FLEX-WP-0028 admitted a dedicated package. Runtime ConfigMap and NetworkPolicy now pin flex-auth-informed-decision-sitting. Memos are in the live store for the existing named recipient. No human bind. Assistant: grok Assistant-Session: 01a09dc1-b21e-77e1-919e-fcad2f82b267
8.3 KiB
| id | type | title | domain | repo | status | owner | topic_slug | flavor | depends_on | created | updated | related | origin | origin_ref | state_hub_workstream_id | ||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| INFD-WP-0002 | workplan | Compact sign-off batches for credentials and decisions | infotech | informed-decision | active | grok | netkingdom | planning |
|
2026-09-14 | 2026-09-15 |
|
demand | the-custodian/history/20260914-open-workplan-chokepoints.md | a2939a36-eeab-522b-b35a-5399af2757bf |
Compact sign-off batches for credentials and decisions
Founder direction 2026-09-14: credential and decision chokepoints should
move through the informed-decision framework as batches that can be
signed off in a compact timeframe, not as twelve disconnected
needs_human tasks.
INFD-WP-0001 still owns Stage 1 (walking skeleton against a deployed
approval-engine, T08). This plan does not absorb the earlier
residual “full L3 product.” That remains residual until separately
promoted. This plan is the demanded slice: review-groups of Decision
Memos for (1) credential/custody items and (2) founder/owner
decisions.
Invariant from Stage 1: one question per memo. A batch is a
Umlaufmappe grouping of memos, not one memo with unrelated acts.
Humans bind; agents draft. This repository still does not evaluate
authorization (access-engine remains the only PDP).
Draft the first two batches (agent-authored, unsigned)
id: INFD-WP-0002-T01
status: done
priority: high
state_hub_task_id: "03d1b699-cb7b-5954-a4d2-cbe06af24c5a"
From the 2026-09-14 chokepoint assessment, assemble two compact batches
as Decision Memo files (or the current memo schema) under
docs/batches/2026-09-14/:
- Credentials / custody — OpenBao paths, issuer/registration
leftovers, CCR-style items, and any
warden routepointer that still needs a human to actually mint or seal. Each memo is one act. No secret values in the memos. - Decisions / assent — founder or owner sign-offs currently holding workplans (reviews, explicit approvals, policy accepts). Each memo is one question.
Bound the set so a single sitting can finish it (small N, ordered,
highlights required). Name the review group already admitted
(net-kingdom-admins or the current human review group). Do not submit
until T02.
Done when both batch indexes exist, each memo has one binding target, required highlights, and a trace to the blocking workplan/task id.
2026-09-14: eight unsigned memos under docs/batches/2026-09-14/
(credentials c01–c04, decisions d01–d04). Review group
net-kingdom-admins. Not submitted.
Batch presentation contract (review-group, compact sitting)
id: INFD-WP-0002-T02
status: done
priority: high
depends_on: [INFD-WP-0002-T01]
state_hub_task_id: "8babbc7d-5c79-5130-93ad-e2569ed3208d"
Specify how a batch is presented without forking the Decision Memo schema: ordered list, per-memo bind, progress across the sitting, no “approve all” that skips highlights. Reuse review-group work already in this repo. If Stage 1 UI cannot yet render a group, the contract still holds for a recorded desktop sitting.
Done when docs/specs/ (short addendum, not a new product) states the
batch rules and the anti-requirement: no bundled unrelated acts, no
auto-approval, no agent disposition.
2026-09-14: docs/specs/CompactSignoffBatches.md.
Sign-off sitting once the Stage 1 surface can bind
id: INFD-WP-0002-T03
status: wait
priority: high
depends_on: [INFD-WP-0002-T02, INFD-WP-0001]
state_hub_task_id: "917e3e34-b9de-5c51-ab29-e820957a7407"
Wait until INFD-WP-0001-T08 (or an equivalent deployed bind path)
can take a real human disposition. Then run one compact sitting on the
two batches. Record presentation evidence (view_hash per memo).
Unfinished memos stay in the batch; do not mark the workplan finished
on a partial sitting.
Done when at least one credential memo and one decision memo are bound by a human through this surface, reconstructable from stored presentation, and the blocking hub tasks are updated from those dispositions rather than from chat.
