# Request only. railiance-platform allocates the CCR id. # status is requested — not applied, not approved, no secret values. id: unallocated kind: credential-change-request schema_version: 1 request_type: workload-kv-read title: Informed Decision sitting-requester KeyCape client secret (verifier + attended reader) status: requested created: "2026-09-14" updated: "2026-09-14" origin: INFD-WP-0002-T03 origin_ref: informed-decision/docs/keycape-sitting-requester-registration.md requester: agent: grok reason: >- Compact sitting needs a create-only presenter whose binding.actor is informed-decision. Do not widen CCR-2026-0024/0025 or secrets-engine-requester. review: required: true required_approvers: - platform-operator - key-cape-owner target: domain: infotech tenant: platform workload: informed-decision environment: production purpose: create-only sitting requester; work-record decisions, not PEP consume openbao: mount: platform kv_path: platform/workloads/informed-decision/sitting-requester fields: - CLIENT_SECRET delivery: surface: external-secrets env_name: KEYCAPE_INFORMED_DECISION_SITTING_REQUESTER_CLIENT_SECRET risk: classification: high notes: - Scope must remain approval:create only. - Human disposition uses informed-decision-approver (public PKCE). - infd-20260914-c01 may stay on secrets-engine-requester if consume is in-scope. verification: negative: - approval:approve and approval:consume refused at token exchange - sibling secrets-engine/approval-requester denied - parent listing denied activation_conditions: - KeyCape row exists - attended CAS=0 write to this path only - no sitting POST until exchange proof exists