informed-decision/history/20260909-initial-exploration/vectors/login-binding.json
tegwick ee2cca579c Establish INTENT, Stage 1 GOAL, and founding workplan
Claim ownership of the browser-facing approver UI that approval-engine
deliberately does not contain. approval-engine's INTENT names an approvals
inbox under Non-Goals, and docs/keycape-service-registrations.md records that
the human approver client's client_id and callback URI "must come from its
owner once it exists" — leaving key-cape's KEY-WP-0013-T02 blocked on an
unassigned component.

- INTENT.md: Decision Memo concept, the binding/awareness split and the two
  hashes, ownership and non-ownership against the named estate repositories,
  and a provisional PEP-shaped layer placement flagged for a gate-house ruling
  rather than asserted.
- GOAL.md: Stage 1 is the L3 approval approver surface — the narrowest real
  consumer with a live blocking dependency — plus the written answer to who
  owns the approver UI.
- workplans/INFD-WP-0001: founding documents, the gate-house layer/ownership
  ruling, the four specs (PRD, UseCaseCatalog, ArchitectureBlueprint,
  EvidenceModel), schema and canonicalizer promotion out of history/ with the
  isolation vectors under test, the key-cape client registration, and a
  walking skeleton that includes return and discuss.

history/ is preserved unmodified as provenance.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01V3W1dQG7GFFM9d94jFx7iR

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1565372@bnt-lap001
Assistant-Session: 16bb2f25-b34c-49ef-8e94-5fec3567a568
2026-09-09 10:47:36 +02:00

73 lines
2 KiB
JSON

{
"memo_id": "01K4LOGIN00000000000000001",
"memo_version": 1,
"question": "Log into Payroll-Prod as Bernd Worsch in tenant ACME?",
"requested_act": "login",
"binding_level": "organizational",
"brief": "You are entering Payroll-Prod. Sessions are recorded. Privileges at the gate are identity-scoped, not hat-scoped.",
"locale": "en",
"ui_release": "informed-decision@0.4.0",
"packet": [],
"highlights": [],
"binding": {
"principal": {
"id": "01K4PERSONBERND00000000001",
"kind": "person",
"display_name": "Bernd Worsch",
"role": "employee",
"identifiers": [
{ "scheme": "email", "value": "bernd.worsch@example.com" },
{ "scheme": "idp:oidc-sub", "value": "auth.example.com|bernd" }
]
},
"available_identities": [
{
"id": "01K4PERSONBERND00000000001",
"kind": "person",
"display_name": "Bernd Worsch",
"identifiers": [
{ "scheme": "idp:oidc-sub", "value": "auth.example.com|bernd" }
]
},
{
"id": "01K4PERSONBERNDADMIN000001",
"kind": "person",
"display_name": "Bernd Worsch (break-glass)",
"identifiers": [
{ "scheme": "idp:oidc-sub", "value": "auth.example.com|bernd-bg" }
]
}
],
"target": {
"kind": "tenant",
"id": "tenant:acme",
"label": "ACME Corp",
"environment": "prod",
"requires_new_bind": true
},
"available_bind_scopes": [
{
"kind": "tenant",
"id": "tenant:acme",
"label": "ACME Corp",
"environment": "prod",
"requires_new_bind": true
},
{
"kind": "tenant",
"id": "tenant:beta",
"label": "Beta GmbH",
"environment": "prod",
"requires_new_bind": true
}
],
"granted_at_bind": {
"roles": ["authenticated"],
"permissions": ["session.create"]
},
"terms": {
"monitoring": true,
"consent_code": "LOGIN-PROD-2026"
}
}
}