Draft the 2026-09-21 spend-envelope budget memo for SECRETS-WP-0009-T03
One unsigned memo, infd-20260921-b01, accepting the Glas Anthropic spend envelope. The approval-create tool now takes an explicit batch, receipt and expected count; defaults keep the 2026-09-14 sitting unchanged. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: opus Assistant-Process: 272244@bnt-lap001 Assistant-Session: c8962fa7-b290-47df-865f-403ddb6c77e9
This commit is contained in:
parent
1bce7c663a
commit
c8c60ebc21
9 changed files with 366 additions and 3 deletions
47
docs/batches/2026-09-21/OPERATOR.md
Normal file
47
docs/batches/2026-09-21/OPERATOR.md
Normal file
|
|
@ -0,0 +1,47 @@
|
|||
# Budget sitting — operator packet (SECRETS-WP-0009-T03)
|
||||
|
||||
Review group: `net-kingdom-admins`.
|
||||
Surface: https://decisions.coulomb.social/
|
||||
Contract: `docs/specs/CompactSignoffBatches.md`.
|
||||
Generator: `tools/prepare_budget_batch.py` (re-running rewrites the same bytes).
|
||||
|
||||
An agent may draft, order, and record evidence. It may not `accept` / `decline` / `seal`.
|
||||
|
||||
## One unsigned memo
|
||||
|
||||
| n | memo_id | Blocking record |
|
||||
| --: | --- | --- |
|
||||
| 1 | `infd-20260921-b01` | SECRETS-WP-0009-T03 spend envelope (`authority_ref` for HFACT-WP-0001 SpendPolicy) |
|
||||
|
||||
Required acknowledgement: the EUR 100 monthly limit is recorded, not enforced.
|
||||
|
||||
## Steps
|
||||
|
||||
1. **Create the native approval (attended).** Same contained reader as the
|
||||
2026-09-14 sitting, with the batch selected explicitly:
|
||||
|
||||
```bash
|
||||
tools/create_sitting_approvals.sh --sitting 2026-09-21 \
|
||||
--receipt 2026-09-21-budget-approval-create.json --expect 1
|
||||
```
|
||||
|
||||
Check first without credentials:
|
||||
`.venv/bin/python -B tools/create_sitting_approvals.py --dry-run --sitting 2026-09-21 --receipt 2026-09-21-budget-approval-create.json --expect 1`.
|
||||
The receipt at `docs/evidence/2026-09-21-budget-approval-create.json` gives
|
||||
`approval_id` and the engine-computed binding digest.
|
||||
|
||||
2. **Flex Auth admission as a visible version change.** In
|
||||
`flex-auth/examples/informed-decision-sitting/policy.md`: `version: v1` → `v2`,
|
||||
add `"memo:infd-20260921-b01"` to `records` with the receipt's `approval_id`,
|
||||
`binding_digest`, `label: "b01"`, the binding from
|
||||
`approval-create-intents.json`, `memo_version: 1`; mirror it in `records.json`.
|
||||
Keep all seven v1 records. Do not add the record before step 1: an empty
|
||||
approval id must never be a policy value. Build the image in CI, bump
|
||||
`values/informed-decision-sitting.yaml` digest, deploy.
|
||||
|
||||
3. **Point Informed Decision at v2.** `deploy/sitting-admission.json`:
|
||||
`version: v2`, new `package_digest`. Roll out the review service.
|
||||
|
||||
4. **Load and sit.** Attach the live KeyCape subject, load the memo
|
||||
(`tools/load_sitting_memos.py`), and the human accepts at the surface.
|
||||
The accepted approval id is recorded as `authority_ref` in the SpendPolicy.
