Establish INTENT, Stage 1 GOAL, and founding workplan
Claim ownership of the browser-facing approver UI that approval-engine deliberately does not contain. approval-engine's INTENT names an approvals inbox under Non-Goals, and docs/keycape-service-registrations.md records that the human approver client's client_id and callback URI "must come from its owner once it exists" — leaving key-cape's KEY-WP-0013-T02 blocked on an unassigned component. - INTENT.md: Decision Memo concept, the binding/awareness split and the two hashes, ownership and non-ownership against the named estate repositories, and a provisional PEP-shaped layer placement flagged for a gate-house ruling rather than asserted. - GOAL.md: Stage 1 is the L3 approval approver surface — the narrowest real consumer with a live blocking dependency — plus the written answer to who owns the approver UI. - workplans/INFD-WP-0001: founding documents, the gate-house layer/ownership ruling, the four specs (PRD, UseCaseCatalog, ArchitectureBlueprint, EvidenceModel), schema and canonicalizer promotion out of history/ with the isolation vectors under test, the key-cape client registration, and a walking skeleton that includes return and discuss. history/ is preserved unmodified as provenance. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01V3W1dQG7GFFM9d94jFx7iR Assistant: claude-code Assistant-Model: opus Assistant-Process: 1565372@bnt-lap001 Assistant-Session: 16bb2f25-b34c-49ef-8e94-5fec3567a568
This commit is contained in:
parent
771ddb9ced
commit
ee2cca579c
16 changed files with 3218 additions and 1 deletions
|
|
@ -0,0 +1,31 @@
|
|||
{
|
||||
"memo_id": "01K4Q8Z3R7V2N6K9M1P5T8W4XC",
|
||||
"memo_version": 2,
|
||||
"question": "Do you formally accept ADR-0042 as the billing architecture for prod?",
|
||||
"requested_act": "accept",
|
||||
"binding_level": "aes",
|
||||
"brief": "Replace nightly batch invoicing with an append-only event ledger.",
|
||||
"locale": "en",
|
||||
"ui_release": "informed-decision@0.3.1",
|
||||
"packet": [
|
||||
{
|
||||
"item_id": "01K4Q8DOC0000000000000001",
|
||||
"hash": {
|
||||
"alg": "sha256",
|
||||
"hex": "6b1c0f8a9d2e4c7b8a1f0e3d5c6b7a8f9e0d1c2b3a4f5e6d7c8b9a0f1e2d3c4b"
|
||||
}
|
||||
}
|
||||
],
|
||||
"highlights": [
|
||||
{
|
||||
"id": "01K4Q8HL00000000000000001",
|
||||
"item_id": "01K4Q8DOC0000000000000001",
|
||||
"severity": "critical",
|
||||
"required_ack": true,
|
||||
"locator": {
|
||||
"kind": "markdown_heading",
|
||||
"heading": "Consequences / rollback"
|
||||
}
|
||||
}
|
||||
]
|
||||
}
|
||||
|
|
@ -0,0 +1,5 @@
|
|||
{
|
||||
"login_view_hash": "492d9d311bf44ec9de0d0abef28abac7d31df2781527e8fe276a3186ee1b06b8",
|
||||
"login_awareness_hash": "2be7742970a01e7a879ae5040660659fb8c9a5c024e6c7fb338f3944a4fe05d1",
|
||||
"adr_view_hash": "1c89ec07c3cc9d16f85a1ba1be5169456b3c55d21161f64037787779ae91f202"
|
||||
}
|
||||
|
|
@ -0,0 +1,63 @@
|
|||
{
|
||||
"memo_id": "01K4LOGIN00000000000000001",
|
||||
"memo_version": 1,
|
||||
"locale": "en",
|
||||
"ui_release": "informed-decision@0.4.0",
|
||||
"proposed_hat": {
|
||||
"id": "hat:finance-controller",
|
||||
"label": "Finance Controller",
|
||||
"kind": "access_profile",
|
||||
"elevates": false,
|
||||
"permissions_preview": ["invoice.read", "invoice.export"],
|
||||
"scope_id": "tenant:acme"
|
||||
},
|
||||
"proposed_hat_source": "last_used",
|
||||
"available_hats": [
|
||||
{
|
||||
"id": "hat:finance-controller",
|
||||
"label": "Finance Controller",
|
||||
"kind": "access_profile",
