (hub prefix 57412aef, needs_human)
## Question
After HA failover and restore drills pass, retire WSL2 as a State Hub fallback?
## One act
Founder/operator approval of the retirement once T05/T06 drills have passed.
This memo does not skip the drills.
## Must not
- Treat this accept as proof that drills already passed
- Keep WSL2 as an undeclared fallback after accept

View file

@ -0,0 +1 @@
{"approval_binding_digest":null,"approval_id":null,"binding":{"justification":null,"principal":{"display_name":"Named reviewer in net-kingdom-admins","id":"pending-human-session","identifiers":[],"kind":"person","role":"reviewer"},"target":{"environment":"prod","id":"ccr-2026-0019","kind":"ccr","label":"Existing operator-group claim for factory path","requires_new_bind":false},"terms":null},"binding_level":"organizational","brief":"HFACT-WP-0001-T03 waits on NetKingdom/KeyCape confirmation of the exact existing operator-group claim. This memo is that confirmation question. It does not mint a new group.","highlights":[{"id":"infd-20260914-d02-h1","item_id":"infd-20260914-d02-packet","locator":{"kind":"work_record","task":"HFACT-WP-0001-T03","workplan":"HFACT-WP-0001"},"note":"Confirm the existing claim. Do not invent a new group or CCR.","required_ack":true,"severity":"critical"}],"id":"infd-20260914-d02","locale":"en","packet":[{"hash":"sha256:dffe006442779e3076526d72bd481a163b32b3bfe84c51952e1f2dcd53174e72","item_id":"infd-20260914-d02-packet","label":"infd-20260914-d02-packet"}],"question":"Confirm the existing operator-group claim for CCR-2026-0019 as required by the factory identity/audit/approval path?","requested_act":"approve","sealed":false,"step_kind":"approve","ui_release":"informed-decision@0.2.0","version":1}

View file

@ -0,0 +1,16 @@
# HFACT-WP-0001-T03 — confirm CCR-2026-0019 operator-group
Blocking workplan: HFACT-WP-0001
Blocking task: HFACT-WP-0001-T03 (hub prefix 67c80db1, needs_human)
## Question
Confirm the existing operator-group claim for CCR-2026-0019 as required by the
factory identity, audit and approval path?
## One act
Confirm the already-named operator-group claim. Required-owner review and
attended apply remain separate acts.
## Must not
- Create a new CCR in this memo
- Collapse T03 with T05 live worker proof

View file

@ -0,0 +1 @@
{"approval_binding_digest":null,"approval_id":null,"binding":{"justification":null,"principal":{"display_name":"Named reviewer in net-kingdom-admins","id":"pending-human-session","identifiers":[],"kind":"person","role":"reviewer"},"target":{"environment":"prod","id":"mason-wp-0005","kind":"workplan","label":"fluid-telegram operator credential lane plan","requires_new_bind":false},"terms":null},"binding_level":"organizational","brief":"MASON-WP-0005 has a review/decision task before building the operator lane. This memo is that plan accept. Path/OIDC binding (another task) is a separate memo if needed later.","highlights":[{"id":"infd-20260914-d03-h1","item_id":"infd-20260914-d03-packet","locator":{"kind":"work_record","task":"Review the plan and obtain the decision","workplan":"MASON-WP-0005"},"note":"Accepting the plan is not confirming the OIDC binding and is not a BotFather login.","required_ack":true,"severity":"critical"}],"id":"infd-20260914-d03","locale":"en","packet":[{"hash":"sha256:d44745e5a6281e3f21cfbe5ac9c758cd06b5c7ddb49fd4b468aebcbeb2d301a0","item_id":"infd-20260914-d03-packet","label":"infd-20260914-d03-packet"}],"question":"Accept the fluid-telegram operator credential lane plan so construction may proceed?","requested_act":"approve","sealed":false,"step_kind":"approve","ui_release":"informed-decision@0.2.0","version":1}

View file

@ -0,0 +1,15 @@
# MASON-WP-0005 — accept operator lane plan
Blocking workplan: MASON-WP-0005
Blocking task: Review the plan and obtain the decision (hub prefix 48a2b4ec)
## Question
Accept the fluid-telegram operator credential lane plan so construction may proceed?
## One act
Organizational accept of the written plan. BotFather login, DNS, and OIDC
binding remain other tasks.
## Must not
- Perform BotFather login in this sitting
- Record a telegram token

