informed-decision/workplans/INFD-WP-0002-compact-signoff-batches.md
tegwick c3742e27d2 Land attended sitting create now that CCR-2026-0026/0027 is live.
Platform verified create-only exchange; this shell cannot POST.
create_sitting_approvals.py requires attended reader, skips c01, and
refuses a non-loopback approval origin. Dry-run lists the seven memos.

Assistant: grok
Assistant-Session: 01a09dc1-b21e-77e1-919e-fcad2f82b267
2026-09-15 22:19:25 +02:00

7 KiB
Raw Blame History

id type title domain repo status owner topic_slug flavor depends_on created updated related origin origin_ref state_hub_workstream_id
INFD-WP-0002 workplan Compact sign-off batches for credentials and decisions infotech informed-decision active grok netkingdom planning
INFD-WP-0001
2026-09-14 2026-09-15
INFD-WP-0001
STATE-WP-0092
COORDINATION-WP-0005
demand the-custodian/history/20260914-open-workplan-chokepoints.md a2939a36-eeab-522b-b35a-5399af2757bf

Compact sign-off batches for credentials and decisions

Founder direction 2026-09-14: credential and decision chokepoints should move through the informed-decision framework as batches that can be signed off in a compact timeframe, not as twelve disconnected needs_human tasks.

INFD-WP-0001 still owns Stage 1 (walking skeleton against a deployed approval-engine, T08). This plan does not absorb the earlier residual “full L3 product.” That remains residual until separately promoted. This plan is the demanded slice: review-groups of Decision Memos for (1) credential/custody items and (2) founder/owner decisions.

Invariant from Stage 1: one question per memo. A batch is a Umlaufmappe grouping of memos, not one memo with unrelated acts. Humans bind; agents draft. This repository still does not evaluate authorization (access-engine remains the only PDP).

Draft the first two batches (agent-authored, unsigned)

id: INFD-WP-0002-T01
status: done
priority: high
state_hub_task_id: "03d1b699-cb7b-5954-a4d2-cbe06af24c5a"

From the 2026-09-14 chokepoint assessment, assemble two compact batches as Decision Memo files (or the current memo schema) under docs/batches/2026-09-14/:

  1. Credentials / custody — OpenBao paths, issuer/registration leftovers, CCR-style items, and any warden route pointer that still needs a human to actually mint or seal. Each memo is one act. No secret values in the memos.
  2. Decisions / assent — founder or owner sign-offs currently holding workplans (reviews, explicit approvals, policy accepts). Each memo is one question.

Bound the set so a single sitting can finish it (small N, ordered, highlights required). Name the review group already admitted (net-kingdom-admins or the current human review group). Do not submit until T02.

Done when both batch indexes exist, each memo has one binding target, required highlights, and a trace to the blocking workplan/task id.

2026-09-14: eight unsigned memos under docs/batches/2026-09-14/ (credentials c01c04, decisions d01d04). Review group net-kingdom-admins. Not submitted.

Batch presentation contract (review-group, compact sitting)

id: INFD-WP-0002-T02
status: done
priority: high
depends_on: [INFD-WP-0002-T01]
state_hub_task_id: "8babbc7d-5c79-5130-93ad-e2569ed3208d"

Specify how a batch is presented without forking the Decision Memo schema: ordered list, per-memo bind, progress across the sitting, no “approve all” that skips highlights. Reuse review-group work already in this repo. If Stage 1 UI cannot yet render a group, the contract still holds for a recorded desktop sitting.

Done when docs/specs/ (short addendum, not a new product) states the batch rules and the anti-requirement: no bundled unrelated acts, no auto-approval, no agent disposition.

2026-09-14: docs/specs/CompactSignoffBatches.md.

Sign-off sitting once the Stage 1 surface can bind

id: INFD-WP-0002-T03
status: wait
priority: high
depends_on: [INFD-WP-0002-T02, INFD-WP-0001]
state_hub_task_id: "917e3e34-b9de-5c51-ab29-e820957a7407"

Wait until INFD-WP-0001-T08 (or an equivalent deployed bind path) can take a real human disposition. Then run one compact sitting on the two batches. Record presentation evidence (view_hash per memo). Unfinished memos stay in the batch; do not mark the workplan finished on a partial sitting.

Done when at least one credential memo and one decision memo are bound by a human through this surface, reconstructable from stored presentation, and the blocking hub tasks are updated from those dispositions rather than from chat.

2026-09-14 — T08 bind path historically proven; this sitting still cannot run. Probe docs/evidence/2026-09-14-infd-0002-t03-bind-path-probe.json. The live store already holds three accept dispositions with confirmed engine submissions for SECRETS-WP-0010-T03-{apply,verify,exec} (presentations + required acks). That is not this batch. Compact memos remain approval_id: null / pending-human-session and are not in the store. New accept is refused: origin /readyz 503 approval_path_not_connected because audit-core is not Ready, its Service has no ready endpoints, and the review pod gets connection refused talking to the audit ClusterIP. Operator packet docs/batches/2026-09-14/OPERATOR.md; preflight tools/sitting_bind_preflight.py. No agent disposition. Task stays wait.

2026-09-14 22:16 UTC — live accept reopened; sitting still not admitted. audit-core b0e6792 is Ready; origin /readyz 200; preflight live_accept=open. Remaining gates: (1) Flex Auth T03 package still allows only memo:SECRETS-WP-0010-T03-*docs/batches/2026-09-14/policy-request.md is a request, not an admission; (2) no approval:create requester for these eight acts; (3) drafts still approval_id: null / pending-human-session; (4) human bind. Attach tool tools/attach_compact_bindings.py writes bound copies from a created receipt and live subject; it does not create approvals or dispositions. Evidence: docs/evidence/2026-09-14-infd-0002-t03-accept-reopened.json. Task stays wait.

2026-09-14 22:44 UTC — sitting requester requested, not registered. docs/keycape-sitting-requester-registration.md asks key-cape for a create-only confidential client (informed-decision-sitting-requester, sub=informed-decision, scope approval:create only, no approve/consume, no redirect). Intents for the eight bindings are in docs/batches/2026-09-14/approval-create-intents.json (posted: false; c01 create-client undecided). No secret, no POST, no bind.

2026-09-15 — requester live; sittings still wait on attended create + human bind. RPF-WP-0042 finished: CCR-2026-0026/0027 applied, exchange proof verified, no sitting POST. tools/create_sitting_approvals.py requires attended reader and posts seven intents (c01 skipped). Flex Auth package still waits on those native ids. This shell is not an attended session. Task stays wait.

Feed outcomes back to State Hub without hub-authoring

id: INFD-WP-0002-T04
status: wait
priority: medium
depends_on: [INFD-WP-0002-T03]
state_hub_task_id: "26d8ff42-65bb-582e-9ecf-dbd367eaa7a8"

For each bound memo, update the owning repo file (task status, decision record, CCR note) and let fix-consistency project. Do not POST /workplans/ or mint hub-only tasks. Residual unsigned memos either stay in a later batch or are declined with a reason.

Done when the assessments credential/decision examples that were in the sitting show file-level status changes and a progress event naming the memo ids.