|
||||
"elevates": false,
|
||||
"permissions_preview": ["invoice.read", "invoice.export"],
|
||||
"scope_id": "tenant:acme"
|
||||
},
|
||||
{
|
||||
"id": "hat:auditor-readonly",
|
||||
"label": "Auditor (read-only)",
|
||||
"kind": "perspective",
|
||||
"elevates": false,
|
||||
"permissions_preview": ["invoice.read"],
|
||||
"scope_id": "tenant:acme"
|
||||
},
|
||||
{
|
||||
"id": "hat:payroll-admin",
|
||||
"label": "Payroll Admin",
|
||||
"kind": "role",
|
||||
"elevates": true,
|
||||
"permissions_preview": ["payroll.run", "employee.export-all"],
|
||||
"scope_id": "tenant:acme"
|
||||
}
|
||||
],
|
||||
"available_scopes": [
|
||||
{
|
||||
"kind": "tenant",
|
||||
"id": "tenant:acme",
|
||||
"label": "ACME Corp",
|
||||
"environment": "prod",
|
||||
"requires_new_bind": true
|
||||
},
|
||||
{
|
||||
"kind": "tenant",
|
||||
"id": "tenant:beta",
|
||||
"label": "Beta GmbH",
|
||||
"environment": "prod",
|
||||
"requires_new_bind": true
|
||||
}
|
||||
],
|
||||
"last_session": {
|
||||
"ended_at": "2026-09-08T16:12:00Z",
|
||||
"hat_id": "hat:finance-controller",
|
||||
"scope_id": "tenant:acme"
|
||||
},
|
||||
"situation_note": "Last session Tuesday 18:12 CEST as Finance Controller in ACME. Payroll Admin is an elevating hat and needs its own bind."
|
||||
}
|
||||
|
|
@ -0,0 +1,73 @@
|
|||
{
|
||||
"memo_id": "01K4LOGIN00000000000000001",
|
||||
"memo_version": 1,
|
||||
"question": "Log into Payroll-Prod as Bernd Worsch in tenant ACME?",
|
||||
"requested_act": "login",
|
||||
"binding_level": "organizational",
|
||||
"brief": "You are entering Payroll-Prod. Sessions are recorded. Privileges at the gate are identity-scoped, not hat-scoped.",
|
||||
"locale": "en",
|
||||
"ui_release": "informed-decision@0.4.0",
|
||||
"packet": [],
|
||||
"highlights": [],
|
||||
"binding": {
|
||||
"principal": {
|
||||
"id": "01K4PERSONBERND00000000001",
|
||||
"kind": "person",
|
||||
"display_name": "Bernd Worsch",
|
||||
"role": "employee",
|
||||
"identifiers": [
|
||||
{ "scheme": "email", "value": "bernd.worsch@example.com" },
|
||||
{ "scheme": "idp:oidc-sub", "value": "auth.example.com|bernd" }
|
||||
]
|
||||
},
|
||||
"available_identities": [
|
||||
{
|
||||
"id": "01K4PERSONBERND00000000001",
|
||||
"kind": "person",
|
||||
"display_name": "Bernd Worsch",
|
||||
"identifiers": [
|
||||
{ "scheme": "idp:oidc-sub", "value": "auth.example.com|bernd" }
|
||||
]
|
||||
},
|
||||
{
|
||||
"id": "01K4PERSONBERNDADMIN000001",
|
||||
"kind": "person",
|
||||
"display_name": "Bernd Worsch (break-glass)",
|
||||
"identifiers": [
|
||||
{ "scheme": "idp:oidc-sub", "value": "auth.example.com|bernd-bg" }
|
||||
]
|
||||
}
|
||||
],
|
||||
"target": {
|
||||
"kind": "tenant",
|
||||
"id": "tenant:acme",
|
||||
"label": "ACME Corp",
|
||||
"environment": "prod",
|
||||
"requires_new_bind": true
|
||||
},
|
||||
"available_bind_scopes": [
|
||||
{
|
||||
"kind": "tenant",
|
||||
"id": "tenant:acme",
|
||||
"label": "ACME Corp",
|
||||
"environment": "prod",
|
||||
"requires_new_bind": true
|
||||
},
|
||||
{
|
||||
"kind": "tenant",
|
||||
"id": "tenant:beta",
|
||||
"label": "Beta GmbH",
|
||||
"environment": "prod",
|
||||
"requires_new_bind": true
|
||||
}
|
||||
],
|
||||
"granted_at_bind": {
|
||||
"roles": ["authenticated"],
|
||||
"permissions": ["session.create"]
|
||||
},
|
||||
"terms": {
|
||||
"monitoring": true,
|
||||
"consent_code": "LOGIN-PROD-2026"
|
||||
}
|
||||
}
|
||||
}
|
||||
Loading…
Add table
Add a link
Reference in a new issue