|
||||
28
docs/batches/2026-09-21/approval-create-intents.json
Normal file
28
docs/batches/2026-09-21/approval-create-intents.json
Normal file
|
|
@ -0,0 +1,28 @@
|
|||
{
|
||||
"kind": "informed-decision-approval-create-intents",
|
||||
"sitting_id": "infd-sitting-2026-09-21",
|
||||
"status": "not-posted",
|
||||
"posted": false,
|
||||
"requester_client": "informed-decision-sitting-requester",
|
||||
"human_control": true,
|
||||
"pdp_path": false,
|
||||
"required_count": 1,
|
||||
"note": "Intents only. Digests are computed by approval-engine at create; do not invent them here.",
|
||||
"intents": [
|
||||
{
|
||||
"memo_id": "infd-20260921-b01",
|
||||
"create_client": "informed-decision-sitting-requester",
|
||||
"binding": {
|
||||
"action": "accept",
|
||||
"actor": "informed-decision",
|
||||
"principal": "helixforge-factory",
|
||||
"purpose": "Accept the spend envelope for metered Glas runs on the Anthropic key",
|
||||
"target": {
|
||||
"id": "spend-envelope:hfact-glas-anthropic-2026-09",
|
||||
"type": "spend-envelope",
|
||||
"system": "rein-aharness"
|
||||
}
|
||||
}
|
||||
}
|
||||
]
|
||||
}
|
||||
24
docs/batches/2026-09-21/budget/index.json
Normal file
24
docs/batches/2026-09-21/budget/index.json
Normal file
|
|
@ -0,0 +1,24 @@
|
|||
{
|
||||
"kind": "informed-decision-batch",
|
||||
"id": "infd-batch-2026-09-21-budget",
|
||||
"review_group": "net-kingdom-admins",
|
||||
"status": "draft-unsigned",
|
||||
"submitted": false,
|
||||
"one_question_per_memo": true,
|
||||
"approve_all_forbidden": true,
|
||||
"agent_disposition_forbidden": true,
|
||||
"ordinal": [
|
||||
{
|
||||
"n": 1,
|
||||
"memo_id": "infd-20260921-b01",
|
||||
"workplan": "SECRETS-WP-0009",
|
||||
"task": "SECRETS-WP-0009-T03",
|
||||
"hub_task_prefix": "f8069c8a",
|
||||
"question": "Accept the spend envelope for metered Glas runs on the Anthropic key (EUR 5 per run, 20 per day, 500 total, until 2027-01-31)?",
|
||||
"memo": "infd-20260921-b01.memo.json",
|
||||
"packet": "infd-20260921-b01.packet.md",
|
||||
"packet_hash": "sha256:a3d3f4e33d75579795c0e407971c0d472432569ef68a9408e9897587a58f0deb",
|
||||
"required_highlight": "infd-20260921-b01-h1"
|
||||
}
|
||||
]
|
||||
}
|
||||
|
|
@ -0,0 +1 @@
|
|||
{"approval_binding_digest":null,"approval_id":null,"binding":{"justification":null,"principal":{"display_name":"Named reviewer in net-kingdom-admins","id":"pending-human-session","identifiers":[],"kind":"person","role":"reviewer"},"target":{"environment":"prod","id":"spend-envelope:hfact-glas-anthropic-2026-09","kind":"spend-envelope","label":"Glas metered runs on the Anthropic key (railiance01)","requires_new_bind":false},"terms":null},"binding_level":"organizational","brief":"Sets the spending authority that rein-aharness MessagesOwner enforces before each metered Glas run on railiance01. Accepting it does not deliver the key, run a model or create an OpenBao policy; those are three separate SECRETS-WP-0009-T03 approvals. The EUR 100 monthly limit is recorded here but not enforced by the software.","highlights":[{"id":"infd-20260921-b01-h1","item_id":"infd-20260921-b01-packet","locator":{"kind":"work_record","task":"SECRETS-WP-0009-T03","workplan":"SECRETS-WP-0009"},"note":"The EUR 100 per month limit is NOT enforced: SpendPolicy has no monthly ceiling. Only EUR 5 per run, EUR 20 per day and EUR 500 total are enforced. Every completed run is charged its full reservation (EUR 4.9938), not its actual cost.","required_ack":true,"severity":"critical"}],"id":"infd-20260921-b01","locale":"en","packet":[{"hash":"sha256:a3d3f4e33d75579795c0e407971c0d472432569ef68a9408e9897587a58f0deb","item_id":"infd-20260921-b01-packet","label":"infd-20260921-b01-packet"}],"question":"Accept the spend envelope for metered Glas runs on the Anthropic key (EUR 5 per run, 20 per day, 500 total, until 2027-01-31)?","requested_act":"approve","sealed":false,"step_kind":"approve","ui_release":"informed-decision@0.2.0","version":1}
|
||||
51
docs/batches/2026-09-21/budget/infd-20260921-b01.packet.md
Normal file
51
docs/batches/2026-09-21/budget/infd-20260921-b01.packet.md
Normal file
|
|
@ -0,0 +1,51 @@
|
|||
# SECRETS-WP-0009-T03 — spend envelope for metered Glas runs
|
||||
|
||||
Blocking workplan: SECRETS-WP-0009
|
||||
Blocking task: SECRETS-WP-0009-T03 (hub prefix f8069c8a)
|
||||
Related: HFACT-WP-0001-T01/T04 (SpendPolicy and owner config), GLAS-WP-0012
|
||||
|
||||
## Question
|
||||
Accept the spend envelope for metered Glas runs on the Anthropic key (EUR 5 per run, 20 per day, 500 total, until 2027-01-31)?