View file

@ -0,0 +1 @@
{"approval_binding_digest":null,"approval_id":null,"binding":{"justification":null,"principal":{"display_name":"Named reviewer in net-kingdom-admins","id":"pending-human-session","identifiers":[],"kind":"person","role":"reviewer"},"target":{"environment":"prod","id":"rclk-wp-0002-t01","kind":"workplan","label":"Railiance Clock ownership and security role","requires_new_bind":false},"terms":null},"binding_level":"organizational","brief":"RCLK-WP-0002-T01 is the owner/security-role confirmation. This memo is that confirmation. It does not change OS clocks or admit railiance01 as production time authority by itself.","highlights":[{"id":"infd-20260914-d04-h1","item_id":"infd-20260914-d04-packet","locator":{"kind":"work_record","task":"RCLK-WP-0002-T01","workplan":"RCLK-WP-0002"},"note":"Confirmation is ownership/role, not a clock change on any host.","required_ack":true,"severity":"critical"}],"id":"infd-20260914-d04","locale":"en","packet":[{"hash":"sha256:d7814954d261031ed61627e340d6beadecd8c559fb1a24c9fecb752b30cdbc53","item_id":"infd-20260914-d04-packet","label":"infd-20260914-d04-packet"}],"question":"Confirm ecosystem ownership and the security role for Railiance Clock as specified?","requested_act":"approve","sealed":false,"step_kind":"approve","ui_release":"informed-decision@0.2.0","version":1}

View file

@ -0,0 +1,15 @@
# RCLK-WP-0002-T01 — confirm clock ownership
Blocking workplan: RCLK-WP-0002
Blocking task: RCLK-WP-0002-T01 (hub prefix 437734bd)
## Question
Confirm ecosystem ownership and the security role for Railiance Clock as specified?
## One act
Owner confirmation of the documented role split (railiance-infra for host UTC,
clock repo for specs). No NTP or OS change is authorized by this memo.
## Must not
- Change ntp.ubuntu.com or systemd-timesyncd from this sitting
- Treat this as RCLK-WP-0004 pilot admission

View file

@ -0,0 +1,13 @@
{
"kind": "informed-decision-sitting",
"id": "infd-sitting-2026-09-14",
"review_group": "net-kingdom-admins",
"status": "draft-unsigned",
"batches": [
"infd-batch-2026-09-14-credentials",
"infd-batch-2026-09-14-decisions"
],
"memo_count": 8,
"bind_path": "INFD-WP-0001-T08 (not yet complete)",
"note": "Unsigned drafts. Do not submit until CompactSignoffBatches.md is accepted. Live bind substitutes pending-human-session with the authenticated key-cape subject."
}

View file

@ -0,0 +1,52 @@
# Compact sign-off batches
Addendum to the Stage 1 specs (INFD-WP-0002-T02). Not a new product.
Does not fork the Decision Memo schema.
## What a batch is
A batch is an *Umlaufmappe* **grouping** of Decision Memos that one
admitted review group can bind in a compact sitting.
- One question per memo (INTENT invariant).
- Ordered list (`ordinal` in the batch index).
- Per-memo bind. Progress is “how many memos in this sitting have a
human disposition,” not a batch-level verdict.
- Review group: `net-kingdom-admins` (operator-admitted 2026-09-14).
- Humans bind; agents draft. Unsigned drafts use principal
`pending-human-session`. Live bind substitutes the authenticated
key-cape subject.
If Stage 1 UI cannot yet render a group, the same rules hold for a
recorded desktop sitting: open memos in order, acknowledge required
highlights, bind one memo at a time, keep `view_hash` per memo.
## Anti-requirements
- **No bundled unrelated acts.** One memo must not ask for a mint, a
deploy, and an ADR accept together.
- **No “approve all”** that skips required highlights.
- **No agent disposition.** An agent may draft, order, and record
evidence. It may not `accept` / `decline` / `seal`.
- **No secret values** in packets or memos.
- **No auto-approval** from review-group membership. Membership is
eligibility, not a bind.
- This addendum does **not** complete INFD-WP-0001-T08. Live bind waits
on that path.
## Sitting progress
```text
draft-unsigned → (T08 bind path live) → circulating → per-memo completed
```
Unfinished memos stay in the batch. A partial sitting does not finish
INFD-WP-0002. File-level updates of owning workplans happen only after
a human bind (T04), via repo files + `fix-consistency`, never
`POST /workplans/`.
## First sitting (unsigned)
`docs/batches/2026-09-14/` — four credential/custody memos and four
decision/assent memos. Indexes name the blocking workplan/task. Do not
submit until a human sitting is opened under T03.

