informed-decision/workplans/INFD-WP-0002-compact-signoff-batches.md
tegwick 8c03eb85c0 Request sitting-requester OpenBao custody without allocating a CCR.
Verifier + attended reader on a new informed-decision KV path, not a
widening of CCR-2026-0024/0025. Intents still match approval-engine
canonical binding. No secret, no apply, no bind.

Assistant: grok
Assistant-Session: 01a09dc1-b21e-77e1-919e-fcad2f82b267
2026-09-15 01:04:10 +02:00

177 lines
6.9 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

---
id: INFD-WP-0002
type: workplan
title: "Compact sign-off batches for credentials and decisions"
domain: infotech
repo: informed-decision
status: active
owner: grok
topic_slug: netkingdom
flavor: planning
depends_on:
- INFD-WP-0001
created: "2026-09-14"
updated: "2026-09-15"
related:
- INFD-WP-0001
- STATE-WP-0092
- COORDINATION-WP-0005
origin: demand
origin_ref: the-custodian/history/20260914-open-workplan-chokepoints.md
state_hub_workstream_id: "a2939a36-eeab-522b-b35a-5399af2757bf"
---
# Compact sign-off batches for credentials and decisions
Founder direction 2026-09-14: credential and decision chokepoints should
move through the informed-decision framework as **batches that can be
signed off in a compact timeframe**, not as twelve disconnected
`needs_human` tasks.
`INFD-WP-0001` still owns Stage 1 (walking skeleton against a deployed
`approval-engine`, T08). This plan does **not** absorb the earlier
residual “full L3 product.” That remains residual until separately
promoted. This plan is the demanded slice: **review-groups of Decision
Memos** for (1) credential/custody items and (2) founder/owner
decisions.
Invariant from Stage 1: **one question per memo**. A batch is a
*Umlaufmappe* grouping of memos, not one memo with unrelated acts.
Humans bind; agents draft. This repository still does not evaluate
authorization (`access-engine` remains the only PDP).
## Draft the first two batches (agent-authored, unsigned)
```task
id: INFD-WP-0002-T01
status: done
priority: high
state_hub_task_id: "03d1b699-cb7b-5954-a4d2-cbe06af24c5a"
```
From the 2026-09-14 chokepoint assessment, assemble two compact batches
as Decision Memo files (or the current memo schema) under
`docs/batches/2026-09-14/`:
1. **Credentials / custody** — OpenBao paths, issuer/registration
leftovers, CCR-style items, and any `warden route` pointer that still
needs a human to actually mint or seal. Each memo is one act. No
secret values in the memos.
2. **Decisions / assent** — founder or owner sign-offs currently holding
workplans (reviews, explicit approvals, policy accepts). Each memo is
one question.
Bound the set so a single sitting can finish it (small N, ordered,
highlights required). Name the review group already admitted
(`net-kingdom-admins` or the current human review group). Do not submit
until T02.
Done when both batch indexes exist, each memo has one binding target,
required highlights, and a trace to the blocking workplan/task id.
2026-09-14: eight unsigned memos under `docs/batches/2026-09-14/`
(credentials c01c04, decisions d01d04). Review group
`net-kingdom-admins`. Not submitted.
## Batch presentation contract (review-group, compact sitting)
```task
id: INFD-WP-0002-T02
status: done
priority: high
depends_on: [INFD-WP-0002-T01]
state_hub_task_id: "8babbc7d-5c79-5130-93ad-e2569ed3208d"
```
Specify how a batch is presented without forking the Decision Memo
schema: ordered list, per-memo bind, progress across the sitting,
no “approve all” that skips highlights. Reuse review-group work already
in this repo. If Stage 1 UI cannot yet render a group, the contract
still holds for a recorded desktop sitting.
Done when `docs/specs/` (short addendum, not a new product) states the
batch rules and the anti-requirement: no bundled unrelated acts, no
