# Sitting requester custody — requested, not allocated **Workplan:** `INFD-WP-0002-T03` **Owner:** `railiance-platform` (OpenBao KV + ESO + attended reader) **Peer:** `key-cape` (client row; not yet registered) **Status:** requested 2026-09-14. **No CCR id is allocated here. No secret is in this repository. Do not apply from this file.** Same split as `CCR-2026-0024` / `CCR-2026-0025` for `secrets-engine-requester`: one KeyCape **verifier** path (ESO) and one **attended operator reader**. Do not widen those CCRs or that KV path. ## What to allocate Platform assigns the next CCR pair. Suggested shape, names only: | Piece | Suggested value | | --- | --- | | KV path | `platform/workloads/informed-decision/sitting-requester` | | Field | `CLIENT_SECRET` only | | Verifier policy | read that path; Kubernetes auth for `external-secrets` in `external-secrets` | | Reader policy | read that path; OIDC attended operator; sibling paths and parent listing denied | | ESO / env | `KEYCAPE_INFORMED_DECISION_SITTING_REQUESTER_CLIENT_SECRET` (already the `secretRef` name in the KeyCape request) | | Workload | `informed-decision` | | Tenant | `platform` / `tenant:platform` | Do not put `approval:approve` or `approval:consume` material on this path. The human PKCE client stays public and secretless. ## Activation conditions (when platform and key-cape accept) 1. KeyCape owns `informed-decision-sitting-requester` (`applied: false` today). 2. Attended authority writes CAS=0 custody to the new path only. 3. Exact policy/auth readback; sibling `secrets-engine/approval-requester` denied. 4. Excess scopes (`approval:approve`, `approval:consume`, `approval:read`) refused at token exchange. 5. Wrong secret refused. No human entry synthesized. No POST of sitting intents until that proof exists. Registration contract: `docs/keycape-sitting-requester-registration.md`. Create intents (not posted): `docs/batches/2026-09-14/approval-create-intents.json`.