informed-decision/docs/batches/2026-09-14/OPERATOR.md
tegwick 6289ecbb68 Re-open INFD-WP-0002-T03 live accept; keep the sitting unsigned.
audit-core rollout made origin /readyz 200. Remaining gates are the
T03-only Flex Auth package, no approval:create requester for these
eight acts, and a live KeyCape subject. Attach writes bound copies
from a created receipt; it does not bind.

Assistant: grok
Assistant-Session: 01a09dc1-b21e-77e1-919e-fcad2f82b267
2026-09-15 00:35:14 +02:00

3.2 KiB

Compact sitting — operator packet (INFD-WP-0002-T03)

Review group: net-kingdom-admins. Surface: https://decisions.coulomb.social/ Contract: docs/specs/CompactSignoffBatches.md.

An agent may draft, order, and record evidence. It may not accept / decline / seal. Do not mark INFD-WP-0002 finished on a partial sitting.

What is already proven

On 2026-09-14 around 01:06 UTC this origin took three real human accepts for SECRETS-WP-0010-T03-{apply,verify,exec}. That is T08 history, not this batch. infd-20260914-c01 must not reuse those approval ids.

Live accept reopened (2026-09-14 22:16 UTC)

audit-core /readyz was hanging; the Service had no ready endpoints; this origin refused accept (/readyz 503). audit-core b0e6792 rolled out. Now:

  • Origin /healthz 200, /readyz 200 ready, /auth/start 303 to KeyCape
  • Review pod reaches audit-core.audit-core.svc:8080 healthz/readyz 200
  • Preflight: live_accept=open, still not ready_to_sit

Evidence: docs/evidence/2026-09-14-infd-0002-t03-accept-reopened.json.

What still blocks this sitting

  1. Flex Auth still admits only the three T03 memo ids (FLEX-WP-0027, examples/informed-decision-t03). Compact ids would be denied. Request shape: policy-request.md. Do not expand the T03 mandate in place.
  2. No approval:create requester whose binding.actor matches these acts. Do not reuse secrets-engine-requester for WSL2, clock ownership, mason plan, or warden seal.
  3. Drafts still have approval_id: null and principal pending-human-session. Live review refuses missing_act_binding / wrong_recipient.
  4. A human must bind. An agent must not.

Eight unsigned memos (this sitting)

Open in this order. One question each. No approve-all.

n memo_id Blocking record
1 infd-20260914-c01 SECRETS-WP-0010 native delivery
2 infd-20260914-c02 RPF-WP-0035-T02
3 infd-20260914-c03 NK-WP-0032-T03
4 infd-20260914-c04 WARDEN-WP-0027-T02
5 infd-20260914-d01 CUST-WP-0038-T08
6 infd-20260914-d02 HFACT-WP-0001-T03
7 infd-20260914-d03 MASON-WP-0005 plan
8 infd-20260914-d04 RCLK-WP-0002-T01

After requester, receipts, and policy admission

  1. uv run python tools/sitting_bind_preflight.py --origin https://decisions.coulomb.sociallive_accept must stay open.
  2. Owning requester creates eight human_control=true objects, required_count 1, no entries. Carry the native id and binding.digest; do not invent a digest.
  3. uv run python tools/attach_compact_bindings.py --principal <exact-keycape-sub> --receipt <created.json> writes bound/ copies. Unsigned drafts stay unsigned.
  4. Flex Auth admits a new package pinning those eight memo: ids to the native approval id/digest, same identity bar as T03, deny everything else.
  5. Load packet bytes then save_memo from bound/ into the review store.
  6. Sign in. Open /review?memo_id=infd-20260914-c01 through …-d04 in order. Acknowledge the required highlight. Bind that memo. Repeat.
  7. Unfinished memos stay in the batch. File-level owning-repo updates are T04 after a human bind, via fix-consistency, never POST /workplans/.