auto-approval, no agent disposition.
2026-09-14: `docs/specs/CompactSignoffBatches.md`.
## Sign-off sitting once the Stage 1 surface can bind
```task
id: INFD-WP-0002-T03
status: wait
priority: high
depends_on: [INFD-WP-0002-T02, INFD-WP-0001]
state_hub_task_id: "917e3e34-b9de-5c51-ab29-e820957a7407"
```
Wait until `INFD-WP-0001-T08` (or an equivalent deployed bind path)
can take a real human disposition. Then run one compact sitting on the
two batches. Record presentation evidence (`view_hash` per memo).
Unfinished memos stay in the batch; do not mark the workplan finished
on a partial sitting.
Done when at least one credential memo and one decision memo are bound
by a human through this surface, reconstructable from stored
presentation, and the blocking hub tasks are updated from those
dispositions rather than from chat.
2026-09-14 — **T08 bind path historically proven; this sitting still
cannot run.** Probe
`docs/evidence/2026-09-14-infd-0002-t03-bind-path-probe.json`.
The live store already holds three `accept` dispositions with confirmed
engine submissions for `SECRETS-WP-0010-T03-{apply,verify,exec}`
(presentations + required acks). That is not this batch. Compact memos
remain `approval_id: null` / `pending-human-session` and are not in the
store. New accept is refused: origin `/readyz` 503
`approval_path_not_connected` because `audit-core` is not Ready, its
Service has no ready endpoints, and the review pod gets connection
refused talking to the audit ClusterIP. Operator packet
`docs/batches/2026-09-14/OPERATOR.md`; preflight
`tools/sitting_bind_preflight.py`. No agent disposition. Task stays
`wait`.
2026-09-14 22:16 UTC — **live accept reopened; sitting still not
admitted.** audit-core `b0e6792` is Ready; origin `/readyz` 200;
preflight `live_accept=open`. Remaining gates: (1) Flex Auth T03
package still allows only `memo:SECRETS-WP-0010-T03-*`
`docs/batches/2026-09-14/policy-request.md` is a request, not an
admission; (2) no `approval:create` requester for these eight acts;
(3) drafts still `approval_id: null` / `pending-human-session`;
(4) human bind. Attach tool `tools/attach_compact_bindings.py` writes
bound copies from a created receipt and live subject; it does not
create approvals or dispositions. Evidence:
`docs/evidence/2026-09-14-infd-0002-t03-accept-reopened.json`.
Task stays `wait`.
2026-09-14 22:44 UTC — **sitting requester requested, not registered.**
`docs/keycape-sitting-requester-registration.md` asks key-cape for a
create-only confidential client (`informed-decision-sitting-requester`,
`sub=informed-decision`, scope `approval:create` only, no approve/consume,
no redirect). Intents for the eight bindings are in
`docs/batches/2026-09-14/approval-create-intents.json` (`posted: false`;
`c01` create-client undecided). No secret, no POST, no bind.
2026-09-14 23:00 UTC — **custody requested from railiance-platform, no CCR
id allocated.** `docs/sitting-requester-custody-request.md` asks for a new
KV path `platform/workloads/informed-decision/sitting-requester` (verifier +
attended reader), not a widening of CCR-2026-0024/0025. Task stays `wait`.
## Feed outcomes back to State Hub without hub-authoring
```task
id: INFD-WP-0002-T04
status: wait
priority: medium
depends_on: [INFD-WP-0002-T03]
state_hub_task_id: "26d8ff42-65bb-582e-9ecf-dbd367eaa7a8"
```
For each bound memo, update the **owning repo file** (task status,
decision record, CCR note) and let `fix-consistency` project. Do not
`POST /workplans/` or mint hub-only tasks. Residual unsigned memos
either stay in a later batch or are declined with a reason.
Done when the assessments credential/decision examples that were in
the sitting show file-level status changes and a progress event naming
the memo ids.