# Custody — eng-coulomb-railiance01-ho-001 ## Decision The engagement record and vault are owned by the `coulomb` client and classified `client_confidential`. Their present location in `kaizen-agentic` is transitional supplier custody, not supplier ownership. The selected receiving authority is: ```text repository: railiance-infra path: docs/evidence/resource-hosteurope-railiance01/engagements/ eng-coulomb-railiance01-ho-001/ ``` `railiance-infra` is the canonical S1 owner for Railiance01 inventory, hardening, access, and host-operational evidence, and already maintains the `resource-hosteurope-railiance01` evidence interface. `reef-railiance` is not the target: it owns grouped reef identity, topology, and bindings, not detailed host-operation records. ## Current data classes | Tree | Classification | Intended custody | |------|----------------|------------------| | `ENGAGEMENT.yaml`, request, schedule, bound definition | client operational record | receiving repo | | `vault/`, reports, checklists, access plan | client confidential | receiving repo | | engagement-local `.kaizen/metrics/` | client execution evidence | receiving repo | | `commercial/` | client settlement metadata | receiving repo or financial authority | | reusable role craft under `roles/host-operator/` | supplier craft | remains in kaizen-agentic | The committed access plan contains operational routing and host identity, but no credential value. Secrets, private keys, tokens, and passwords must never be added to this tree or to a transfer package. ## Transfer gate The supplier copy remains the source of truth until all of these are true: 1. The receiving repository accepts the path and confidentiality policy. 2. The complete engagement tree is copied with history or an attributable import commit, and the receiver validates its manifest. 3. The receiver records the accepted commit and acceptance date in `vault/handoff/custody-transfer.yaml`. 4. Scheduled execution and access references are changed to the receiving path. 5. Only then may this supplier copy be reduced to a non-confidential pointer or removed in a separately reviewed, recoverable change. Until acceptance, do not add new sensitive operational evidence here unless it is necessary to maintain the active engagement. Do not claim that a handoff pack created inside this repository has itself transferred custody.