informed-decision/docs/batches/2026-09-14/policy-request.md
tegwick 6289ecbb68 Re-open INFD-WP-0002-T03 live accept; keep the sitting unsigned.
audit-core rollout made origin /readyz 200. Remaining gates are the
T03-only Flex Auth package, no approval:create requester for these
eight acts, and a live KeyCape subject. Attach writes bound copies
from a created receipt; it does not bind.

Assistant: grok
Assistant-Session: 01a09dc1-b21e-77e1-919e-fcad2f82b267
2026-09-15 00:35:14 +02:00

1.6 KiB

Flex Auth policy request — compact sitting

Not admitted. Not a local allow. Not an expansion of the T03 three-record mandate (FLEX-WP-0027, examples/informed-decision-t03).

net-kingdom-admins may review these eight Decision Memos only after the operator admits a new package that pins exact memo_id, approval_id and native binding.digest. Until those approval objects exist, this file is a request shape, not a compilable package.

Intended allow (same identity bar as T03)

  • caller: system:serviceaccount:informed-decision:review via TokenReview
  • subject: verified human, tenant:platform, group net-kingdom-admins, KeyCape AAL2 MFA facts as in the T03 package
  • actions: read, acknowledge, accept, return, discuss, decline
  • deny every other resource id
  • no consume, no approval create, no presentation claim as policy input

Exact resource ids (approval ids still unknown)

resource.id Blocking record
memo:infd-20260914-c01 SECRETS-WP-0010 native delivery
memo:infd-20260914-c02 RPF-WP-0035-T02
memo:infd-20260914-c03 NK-WP-0032-T03
memo:infd-20260914-c04 WARDEN-WP-0027-T02
memo:infd-20260914-d01 CUST-WP-0038-T08
memo:infd-20260914-d02 HFACT-WP-0001-T03
memo:infd-20260914-d03 MASON-WP-0005 plan
memo:infd-20260914-d04 RCLK-WP-0002-T01

Do not copy T03 approval ids into this table. Do not serve this list as policy until a created-receipt supplies approval_id and binding.digest for every row.

Owner: flex-auth. This repository drafts; it does not evaluate authorization.