View file

@ -0,0 +1,40 @@
from pathlib import Path
import json
from informed_decision.records import memo_from
ROOT = Path(__file__).resolve().parents[1] / "docs" / "batches" / "2026-09-14"
def test_sitting_has_two_unsigned_batches_of_four():
sitting = json.loads((ROOT / "sitting.json").read_text())
assert sitting["status"] == "draft-unsigned"
assert sitting["review_group"] == "net-kingdom-admins"
assert sitting["memo_count"] == 8
assert sitting.get("submitted") is not True
def test_each_memo_is_one_question_with_required_highlight_and_workplan_trace():
questions = set()
for name in ("credentials", "decisions"):
index = json.loads((ROOT / name / "index.json").read_text())
assert index["one_question_per_memo"] is True
assert index["approve_all_forbidden"] is True
assert index["agent_disposition_forbidden"] is True
assert index["submitted"] is False
assert len(index["ordinal"]) == 4
for row in index["ordinal"]:
memo = memo_from(json.loads((ROOT / name / row["memo"]).read_text()))
assert memo.question == row["question"]
assert memo.question not in questions
questions.add(memo.question)
assert memo.requested_act == "approve"
assert memo.approval_id is None
assert row["required_highlight"] in memo.required_ack_ids
assert row["workplan"]
assert row["hub_task_prefix"]
packet = (ROOT / name / row["packet"]).read_text()
assert "password" not in packet.lower()
assert "secret_id" not in packet.lower()
assert row["workplan"] in packet
assert len(questions) == 8

