{ "task": "INFD-WP-0004-T01", "observed_by": "operator, read-only query of live policy_observations", "checks": "4 latest read checks at 2026-09-21T20:37:40Z (memo:infd-20260914-d02, d03, d04, memo:infd-20260921-b01), all policy_denied", "subject_attributes_match_policy": { "groups_contains_net_kingdom_admins": true, "tenant_source": "directory-asserted", "principal_type_source": "authentication-derived", "level": "aal2", "methods": ["pwd", "otp"] }, "auth_age_at_check_seconds": 1744, "policy_maximum_age_seconds": 900, "finding": "The only failing condition is MFA freshness. The operator reported a fresh sign-in, but the assurance timestamp KeyCape supplied was about 29 minutes old at check time. This is consistent with INFD-IN-0005 (a reused session, or a prior timestamp carried forward). There is no identity or group regression. The three SECRETS-WP-0010-T03 memos are additionally outside the served compact-sitting v2 package.", "consequence": "A browsing overview cannot rely on the binding-grade read bar. Pursue the list action (INFD-IN-0008) and continue INFD-IN-0005 separately for binding." }