informed-decision/docs/batches/2026-09-14/policy-request.md
tegwick 6289ecbb68 Re-open INFD-WP-0002-T03 live accept; keep the sitting unsigned.
audit-core rollout made origin /readyz 200. Remaining gates are the
T03-only Flex Auth package, no approval:create requester for these
eight acts, and a live KeyCape subject. Attach writes bound copies
from a created receipt; it does not bind.

Assistant: grok
Assistant-Session: 01a09dc1-b21e-77e1-919e-fcad2f82b267
2026-09-15 00:35:14 +02:00

37 lines
1.6 KiB
Markdown

# Flex Auth policy request — compact sitting
Not admitted. Not a local allow. Not an expansion of the T03 three-record
mandate (`FLEX-WP-0027`, `examples/informed-decision-t03`).
`net-kingdom-admins` may review these eight Decision Memos **only after**
the operator admits a new package that pins exact `memo_id`, `approval_id`
and native `binding.digest`. Until those approval objects exist, this file
is a request shape, not a compilable package.
## Intended allow (same identity bar as T03)
- caller: `system:serviceaccount:informed-decision:review` via TokenReview
- subject: verified human, `tenant:platform`, group `net-kingdom-admins`,
KeyCape AAL2 MFA facts as in the T03 package
- actions: `read`, `acknowledge`, `accept`, `return`, `discuss`, `decline`
- deny every other resource id
- no consume, no approval create, no presentation claim as policy input
## Exact resource ids (approval ids still unknown)
| resource.id | Blocking record |
| --- | --- |
| `memo:infd-20260914-c01` | SECRETS-WP-0010 native delivery |
| `memo:infd-20260914-c02` | RPF-WP-0035-T02 |
| `memo:infd-20260914-c03` | NK-WP-0032-T03 |
| `memo:infd-20260914-c04` | WARDEN-WP-0027-T02 |
| `memo:infd-20260914-d01` | CUST-WP-0038-T08 |
| `memo:infd-20260914-d02` | HFACT-WP-0001-T03 |
| `memo:infd-20260914-d03` | MASON-WP-0005 plan |
| `memo:infd-20260914-d04` | RCLK-WP-0002-T01 |
Do not copy T03 approval ids into this table. Do not serve this list as
policy until a created-receipt supplies `approval_id` and `binding.digest`
for every row.
Owner: flex-auth. This repository drafts; it does not evaluate authorization.