2026-09-05 01:27:16 +02:00
|
|
|
---
|
|
|
|
|
id: KEY-WP-0015
|
|
|
|
|
type: workplan
|
|
|
|
|
title: "Reconcile repository scope with implementation and intent"
|
|
|
|
|
domain: infotech
|
|
|
|
|
repo: key-cape
|
|
|
|
|
status: finished
|
|
|
|
|
owner: codex
|
|
|
|
|
topic_slug: scope-intent-assessment
|
|
|
|
|
created: "2026-09-05"
|
|
|
|
|
updated: "2026-09-05"
|
Align approval registrations to the tenant:platform decision
Operator decision 5ed3fb35-eca9-413a-82b9-95171ba85bf6 accepts tenant:platform
as the platform management tenant for the Glas approval chain, requiring exact
spelling across the approval store, the service-client JWT claim and the
lifecycle CheckRequest.
Changes the tenant field on secrets-engine-approval and approval-engine-operator
only, in the registration fixture and the provisioning packet. Unrelated clients
and the human directory default keep tenant:coulomb, and no audience, scope,
subject, role, lifetime or MFA grant changes.
Adds issuance evidence that the approval shape emits tenant:platform exactly and
never an alias the caller requests, that the OpenBao client gains no
cross-tenant reach, and a fixture guard pinning every reviewed client's tenant.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NV9oijZukGyGbRQGGKnK4P
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 713576@bnt-lap001
Assistant-Session: 384c511d-9bce-4cb8-a676-2aef6c0c8df6
2026-09-06 22:30:32 +02:00
|
|
|
state_hub_workstream_id: "14a7312b-ec92-5640-8b26-cbaa4753c18e"
|
2026-09-05 01:27:16 +02:00
|
|
|
---
|
|
|
|
|
|
|
|
|
|
## Inventory implementation and document scope gaps
|
|
|
|
|
|
|
|
|
|
```task
|
|
|
|
|
id: KEY-WP-0015-T01
|
|
|
|
|
status: done
|
|
|
|
|
priority: medium
|
Align approval registrations to the tenant:platform decision
Operator decision 5ed3fb35-eca9-413a-82b9-95171ba85bf6 accepts tenant:platform
as the platform management tenant for the Glas approval chain, requiring exact
spelling across the approval store, the service-client JWT claim and the
lifecycle CheckRequest.
Changes the tenant field on secrets-engine-approval and approval-engine-operator
only, in the registration fixture and the provisioning packet. Unrelated clients
and the human directory default keep tenant:coulomb, and no audience, scope,
subject, role, lifetime or MFA grant changes.
Adds issuance evidence that the approval shape emits tenant:platform exactly and
never an alias the caller requests, that the OpenBao client gains no
cross-tenant reach, and a fixture guard pinning every reviewed client's tenant.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NV9oijZukGyGbRQGGKnK4P
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 713576@bnt-lap001
Assistant-Session: 384c511d-9bce-4cb8-a676-2aef6c0c8df6
2026-09-06 22:30:32 +02:00
|
|
|
state_hub_task_id: "99be1489-d9e5-53b1-9c82-75dc961131f7"
|
2026-09-05 01:27:16 +02:00
|
|
|
```
|
|
|
|
|
|
|
|
|
|
Reviewed source revision b989de4, INTENT, SCOPE, runtime composition, authentication
|
|
|
|
|
commands, adapters, migration/validator code, tests, packaging and open workplans.
|
|
|
|
|
Updated SCOPE.md to describe implemented surfaces and their actual limits.
|
|
|
|
|
Recorded evidence, ten prioritized gaps and closure criteria in
|
|
|
|
|
history/2026-09-05-011726-scope-intent-assessment.md. INTENT and implementation are
|
|
|
|
|
unchanged. Findings are assessment results, not implementation completion claims.
|