diff --git a/workplans/KEY-WP-0014-native-credential-lane-handoff.md b/workplans/KEY-WP-0014-native-credential-lane-handoff.md index 0f1306e..1482784 100644 --- a/workplans/KEY-WP-0014-native-credential-lane-handoff.md +++ b/workplans/KEY-WP-0014-native-credential-lane-handoff.md @@ -309,3 +309,23 @@ If the rotation is scheduled, it is also the first opportunity to close the `real_predecessor_rotation_tested: false` gap recorded above — `verify-client` with `-previous-secret-env` is exactly step 4, and the predecessor would finally be genuinely distinct. + +**Decision, 2026-09-10: not yet.** The repository owner declined to schedule the +rotation now. Recorded with the reasoning so it is revisited on evidence rather +than re-litigated from scratch: nothing indicates compromise, the offer stands +open, and the estate already has one founder-attended window pending for the two +fail-closed startup changes. Rotating for hygiene alone, in a second attended +session, against a credential with no incident attached, is work the owner chose +not to spend now. + +This is a deferral, not a refusal, and the thing that should reopen it is a +change in evidence rather than the passage of time: an actual exposure or +suspected one (see KEY-WP-0011), the Qonto secret's age becoming a stated concern, +a consumer requiring proof of rotation, or a decision to prove rotation step 4 +before relying on it elsewhere. Any of those makes the answer different; a +calendar date does not. + +T04 therefore stays `wait` with nothing outstanding from any counterparty. The +authority is answered, the transport named, the CCR offered on request, and +`verify-client` is ready for step 4 whenever a window is chosen. Nobody is waiting +on KeyCape, and KeyCape is waiting on a decision that has now been taken.