2026-09-14 — T08 bind path historically proven; this sitting still
cannot run. Probe
docs/evidence/2026-09-14-infd-0002-t03-bind-path-probe.json.
The live store already holds three accept dispositions with confirmed
engine submissions for SECRETS-WP-0010-T03-{apply,verify,exec}
(presentations + required acks). That is not this batch. Compact memos
remain approval_id: null / pending-human-session and are not in the
store. New accept is refused: origin /readyz 503
approval_path_not_connected because audit-core is not Ready, its
Service has no ready endpoints, and the review pod gets connection
refused talking to the audit ClusterIP. Operator packet
docs/batches/2026-09-14/OPERATOR.md; preflight
tools/sitting_bind_preflight.py. No agent disposition. Task stays
wait.
2026-09-14 22:16 UTC — live accept reopened; sitting still not
admitted. audit-core b0e6792 is Ready; origin /readyz 200;
preflight live_accept=open. Remaining gates: (1) Flex Auth T03
package still allows only memo:SECRETS-WP-0010-T03-* —
docs/batches/2026-09-14/policy-request.md is a request, not an
admission; (2) no approval:create requester for these eight acts;
(3) drafts still approval_id: null / pending-human-session;
(4) human bind. Attach tool tools/attach_compact_bindings.py writes
bound copies from a created receipt and live subject; it does not
create approvals or dispositions. Evidence:
docs/evidence/2026-09-14-infd-0002-t03-accept-reopened.json.
Task stays wait.
2026-09-14 22:44 UTC — sitting requester requested, not registered.
docs/keycape-sitting-requester-registration.md asks key-cape for a
create-only confidential client (informed-decision-sitting-requester,
sub=informed-decision, scope approval:create only, no approve/consume,
no redirect). Intents for the eight bindings are in
docs/batches/2026-09-14/approval-create-intents.json (posted: false;
c01 create-client undecided). No secret, no POST, no bind.
2026-09-15 — requester live; sittings still wait on attended create +
human bind. RPF-WP-0042 finished: CCR-2026-0026/0027 applied, exchange
proof verified, no sitting POST. tools/create_sitting_approvals.py
requires attended reader and posts seven intents (c01 skipped). Flex
Auth package still waits on those native ids. This shell is not an
attended session. Task stays wait.
2026-09-15 20:22 UTC — front door exists in source catalog, not in the
installed warden bundle. Playbook now names
tools/create_sitting_approvals.py as the sitting-POST child (proof-only
child stays prove-sitting-requester-exchange.sh). Operator must export
WARDEN_ROUTING_CATALOG and BAO_ADDR=http://127.0.0.1:18200. No POST
from this shell. Task stays wait.
2026-09-15 20:35 UTC — seven unapproved objects exist. Attended create
wrote docs/evidence/2026-09-15-sitting-approval-creates.json
(created / seven_unapproved_requests_created, no entries). Warden
then failed closed on child stdout; wrapper is now silent. c01 skipped.
Flex Auth draft docs/batches/2026-09-14/policy-package.md is not
admitted. Attach still needs the operator KeyCape sub. No human bind.
Task stays wait.
2026-09-15 21:31 UTC — sitting PDP live on the origin; seven memos
loaded. FLEX-WP-0028 admitted
flex-auth-informed-decision-sitting /
informed-decision.compact-sitting
(sha256:e0afd52e046616a93142f4064704b1cee6496801d94612fce29a958cf04eb41a).
Review ConfigMap informed-decision-runtime-bab38e8704a2; egress peer
cut over from T03. Named recipient reused from existing presentations
(not written to git). Store has seven infd-20260914-* memos plus the
three T03 records. Human bind remaining. Task stays wait.
Feed outcomes back to State Hub without hub-authoring
id: INFD-WP-0002-T04
status: wait
priority: medium
depends_on: [INFD-WP-0002-T03]
state_hub_task_id: "26d8ff42-65bb-582e-9ecf-dbd367eaa7a8"
For each bound memo, update the owning repo file (task status,
decision record, CCR note) and let fix-consistency project. Do not
POST /workplans/ or mint hub-only tasks. Residual unsigned memos
either stay in a later batch or are declined with a reason.
Done when the assessment’s credential/decision examples that were in the sitting show file-level status changes and a progress event naming the memo ids.