Claim ownership of the browser-facing approver UI that approval-engine deliberately does not contain. approval-engine's INTENT names an approvals inbox under Non-Goals, and docs/keycape-service-registrations.md records that the human approver client's client_id and callback URI "must come from its owner once it exists" — leaving key-cape's KEY-WP-0013-T02 blocked on an unassigned component. - INTENT.md: Decision Memo concept, the binding/awareness split and the two hashes, ownership and non-ownership against the named estate repositories, and a provisional PEP-shaped layer placement flagged for a gate-house ruling rather than asserted. - GOAL.md: Stage 1 is the L3 approval approver surface — the narrowest real consumer with a live blocking dependency — plus the written answer to who owns the approver UI. - workplans/INFD-WP-0001: founding documents, the gate-house layer/ownership ruling, the four specs (PRD, UseCaseCatalog, ArchitectureBlueprint, EvidenceModel), schema and canonicalizer promotion out of history/ with the isolation vectors under test, the key-cape client registration, and a walking skeleton that includes return and discuss. history/ is preserved unmodified as provenance. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01V3W1dQG7GFFM9d94jFx7iR Assistant: claude-code Assistant-Model: opus Assistant-Process: 1565372@bnt-lap001 Assistant-Session: 16bb2f25-b34c-49ef-8e94-5fec3567a568
153 lines
4.1 KiB
JSON
153 lines
4.1 KiB
JSON
{
|
|
"id": "01K4LOGIN00000000000000001",
|
|
"version": 1,
|
|
"schema_version": "0.2.0",
|
|
"status": "awaiting_actor",
|
|
"depth": 0,
|
|
"title": "Login to Payroll-Prod / ACME",
|
|
"question": "Log into Payroll-Prod as Bernd Worsch in tenant ACME?",
|
|
"requested_act": "login",
|
|
"binding_level": "organizational",
|
|
"locale": "en",
|
|
"created_at": "2026-09-09T08:01:00Z",
|
|
"updated_at": "2026-09-09T08:01:00Z",
|
|
"requester": {
|
|
"id": "01K4SYSTEM00000000000000001",
|
|
"kind": "system",
|
|
"display_name": "Payroll-Prod IdP"
|
|
},
|
|
"subject": {
|
|
"id": "01K4PERSONBERND00000000001",
|
|
"kind": "person",
|
|
"display_name": "Bernd Worsch"
|
|
},
|
|
"brief": "You are entering Payroll-Prod. Sessions are recorded. Privileges at the gate are identity-scoped, not hat-scoped.",
|
|
"identity_context": {
|
|
"system": "Payroll-Prod",
|
|
"environment": "prod",
|
|
"binding": {
|
|
"principal": {
|
|
"id": "01K4PERSONBERND00000000001",
|
|
"kind": "person",
|
|
"display_name": "Bernd Worsch",
|
|
"role": "employee",
|
|
"identifiers": [
|
|
{ "scheme": "email", "value": "bernd.worsch@example.com" },
|
|
{ "scheme": "idp:oidc-sub", "value": "auth.example.com|bernd" }
|
|
]
|
|
},
|
|
"available_identities": [
|
|
{
|
|
"id": "01K4PERSONBERND00000000001",
|
|
"kind": "person",
|
|
"display_name": "Bernd Worsch"
|
|
},
|
|
{
|
|
"id": "01K4PERSONBERNDADMIN000001",
|
|
"kind": "person",
|
|
"display_name": "Bernd Worsch (break-glass)"
|
|
}
|
|
],
|
|
"target": {
|
|
"kind": "tenant",
|
|
"id": "tenant:acme",
|
|
"label": "ACME Corp",
|
|
"environment": "prod",
|
|
"requires_new_bind": true
|
|
},
|
|
"available_bind_scopes": [
|
|
{
|
|
"kind": "tenant",
|
|
"id": "tenant:acme",
|
|
"label": "ACME Corp",
|
|
"environment": "prod",
|
|
"requires_new_bind": true
|
|
},
|
|
{
|
|
"kind": "tenant",
|
|
"id": "tenant:beta",
|
|
"label": "Beta GmbH",
|
|
"environment": "prod",
|
|
"requires_new_bind": true
|
|
}
|
|
],
|
|
"granted_at_bind": {
|
|
"roles": ["authenticated"],
|
|
"permissions": ["session.create"]
|
|
},
|
|
"terms": {
|
|
"monitoring": true,
|
|
"consent_code": "LOGIN-PROD-2026"
|
|
}
|
|
},
|
|
"awareness": {
|
|
"proposed_hat": {
|
|
"id": "hat:finance-controller",
|
|
"label": "Finance Controller",
|
|
"kind": "access_profile",
|
|
"elevates": false,
|
|
"scope_id": "tenant:acme"
|
|
},
|
|
"proposed_hat_source": "last_used",
|
|
"available_hats": [
|
|
{
|
|
"id": "hat:finance-controller",
|
|
"label": "Finance Controller",
|
|
"kind": "access_profile",
|
|
"elevates": false
|
|
},
|
|
{
|
|
"id": "hat:auditor-readonly",
|
|
"label": "Auditor (read-only)",
|
|
"kind": "perspective",
|
|
"elevates": false
|
|
},
|
|
{
|
|
"id": "hat:payroll-admin",
|
|
"label": "Payroll Admin",
|
|
"kind": "role",
|
|
"elevates": true
|
|
}
|
|
],
|
|
"available_scopes": [
|
|
{
|
|
"kind": "tenant",
|
|
"id": "tenant:beta",
|
|
"label": "Beta GmbH",
|
|
"environment": "prod",
|
|
"requires_new_bind": true
|
|
}
|
|
],
|
|
"last_session": {
|
|
"ended_at": "2026-09-08T16:12:00Z",
|
|
"hat_id": "hat:finance-controller",
|
|
"scope_id": "tenant:acme"
|
|
},
|
|
"situation_note": "Last session Tuesday 18:12 CEST as Finance Controller in ACME."
|
|
}
|
|
},
|
|
"packet": [],
|
|
"highlights": [],
|
|
"route": {
|
|
"mode": "sequential",
|
|
"steps": [
|
|
{
|
|
"id": "01K4LOGINSTEP0000000000001",
|
|
"ordinal": 1,
|
|
"kind": "acknowledge",
|
|
"assignee": {
|
|
"id": "01K4PERSONBERND00000000001",
|
|
"kind": "person",
|
|
"display_name": "Bernd Worsch"
|
|
},
|
|
"required_verbs": ["accept", "decline"],
|
|
"min_binding_level": "organizational",
|
|
"status": "active"
|
|
}
|
|
],
|
|
"current_step_ids": ["01K4LOGINSTEP0000000000001"]
|
|
},
|
|
"session": {
|
|
"status": "pending"
|
|
}
|
|
}
|