Deploy verified-group T03 review surface and packet preparation

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a09cbb-87c6-7900-a145-4ce53ba9f1a6
This commit is contained in:
tegwick 2026-09-14 02:47:31 +02:00
parent c5367a5a54
commit 6fb35d953b
14 changed files with 2876 additions and 9 deletions

View file

@ -18,7 +18,7 @@ caller credential. Wrong service accounts and human-token substitution fail
before evaluation in the actual component test.
The subject comes from the verified KeyCape human session, including verified
roles and unchanged assurance facts. Membership tenant and act scope remain
groups and roles and unchanged assurance facts. Membership tenant and act scope remain
distinct. The tenant provenance values are the consumer's typed
`directory-asserted` or `registration-supplied`; human provenance is
`authentication-derived`. Unknown routes refuse before a request is made.
@ -102,3 +102,15 @@ one synthetic human/memo/approval and no production assignment. Its native
package pin proves the consumer seam and cannot be used as admission evidence.
Owner return must include admitted policy/caller pins and deployed allow/refusal
receipts for the exact native human/act before T08 can claim live binding.
## T03 operator mandate — 2026-09-14
The operator explicitly authorized members of `net-kingdom-admins` to review
and approve only the SECRETS-WP-0010-T03 apply, verify and read-only OpenRouter
key-check actions. This is separate from CCR-2026-0019 reader permission.
The consumer now carries the signed access token's validated group array in
`subject.attributes.groups`; it never derives groups from roles or memo content.
The production policy must bind exact memo ids, approval ids and native binding
digests, require authenticated humanity and fresh MFA, and deny every other act.
This mandate is not a disposition: only the human browser session can bind one.