Userinterface for executive decisions modeled as a sign and return book.
Find a file
tegwick d38b9acea6 Tolerate workstation clock skew in the sitting-requester token check
A 3 s WSL2 clock lag made a freshly issued KeyCape token fail PyJWT's iat
check (ImmatureSignatureError), surfacing only as contained_operation_failed.
Allow 30 s leeway and record the exception class, never its message.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 272244@bnt-lap001
Assistant-Session: c8962fa7-b290-47df-865f-403ddb6c77e9
2026-09-21 19:06:42 +02:00
deploy Restore login compatibility with deployed Authelia 4.38 2026-09-16 01:51:38 +02:00
docs Draft the 2026-09-21 spend-envelope budget memo for SECRETS-WP-0009-T03 2026-09-21 18:35:49 +02:00
history/20260909-initial-exploration Establish INTENT, Stage 1 GOAL, and founding workplan 2026-09-09 10:47:36 +02:00
informed_decision Restore login compatibility with deployed Authelia 4.38 2026-09-16 01:51:38 +02:00
intakes Record hub ids written back by fix-consistency 2026-09-21 06:35:09 +02:00
schemas Promote schema and canonicalizer out of history; add EvidenceModel (T06) 2026-09-09 14:16:28 +02:00
tests Apply GH-DEC-2026-017: declare layer Staff, make layer.yaml derived, answer the section 4 question. 2026-09-21 06:33:31 +02:00
tools Tolerate workstation clock skew in the sitting-requester token check 2026-09-21 19:06:42 +02:00
workplans Cut review over to the sitting PDP and load seven memos. 2026-09-15 23:35:35 +02:00
.custodian-brief.md chore(consistency): sync task status from DB [auto] 2026-09-14 17:09:09 +02:00
.dockerignore Package protected review runtime and prepare deployment admission 2026-09-11 01:21:37 +02:00
.gitignore Package protected review runtime and prepare deployment admission 2026-09-11 01:21:37 +02:00
.repo-classification.yaml Use in-vocabulary capability tags 2026-09-09 12:40:50 +02:00
AGENTS.md Raise INFD-IN-0006: is §3's layer vocabulary closed, and what is surface? 2026-09-21 02:11:59 +02:00
Containerfile Package protected review runtime and prepare deployment admission 2026-09-11 01:21:37 +02:00
Containerfile.memo-input Require fresh KeyCape authentication for decision review sign-in 2026-09-16 01:35:02 +02:00
Containerfile.memo-input.dockerignore Require fresh KeyCape authentication for decision review sign-in 2026-09-16 01:35:02 +02:00
GOAL.md Declare the layer per GH-DEC-2026-012; close T02 2026-09-09 22:25:35 +02:00
INTENT.md Apply GH-DEC-2026-017: declare layer Staff, make layer.yaml derived, answer the section 4 question. 2026-09-21 06:33:31 +02:00
layer.yaml Apply GH-DEC-2026-017: declare layer Staff, make layer.yaml derived, answer the section 4 question. 2026-09-21 06:33:31 +02:00
Makefile Package protected review runtime and prepare deployment admission 2026-09-11 01:21:37 +02:00
pep-stance.yaml Declare the layer per GH-DEC-2026-012; close T02 2026-09-09 22:25:35 +02:00
pyproject.toml Package protected review runtime and prepare deployment admission 2026-09-11 01:21:37 +02:00
README.md Establish INTENT, Stage 1 GOAL, and founding workplan 2026-09-09 10:47:36 +02:00
requirements.lock Package protected review runtime and prepare deployment admission 2026-09-11 01:21:37 +02:00
SCOPE.md Record native sender acceptance and retained audit readback gate 2026-09-11 14:23:07 +02:00
uv.lock Deploy verified-group T03 review surface and packet preparation 2026-09-14 02:47:31 +02:00
WORK-RECORDS.md Record hub ids written back by fix-consistency 2026-09-21 06:35:09 +02:00

informed-decision

User interface for executive decisions, modelled as a sign-and-return book — the German Umlaufmappe / Zeichnungsbuch, made cryptographic.

A Decision Memo carries a question, the context needed to answer it, the requested act, and a binding between identity, what was shown, and what was bound. The promise is not "the file was signed" but "this person, in this role, was shown this view, and bound this act."

One object model from a ten-second login (L0) to a multi-party instrument (L5).

Where to start

File What it is
INTENT.md Why this repository exists and what it must never become
GOAL.md The current stage, its invariants, and its definition of done
workplans/ Current work
history/20260909-initial-exploration/ Founding exploration — schema, state transitions, canonicalization, vectors

Stage 1

Own the browser-facing approver UI that approval-engine deliberately does not contain, and answer in writing who owns it. approval-engine is a bearer-token resource server with no browser client; key-cape (KEY-WP-0013-T02) is waiting on a client_id and callback URI that no component has claimed. This repository claims them.

See GOAL.md.

Boundaries

This repository renders questions and records answers. It does not decide (access-engine), does not own the approval object (approval-engine), does not author approval doctrine (gate-house), does not authenticate anyone (key-cape), and does not archive the trail (audit-core).