Userinterface for executive decisions modeled as a sign and return book.
Find a file
tegwick b8e57e8404 Architecture Blueprint and rewritten SCOPE; close T05 and T06
T05 written after the ruling rather than before it, which was the point of
gating it. GH-DEC-2026-012 limit 3 did most of the shaping: the evidence copy
must reach audit-core independently of this component, because here the actor
being audited and the evidence source are the same. Booked as four binding
implementation consequences plus O-02, which must be resolved before T08 ships —
"we will add the independent path later" is how limit 3 becomes
limit-3-in-principle.

Other constraints fixed in the blueprint: presentation/ is the only writer of
view_hash; the approval-engine client exposes no validity cache; a fail-closed
outcome is never recorded as an approver's decline, since the human made none;
the assurance shape is cited from key-cape's contract rather than restated so it
cannot drift; and no polling loop may synthesise the inbox approval-engine
refuses to provide.

T06 closed with the SCOPE.md rewrite the ruling unblocked. It carries a "What
this repository does not claim" section, because a scope file listing only
capabilities overstates them: the decision path is not validated while
GH-DEC-2026-010 is open, the residual is not closed, view_hash is not inside the
approval entry, and nothing is deployed.

Two open items block the remainder. O-01, the human token tenant, blocks T07 and
is not ours alone to decide. O-02, the independent evidence path, blocks T08.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01V3W1dQG7GFFM9d94jFx7iR

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1565372@bnt-lap001
Assistant-Session: 16bb2f25-b34c-49ef-8e94-5fec3567a568
2026-09-09 22:29:06 +02:00
docs Architecture Blueprint and rewritten SCOPE; close T05 and T06 2026-09-09 22:29:06 +02:00
history/20260909-initial-exploration Establish INTENT, Stage 1 GOAL, and founding workplan 2026-09-09 10:47:36 +02:00
informed_decision Declare the layer per GH-DEC-2026-012; close T02 2026-09-09 22:25:35 +02:00
intakes Add PRD and Use Case Catalog; file the gate-house request (T02-T04) 2026-09-09 14:11:36 +02:00
schemas Promote schema and canonicalizer out of history; add EvidenceModel (T06) 2026-09-09 14:16:28 +02:00
tests Declare the layer per GH-DEC-2026-012; close T02 2026-09-09 22:25:35 +02:00
workplans Architecture Blueprint and rewritten SCOPE; close T05 and T06 2026-09-09 22:29:06 +02:00
.custodian-brief.md chore(consistency): sync task status from DB [auto] 2026-09-09 22:26:06 +02:00
.repo-classification.yaml Use in-vocabulary capability tags 2026-09-09 12:40:50 +02:00
AGENTS.md Correct repo flavor to product; add SCOPE, AGENTS, classification 2026-09-09 12:38:41 +02:00
GOAL.md Declare the layer per GH-DEC-2026-012; close T02 2026-09-09 22:25:35 +02:00
INTENT.md Declare the layer per GH-DEC-2026-012; close T02 2026-09-09 22:25:35 +02:00
layer.yaml Declare the layer per GH-DEC-2026-012; close T02 2026-09-09 22:25:35 +02:00
Makefile Promote schema and canonicalizer out of history; add EvidenceModel (T06) 2026-09-09 14:16:28 +02:00
pep-stance.yaml Declare the layer per GH-DEC-2026-012; close T02 2026-09-09 22:25:35 +02:00
pyproject.toml Promote schema and canonicalizer out of history; add EvidenceModel (T06) 2026-09-09 14:16:28 +02:00
README.md Establish INTENT, Stage 1 GOAL, and founding workplan 2026-09-09 10:47:36 +02:00
SCOPE.md Architecture Blueprint and rewritten SCOPE; close T05 and T06 2026-09-09 22:29:06 +02:00
WORK-RECORDS.md Architecture Blueprint and rewritten SCOPE; close T05 and T06 2026-09-09 22:29:06 +02:00

informed-decision

User interface for executive decisions, modelled as a sign-and-return book — the German Umlaufmappe / Zeichnungsbuch, made cryptographic.

A Decision Memo carries a question, the context needed to answer it, the requested act, and a binding between identity, what was shown, and what was bound. The promise is not "the file was signed" but "this person, in this role, was shown this view, and bound this act."

One object model from a ten-second login (L0) to a multi-party instrument (L5).

Where to start

File What it is
INTENT.md Why this repository exists and what it must never become
GOAL.md The current stage, its invariants, and its definition of done
workplans/ Current work
history/20260909-initial-exploration/ Founding exploration — schema, state transitions, canonicalization, vectors

Stage 1

Own the browser-facing approver UI that approval-engine deliberately does not contain, and answer in writing who owns it. approval-engine is a bearer-token resource server with no browser client; key-cape (KEY-WP-0013-T02) is waiting on a client_id and callback URI that no component has claimed. This repository claims them.

See GOAL.md.

Boundaries

This repository renders questions and records answers. It does not decide (access-engine), does not own the approval object (approval-engine), does not author approval doctrine (gate-house), does not authenticate anyone (key-cape), and does not archive the trail (audit-core).