# Flex Auth policy request — compact sitting Not admitted. Not a local allow. Not an expansion of the T03 three-record mandate (`FLEX-WP-0027`, `examples/informed-decision-t03`). `net-kingdom-admins` may review these eight Decision Memos **only after** the operator admits a new package that pins exact `memo_id`, `approval_id` and native `binding.digest`. Until those approval objects exist, this file is a request shape, not a compilable package. ## Intended allow (same identity bar as T03) - caller: `system:serviceaccount:informed-decision:review` via TokenReview - subject: verified human, `tenant:platform`, group `net-kingdom-admins`, KeyCape AAL2 MFA facts as in the T03 package - actions: `read`, `acknowledge`, `accept`, `return`, `discuss`, `decline` - deny every other resource id - no consume, no approval create, no presentation claim as policy input ## Exact resource ids (approval ids still unknown) | resource.id | Blocking record | | --- | --- | | `memo:infd-20260914-c01` | SECRETS-WP-0010 native delivery | | `memo:infd-20260914-c02` | RPF-WP-0035-T02 | | `memo:infd-20260914-c03` | NK-WP-0032-T03 | | `memo:infd-20260914-c04` | WARDEN-WP-0027-T02 | | `memo:infd-20260914-d01` | CUST-WP-0038-T08 | | `memo:infd-20260914-d02` | HFACT-WP-0001-T03 | | `memo:infd-20260914-d03` | MASON-WP-0005 plan | | `memo:infd-20260914-d04` | RCLK-WP-0002-T01 | Do not copy T03 approval ids into this table. Do not serve this list as policy until a created-receipt supplies `approval_id` and `binding.digest` for every row. Owner: flex-auth. This repository drafts; it does not evaluate authorization.