View file

@ -0,0 +1,380 @@
"""Draft unsigned compact sign-off batches (INFD-WP-0002-T01).
One question per memo. No secret values. Does not submit, present, or bind.
"""
from __future__ import annotations
import hashlib
from pathlib import Path
from informed_decision.memo import (
BindingLevel,
BindingSlice,
Highlight,
Memo,
PacketItem,
Principal,
Scope,
StepKind,
)
from informed_decision.records import dumps, memo_from
ROOT = Path(__file__).resolve().parents[1] / "docs" / "batches" / "2026-09-14"
REVIEW_GROUP = "net-kingdom-admins"
PRINCIPAL = Principal(
id="pending-human-session",
kind="person",
display_name="Named reviewer in net-kingdom-admins",
role="reviewer",
)
def _sha(text: str) -> str:
return "sha256:" + hashlib.sha256(text.encode()).hexdigest()
def _memo(*, memo_id: str, question: str, brief: str, target: Scope, packet_id: str, packet_hash: str, highlight: str, workplan: str, task: str) -> Memo:
return Memo(
id=memo_id,
version=1,
question=question,
requested_act="approve",
binding_level=BindingLevel.ORGANIZATIONAL,
brief=brief,
binding=BindingSlice(principal=PRINCIPAL, target=target),
step_kind=StepKind.APPROVE,
packet=(PacketItem(packet_id, packet_id, packet_hash),),
highlights=(
Highlight(
id=f"{memo_id}-h1",
item_id=packet_id,
note=highlight,
required_ack=True,
severity="critical",
locator={"kind": "work_record", "workplan": workplan, "task": task},
),
),
)
CREDENTIALS = [
{
"id": "infd-20260914-c01",
"workplan": "SECRETS-WP-0010",
"task": "Admit and verify real native delivery",
"task_id": "2aa6d2d3-0000-0000-0000-000000000000",
"hub_task_id": "2aa6d2d3",
"question": "Admit real native OpenRouter delivery for intelligence-radar on the existing reviewed lane?",
"brief": (
"SECRETS-WP-0010 native delivery is waiting on a human admit. "
"KeyCape redirects pass. This memo does not display, mint, or rotate a credential. "
"It only asks whether the already-reviewed apply/verify/exec packets may proceed to live native delivery."
),
"highlight": "No secret value is in this packet. Admit is not a mint.",
"target": Scope("secret-catalog-lane", "catalog:openrouter-llm-connect", "Existing llm-connect OpenRouter lane", "prod"),
"packet": """# SECRETS-WP-0010 — admit native delivery
Blocking workplan: SECRETS-WP-0010
Blocking task: Admit and verify real native delivery (hub prefix 2aa6d2d3)
## Question
Admit real native OpenRouter delivery for intelligence-radar on the existing reviewed lane?
## One act
Authorize the operator in `net-kingdom-admins` to complete the already-prepared
apply / verify / exec packets. This is not a new OpenBao path and not a key mint.
## Must not
- Paste or display credential material
- Call OpenRouter inference
- Treat `ops-warden` as a secret vendor
""",
},
{
"id": "infd-20260914-c02",
"workplan": "RPF-WP-0035",
"task": "RPF-WP-0035-T02",
"hub_task_id": "e0c82ea9",
"question": "Accept provisioning of the secrets-engine service JWT login on the reviewed credential lane?",
"brief": (
"RPF-WP-0035-T02 waits on accepting and provisioning secrets-engine service JWT login. "
"This memo is the accept question only. Provisioning remains the platform owner's act after bind."
),
"highlight": "Accept is not permission to invent a client_secret in this memo.",
"target": Scope("credential-lane", "rpf-wp-0035-t02", "secrets-engine service JWT login", "prod"),
"packet": """# RPF-WP-0035-T02 — accept JWT login lane
Blocking workplan: RPF-WP-0035
Blocking task: RPF-WP-0035-T02 (hub prefix e0c82ea9)
## Question
Accept provisioning of the secrets-engine service JWT login on the reviewed credential lane?
## One act
Organizational accept that this lane may be provisioned by its owner. The memo
does not contain a JWT, client secret, or OpenBao policy body.
## Must not
- Embed a token
- Collapse T02 with T03 Fluid lane or T06 reader admission
""",
},
{
"id": "infd-20260914-c03",
"workplan": "NK-WP-0032",
"task": "NK-WP-0032-T03",
"hub_task_id": "73b77110",
"question": "Apply the live OpenBao role addition already specified for the operator-tunneled browser callback?",
"brief": (
"NK-WP-0032-T03 applies a live OpenBao role addition. This memo asks only whether that apply may proceed. "
"The role body stays in the owning repo; it is not copied here."
),
"highlight": "Apply is one role addition, not a general OpenBao admin grant.",
"target": Scope("openbao-role", "nk-wp-0032-t03", "OpenBao role addition for operator-tunneled callback", "prod"),
"packet": """# NK-WP-0032-T03 — apply live OpenBao role
Blocking workplan: NK-WP-0032
Blocking task: NK-WP-0032-T03 (hub prefix 73b77110)
## Question
Apply the live OpenBao role addition already specified for the operator-tunneled browser callback?
## One act
Authorize the NetKingdom owner to apply the already-specified role. This memo
does not include the policy HCL or any secret id.
## Must not
- Broaden to unattended public OpenBao UI
- Treat this as NK-WP-0032-T04 evidence return
""",
},
{
"id": "infd-20260914-c04",
"workplan": "WARDEN-WP-0027",
"task": "WARDEN-WP-0027-T02",
"hub_task_id": "cae498ee",
"question": "Attend the graded lockdown / break-glass seal for ops-warden trust-root work?",
"brief": (
"WARDEN-WP-0027-T02 is attended seal work. This memo asks the reviewer to attend that seal sitting. "
"ops-warden still issues SSH certificates only; this is not a request for an API key."
),
"highlight": "ops-warden does not vend API keys. This is an attended seal, not a secret paste.",
"target": Scope("trust-root", "warden-wp-0027-t02", "ops-warden graded lockdown / break-glass", "prod"),
"packet": """# WARDEN-WP-0027-T02 — attend graded lockdown seal
Blocking workplan: WARDEN-WP-0027
Blocking task: WARDEN-WP-0027-T02 (hub prefix cae498ee)
## Question
Attend the graded lockdown / break-glass seal for ops-warden trust-root work?
## One act
Schedule/complete the attended seal. Credential routing remains: SSH certs from
ops-warden; other secrets from OpenBao via `warden route` pointers.
## Must not
- Ask ops-warden for ISSUE_CORE_API_KEY or similar
- Record seal material in this packet
""",
},
]
DECISIONS = [
{
"id": "infd-20260914-d01",
"workplan": "CUST-WP-0038",
"task": "CUST-WP-0038-T08",
"hub_task_id": "57412aef",
"question": "After HA failover and restore drills pass, retire WSL2 as a State Hub fallback?",
"brief": (
"CUST-WP-0038-T08 requires explicit approval after drills. This memo is that approval question. "
"It does not assert that the drills have already passed."
