Route Binky onboarding through user portal

This commit is contained in:
tegwick 2026-07-27 22:31:43 +02:00
parent 3d108adeb8
commit 1cd137cd9d

View file

@ -117,7 +117,7 @@ grouping vocabulary. The live service-token proof carries
```task
id: KEY-WP-0004-T02
status: todo
status: wait
priority: high
state_hub_task_id: "b5cb4497-095c-4dd7-af31-831deddd422e"
```
@ -126,10 +126,14 @@ Create the user in key-cape's current backend, enroll MFA per profile
requirements (`assurance` claim, `net-kingdom/canon/standards/iam-profile_v0.2.md`),
and assign a tenant-admin role/group scoped to `tenant:friendly:binky` only.
**Prerequisite outside this repo's control:** the `binky-hedgehog.com` mailbox
for `bernd.worsch@` must exist and be reachable for account verification and
MFA enrollment. Flag to Bernd before starting — this task cannot complete
without it.
2026-07-27 direction update: do not complete this through a one-shot operator
script. `USER-WP-0020` and `NK-WP-0023` now own a reusable self-service and
administration portal plus NetKingdom provisioning adapters. This task is
their first production acceptance case.
The `binky-hedgehog.com` mailbox must exist and be reachable for account
verification, but mailbox availability is now an input to the reusable
registration flow rather than a manual provisioning procedure.
Done when: `bernd.worsch@binky-hedgehog.com` completes OIDC/PKCE + MFA login
and receives a token carrying `tenant:friendly:binky` and a tenant-admin role