diff --git a/workplans/KEY-WP-0004-binky-hedgehog-tenant-onboarding.md b/workplans/KEY-WP-0004-binky-hedgehog-tenant-onboarding.md index 38a0377..60080ce 100644 --- a/workplans/KEY-WP-0004-binky-hedgehog-tenant-onboarding.md +++ b/workplans/KEY-WP-0004-binky-hedgehog-tenant-onboarding.md @@ -117,7 +117,7 @@ grouping vocabulary. The live service-token proof carries ```task id: KEY-WP-0004-T02 -status: todo +status: wait priority: high state_hub_task_id: "b5cb4497-095c-4dd7-af31-831deddd422e" ``` @@ -126,10 +126,14 @@ Create the user in key-cape's current backend, enroll MFA per profile requirements (`assurance` claim, `net-kingdom/canon/standards/iam-profile_v0.2.md`), and assign a tenant-admin role/group scoped to `tenant:friendly:binky` only. -**Prerequisite outside this repo's control:** the `binky-hedgehog.com` mailbox -for `bernd.worsch@` must exist and be reachable for account verification and -MFA enrollment. Flag to Bernd before starting — this task cannot complete -without it. +2026-07-27 direction update: do not complete this through a one-shot operator +script. `USER-WP-0020` and `NK-WP-0023` now own a reusable self-service and +administration portal plus NetKingdom provisioning adapters. This task is +their first production acceptance case. + +The `binky-hedgehog.com` mailbox must exist and be reachable for account +verification, but mailbox availability is now an input to the reusable +registration flow rather than a manual provisioning procedure. Done when: `bernd.worsch@binky-hedgehog.com` completes OIDC/PKCE + MFA login and receives a token carrying `tenant:friendly:binky` and a tenant-admin role