),
"highlight": "Approve only if you accept that WSL2 leaves both normal and fallback operating models.",
"target": Scope("operating-model", "cust-wp-0038-t08", "Retire WSL2 State Hub fallback", "prod"),
"packet": """# CUST-WP-0038-T08 — retire WSL2 fallback
Blocking workplan: CUST-WP-0038
Blocking task: CUST-WP-0038-T08 (hub prefix 57412aef, needs_human)
## Question
After HA failover and restore drills pass, retire WSL2 as a State Hub fallback?
## One act
Founder/operator approval of the retirement once T05/T06 drills have passed.
This memo does not skip the drills.
## Must not
- Treat this accept as proof that drills already passed
- Keep WSL2 as an undeclared fallback after accept
""",
},
{
"id": "infd-20260914-d02",
"workplan": "HFACT-WP-0001",
"task": "HFACT-WP-0001-T03",
"hub_task_id": "67c80db1",
"question": "Confirm the existing operator-group claim for CCR-2026-0019 as required by the factory identity/audit/approval path?",
"brief": (
"HFACT-WP-0001-T03 waits on NetKingdom/KeyCape confirmation of the exact existing operator-group claim. "
"This memo is that confirmation question. It does not mint a new group."
),
"highlight": "Confirm the existing claim. Do not invent a new group or CCR.",
"target": Scope("ccr", "ccr-2026-0019", "Existing operator-group claim for factory path", "prod"),
"packet": """# HFACT-WP-0001-T03 — confirm CCR-2026-0019 operator-group
Blocking workplan: HFACT-WP-0001
Blocking task: HFACT-WP-0001-T03 (hub prefix 67c80db1, needs_human)
## Question
Confirm the existing operator-group claim for CCR-2026-0019 as required by the
factory identity, audit and approval path?
## One act
Confirm the already-named operator-group claim. Required-owner review and
attended apply remain separate acts.
## Must not
- Create a new CCR in this memo
- Collapse T03 with T05 live worker proof
""",
},
{
"id": "infd-20260914-d03",
"workplan": "MASON-WP-0005",
"task": "Review the plan and obtain the decision",
"hub_task_id": "48a2b4ec",
"question": "Accept the fluid-telegram operator credential lane plan so construction may proceed?",
"brief": (
"MASON-WP-0005 has a review/decision task before building the operator lane. "
"This memo is that plan accept. Path/OIDC binding (another task) is a separate memo if needed later."
),
"highlight": "Accepting the plan is not confirming the OIDC binding and is not a BotFather login.",
"target": Scope("workplan", "mason-wp-0005", "fluid-telegram operator credential lane plan", "prod"),
"packet": """# MASON-WP-0005 — accept operator lane plan
Blocking workplan: MASON-WP-0005
Blocking task: Review the plan and obtain the decision (hub prefix 48a2b4ec)
## Question
Accept the fluid-telegram operator credential lane plan so construction may proceed?
## One act
Organizational accept of the written plan. BotFather login, DNS, and OIDC
binding remain other tasks.
## Must not
- Perform BotFather login in this sitting
- Record a telegram token
""",
},
{
"id": "infd-20260914-d04",
"workplan": "RCLK-WP-0002",
"task": "RCLK-WP-0002-T01",
"hub_task_id": "437734bd",
"question": "Confirm ecosystem ownership and the security role for Railiance Clock as specified?",
"brief": (
"RCLK-WP-0002-T01 is the owner/security-role confirmation. This memo is that confirmation. "
"It does not change OS clocks or admit railiance01 as production time authority by itself."
),
"highlight": "Confirmation is ownership/role, not a clock change on any host.",
"target": Scope("workplan", "rclk-wp-0002-t01", "Railiance Clock ownership and security role", "prod"),
"packet": """# RCLK-WP-0002-T01 — confirm clock ownership
Blocking workplan: RCLK-WP-0002
Blocking task: RCLK-WP-0002-T01 (hub prefix 437734bd)
## Question
Confirm ecosystem ownership and the security role for Railiance Clock as specified?
## One act
Owner confirmation of the documented role split (railiance-infra for host UTC,
clock repo for specs). No NTP or OS change is authorized by this memo.
## Must not
- Change ntp.ubuntu.com or systemd-timesyncd from this sitting
- Treat this as RCLK-WP-0004 pilot admission
""",
},
]
def write_batch(name: str, items: list[dict]) -> dict:
directory = ROOT / name
directory.mkdir(parents=True, exist_ok=True)
index = {
"kind": "informed-decision-batch",
"id": f"infd-batch-2026-09-14-{name}",
"review_group": REVIEW_GROUP,
"status": "draft-unsigned",
"submitted": False,
"one_question_per_memo": True,
"approve_all_forbidden": True,
"agent_disposition_forbidden": True,
"ordinal": [],
}
for i, item in enumerate(items, start=1):
packet_path = directory / f"{item['id']}.packet.md"
packet_path.write_text(item["packet"], encoding="utf-8")
digest = _sha(item["packet"])
memo = _memo(
memo_id=item["id"],
question=item["question"],
brief=item["brief"],
target=item["target"],
packet_id=item["id"] + "-packet",
packet_hash=digest,
highlight=item["highlight"],
workplan=item["workplan"],
task=item["task"],
)
loaded = memo_from(__import__("json").loads(dumps(memo)))
if loaded.question != item["question"]:
raise RuntimeError("round-trip failed")
memo_path = directory / f"{item['id']}.memo.json"
memo_path.write_text(dumps(memo) + "\n", encoding="utf-8")
index["ordinal"].append(
{
"n": i,
"memo_id": item["id"],
"workplan": item["workplan"],
"task": item["task"],
"hub_task_prefix": item["hub_task_id"],
"question": item["question"],
"memo": memo_path.name,
"packet": packet_path.name,
"packet_hash": digest,
"required_highlight": f"{item['id']}-h1",
}
)
(directory / "index.json").write_text(
__import__("json").dumps(index, indent=2, ensure_ascii=False) + "\n",
encoding="utf-8",
)
return index
def main() -> None:
ROOT.mkdir(parents=True, exist_ok=True)
cred = write_batch("credentials", CREDENTIALS)
dec = write_batch("decisions", DECISIONS)
sitting = {
"kind": "informed-decision-sitting",
"id": "infd-sitting-2026-09-14",
"review_group": REVIEW_GROUP,
"status": "draft-unsigned",
"batches": [cred["id"], dec["id"]],
"memo_count": len(cred["ordinal"]) + len(dec["ordinal"]),
"bind_path": "INFD-WP-0001-T08 (not yet complete)",
"note": "Unsigned drafts. Do not submit until CompactSignoffBatches.md is accepted. Live bind substitutes pending-human-session with the authenticated key-cape subject.",
}
(ROOT / "sitting.json").write_text(
__import__("json").dumps(sitting, indent=2, ensure_ascii=False) + "\n",
encoding="utf-8",
)
print(f"Wrote {sitting['memo_count']} unsigned memos under {ROOT}")
if __name__ == "__main__":
main()