|
||||
|
||||
## One act
|
||||
Accept this envelope as the spend authority for rein-aharness MessagesOwner
|
||||
`metered-once` runs on railiance01 using the Anthropic key of catalog lane
|
||||
`glas-claude-agent-dev-anthropic`. The accepted approval id becomes the
|
||||
SpendPolicy `authority_ref` for envelope `hfact-glas-anthropic-2026-09`.
|
||||
|
||||
## Enforced values (rein-aharness SpendPolicy, decimal strings)
|
||||
|
||||
| Field | Value | Note |
|
||||
| --- | --- | --- |
|
||||
| `per_run_eur` | 5 | Operator-stated |
|
||||
| `daily_eur` | 20 | Operator-stated; timezone Europe/Berlin |
|
||||
| `total_eur` | 500 | Operator-stated; over the whole envelope |
|
||||
| `eur_per_usd` | 0.87 | Operator rate 1 EUR = 1.15 USD (1/1.15 = 0.8696), rounded up |
|
||||
| `max_liability_usd` | 5.74 | Per run. Reserves ceil(5.74 x 0.87) = EUR 4.9938, inside EUR 5 |
|
||||
| `max_budget_usd` | 5.00 | Per run. Claude CLI stop threshold, inside liability |
|
||||
| `valid_from` | acceptance time | |
|
||||
| `expires_at` | 2027-01-31T23:59:59+01:00 | Operator-stated |
|
||||
|
||||
Resulting capacity: at most 4 runs per day and 100 runs in total. A completed run
|
||||
is charged its full reservation, not its reported cost. A failed, cancelled or
|
||||
unaccounted run keeps its reservation and blocks further runs until reconciled.
|
||||
Cost above liability permanently marks the envelope breached.
|
||||
|
||||
The operator's overall USD 600 budget and USD 800 liability caps are dominated
|
||||
by `total_eur` 500 (= USD 575) and need no separate field.
|
||||
|
||||
## Recorded, not enforced
|
||||
- EUR 100 per calendar month. SpendPolicy has no monthly ceiling; a rein-aharness
|
||||
follow-up adds `monthly_eur`. Until then the operator reviews monthly use.
|
||||
|
||||
## Scope bound by the SpendPolicy, filled in before the private file is written
|
||||
`worker_id`, `activity_definition_id`, `target_repo`, `project`, `profile_ref`,
|
||||
`profile_sha256`, `descriptor_sha256`, `repository_grant_id`, `max_turns` come from
|
||||
the admitted factory profile (HFACT-WP-0001-T01). They narrow this envelope; they
|
||||
cannot widen the amounts above.
|
||||
|
||||
## Must not
|
||||
- Deliver, read or display the Anthropic key
|
||||
- Authorize the OpenBao apply, verify or exec actions (separate T03 approvals)
|
||||
- Cover llm-connect or its DeepSeek default; that path is not this envelope
|
||||
- Raise any amount or extend the expiry without a new memo
|
||||
12
docs/batches/2026-09-21/sitting.json
Normal file
12
docs/batches/2026-09-21/sitting.json
Normal file
|
|
@ -0,0 +1,12 @@
|
|||
{
|
||||
"kind": "informed-decision-sitting",
|
||||
"id": "infd-sitting-2026-09-21",
|
||||
"review_group": "net-kingdom-admins",
|
||||
"status": "draft-unsigned",
|
||||
"batches": [
|
||||
"infd-batch-2026-09-21-budget"
|
||||
],
|
||||
"memo_count": 1,
|
||||
"bind_path": "create approval (attended), Flex Auth exact-record admission, load store, human accept",
|
||||
"note": "Unsigned draft. Live bind substitutes pending-human-session with the authenticated key-cape subject."
|
||||
}
|
||||
Loading…
Add table
Add a link
Reference in a new issue