--- id: INFD-WP-0002 type: workplan title: "Compact sign-off batches for credentials and decisions" domain: infotech repo: informed-decision status: active owner: grok topic_slug: netkingdom flavor: planning depends_on: - INFD-WP-0001 created: "2026-09-14" updated: "2026-09-15" related: - INFD-WP-0001 - STATE-WP-0092 - COORDINATION-WP-0005 origin: demand origin_ref: the-custodian/history/20260914-open-workplan-chokepoints.md state_hub_workstream_id: "a2939a36-eeab-522b-b35a-5399af2757bf" --- # Compact sign-off batches for credentials and decisions Founder direction 2026-09-14: credential and decision chokepoints should move through the informed-decision framework as **batches that can be signed off in a compact timeframe**, not as twelve disconnected `needs_human` tasks. `INFD-WP-0001` still owns Stage 1 (walking skeleton against a deployed `approval-engine`, T08). This plan does **not** absorb the earlier residual “full L3 product.” That remains residual until separately promoted. This plan is the demanded slice: **review-groups of Decision Memos** for (1) credential/custody items and (2) founder/owner decisions. Invariant from Stage 1: **one question per memo**. A batch is a *Umlaufmappe* grouping of memos, not one memo with unrelated acts. Humans bind; agents draft. This repository still does not evaluate authorization (`access-engine` remains the only PDP). ## Draft the first two batches (agent-authored, unsigned) ```task id: INFD-WP-0002-T01 status: done priority: high state_hub_task_id: "03d1b699-cb7b-5954-a4d2-cbe06af24c5a" ``` From the 2026-09-14 chokepoint assessment, assemble two compact batches as Decision Memo files (or the current memo schema) under `docs/batches/2026-09-14/`: 1. **Credentials / custody** — OpenBao paths, issuer/registration leftovers, CCR-style items, and any `warden route` pointer that still needs a human to actually mint or seal. Each memo is one act. No secret values in the memos. 2. **Decisions / assent** — founder or owner sign-offs currently holding workplans (reviews, explicit approvals, policy accepts). Each memo is one question. Bound the set so a single sitting can finish it (small N, ordered, highlights required). Name the review group already admitted (`net-kingdom-admins` or the current human review group). Do not submit until T02. Done when both batch indexes exist, each memo has one binding target, required highlights, and a trace to the blocking workplan/task id. 2026-09-14: eight unsigned memos under `docs/batches/2026-09-14/` (credentials c01–c04, decisions d01–d04). Review group `net-kingdom-admins`. Not submitted. ## Batch presentation contract (review-group, compact sitting) ```task id: INFD-WP-0002-T02 status: done priority: high depends_on: [INFD-WP-0002-T01] state_hub_task_id: "8babbc7d-5c79-5130-93ad-e2569ed3208d" ``` Specify how a batch is presented without forking the Decision Memo schema: ordered list, per-memo bind, progress across the sitting, no “approve all” that skips highlights. Reuse review-group work already in this repo. If Stage 1 UI cannot yet render a group, the contract still holds for a recorded desktop sitting. Done when `docs/specs/` (short addendum, not a new product) states the batch rules and the anti-requirement: no bundled unrelated acts, no auto-approval, no agent disposition. 2026-09-14: `docs/specs/CompactSignoffBatches.md`. ## Sign-off sitting once the Stage 1 surface can bind ```task id: INFD-WP-0002-T03 status: wait priority: high depends_on: [INFD-WP-0002-T02, INFD-WP-0001] state_hub_task_id: "917e3e34-b9de-5c51-ab29-e820957a7407" ``` Wait until `INFD-WP-0001-T08` (or an equivalent deployed bind path) can take a real human disposition. Then run one compact sitting on the two batches. Record presentation evidence (`view_hash` per memo). Unfinished memos stay in the batch; do not mark the workplan finished on a partial sitting. Done when at least one credential memo and one decision memo are bound by a human through this surface, reconstructable from stored presentation, and the blocking hub tasks are updated from those dispositions rather than from chat. 2026-09-14 — **T08 bind path historically proven; this sitting still cannot run.** Probe `docs/evidence/2026-09-14-infd-0002-t03-bind-path-probe.json`. The live store already holds three `accept` dispositions with confirmed engine submissions for `SECRETS-WP-0010-T03-{apply,verify,exec}` (presentations + required acks). That is not this batch. Compact memos remain `approval_id: null` / `pending-human-session` and are not in the store. New accept is refused: origin `/readyz` 503 `approval_path_not_connected` because `audit-core` is not Ready, its Service has no ready endpoints, and the review pod gets connection refused talking to the audit ClusterIP. Operator packet `docs/batches/2026-09-14/OPERATOR.md`; preflight `tools/sitting_bind_preflight.py`. No agent disposition. Task stays `wait`. 2026-09-14 22:16 UTC — **live accept reopened; sitting still not admitted.** audit-core `b0e6792` is Ready; origin `/readyz` 200; preflight `live_accept=open`. Remaining gates: (1) Flex Auth T03 package still allows only `memo:SECRETS-WP-0010-T03-*` — `docs/batches/2026-09-14/policy-request.md` is a request, not an admission; (2) no `approval:create` requester for these eight acts; (3) drafts still `approval_id: null` / `pending-human-session`; (4) human bind. Attach tool `tools/attach_compact_bindings.py` writes bound copies from a created receipt and live subject; it does not create approvals or dispositions. Evidence: `docs/evidence/2026-09-14-infd-0002-t03-accept-reopened.json`. Task stays `wait`. 2026-09-14 22:44 UTC — **sitting requester requested, not registered.** `docs/keycape-sitting-requester-registration.md` asks key-cape for a create-only confidential client (`informed-decision-sitting-requester`, `sub=informed-decision`, scope `approval:create` only, no approve/consume, no redirect). Intents for the eight bindings are in `docs/batches/2026-09-14/approval-create-intents.json` (`posted: false`; `c01` create-client undecided). No secret, no POST, no bind. 2026-09-15 — **requester live; sittings still wait on attended create + human bind.** RPF-WP-0042 finished: CCR-2026-0026/0027 applied, exchange proof verified, no sitting POST. `tools/create_sitting_approvals.py` requires attended reader and posts seven intents (`c01` skipped). Flex Auth package still waits on those native ids. This shell is not an attended session. Task stays `wait`. ## Feed outcomes back to State Hub without hub-authoring ```task id: INFD-WP-0002-T04 status: wait priority: medium depends_on: [INFD-WP-0002-T03] state_hub_task_id: "26d8ff42-65bb-582e-9ecf-dbd367eaa7a8" ``` For each bound memo, update the **owning repo file** (task status, decision record, CCR note) and let `fix-consistency` project. Do not `POST /workplans/` or mint hub-only tasks. Residual unsigned memos either stay in a later batch or are declined with a reason. Done when the assessment’s credential/decision examples that were in the sitting show file-level status changes and a progress event naming the memo ids.