View file

@ -4,7 +4,7 @@ type: workplan
title: "Compact sign-off batches for credentials and decisions"
domain: infotech
repo: informed-decision
status: proposed
status: active
owner: grok
topic_slug: netkingdom
flavor: planning
@ -44,7 +44,7 @@ authorization (`access-engine` remains the only PDP).
```task
id: INFD-WP-0002-T01
status: todo
status: done
priority: high
state_hub_task_id: "03d1b699-cb7b-5954-a4d2-cbe06af24c5a"
```
@ -69,11 +69,15 @@ until T02.
Done when both batch indexes exist, each memo has one binding target,
required highlights, and a trace to the blocking workplan/task id.
2026-09-14: eight unsigned memos under `docs/batches/2026-09-14/`
(credentials c01c04, decisions d01d04). Review group
`net-kingdom-admins`. Not submitted.
## Batch presentation contract (review-group, compact sitting)
```task
id: INFD-WP-0002-T02
status: todo
status: done
priority: high
depends_on: [INFD-WP-0002-T01]
state_hub_task_id: "8babbc7d-5c79-5130-93ad-e2569ed3208d"
@ -89,6 +93,8 @@ Done when `docs/specs/` (short addendum, not a new product) states the
batch rules and the anti-requirement: no bundled unrelated acts, no
auto-approval, no agent disposition.
2026-09-14: `docs/specs/CompactSignoffBatches.md`.
## Sign-off sitting once the Stage 1 surface can bind
```task