audit-core rollout made origin /readyz 200. Remaining gates are the T03-only Flex Auth package, no approval:create requester for these eight acts, and a live KeyCape subject. Attach writes bound copies from a created receipt; it does not bind. Assistant: grok Assistant-Session: 01a09dc1-b21e-77e1-919e-fcad2f82b267
37 lines
1.6 KiB
Markdown
37 lines
1.6 KiB
Markdown
# Flex Auth policy request — compact sitting
|
|
|
|
Not admitted. Not a local allow. Not an expansion of the T03 three-record
|
|
mandate (`FLEX-WP-0027`, `examples/informed-decision-t03`).
|
|
|
|
`net-kingdom-admins` may review these eight Decision Memos **only after**
|
|
the operator admits a new package that pins exact `memo_id`, `approval_id`
|
|
and native `binding.digest`. Until those approval objects exist, this file
|
|
is a request shape, not a compilable package.
|
|
|
|
## Intended allow (same identity bar as T03)
|
|
|
|
- caller: `system:serviceaccount:informed-decision:review` via TokenReview
|
|
- subject: verified human, `tenant:platform`, group `net-kingdom-admins`,
|
|
KeyCape AAL2 MFA facts as in the T03 package
|
|
- actions: `read`, `acknowledge`, `accept`, `return`, `discuss`, `decline`
|
|
- deny every other resource id
|
|
- no consume, no approval create, no presentation claim as policy input
|
|
|
|
## Exact resource ids (approval ids still unknown)
|
|
|
|
| resource.id | Blocking record |
|
|
| --- | --- |
|
|
| `memo:infd-20260914-c01` | SECRETS-WP-0010 native delivery |
|
|
| `memo:infd-20260914-c02` | RPF-WP-0035-T02 |
|
|
| `memo:infd-20260914-c03` | NK-WP-0032-T03 |
|
|
| `memo:infd-20260914-c04` | WARDEN-WP-0027-T02 |
|
|
| `memo:infd-20260914-d01` | CUST-WP-0038-T08 |
|
|
| `memo:infd-20260914-d02` | HFACT-WP-0001-T03 |
|
|
| `memo:infd-20260914-d03` | MASON-WP-0005 plan |
|
|
| `memo:infd-20260914-d04` | RCLK-WP-0002-T01 |
|
|
|
|
Do not copy T03 approval ids into this table. Do not serve this list as
|
|
policy until a created-receipt supplies `approval_id` and `binding.digest`
|
|
for every row.
|
|
|
|
Owner: flex-auth. This repository drafts; it does not evaluate authorization.
|