diff --git a/SCOPE.md b/SCOPE.md index da5ac8b..4498d84 100644 --- a/SCOPE.md +++ b/SCOPE.md @@ -1,9 +1,16 @@ # SCOPE -Reviewed 2026-09-09 against source revision `5ae80d3`. The preceding review was +Reviewed 2026-09-09 against source revision `7a73352`. The preceding review was 2026-09-05 against `b989de4`; the [reassessment](history/2026-09-09-scope-reassessment.md) records what changed and how each claim below was checked. +The capability review was performed against `5ae80d3`. `7a73352` landed a minute +before it and changes documentation and workplans only, no source; its substance +reached this document as a peer report and was afterwards confirmed by reading +the commit, which is why the baseline names it. That distinction — read versus +told — is worth keeping in a header whose whole purpose is to let a reader ask +"what changed since?" and get a usable answer. + ## Purpose and boundary KeyCape is Go identity **Tooling** for NetKingdom's lightweight IAM deployment. diff --git a/history/2026-09-09-scope-reassessment.md b/history/2026-09-09-scope-reassessment.md index c833340..394eed1 100644 --- a/history/2026-09-09-scope-reassessment.md +++ b/history/2026-09-09-scope-reassessment.md @@ -1,6 +1,15 @@ # KeyCape scope reassessment — 2026-09-09 -Source baseline: **5ae80d3**. Supersedes the +Source baseline: **7a73352**. The capability review was performed against +`5ae80d3`; `7a73352` landed 58 seconds earlier, touches documentation and +workplans only, and its substance arrived here as a peer report before being +confirmed by reading the commit. The baseline names it so a reader asking "what +changed since?" gets an answer that is not immediately misleading, and the +distinction between read and told is recorded rather than smoothed over — it is +the same distinction the third state below draws, and the one that cost four +corrections this week. + +Supersedes the [2026-09-05 assessment](2026-09-05-011726-scope-intent-assessment.md) against `b989de4`, which remains the record of the ten-gap backlog and its closures. @@ -80,6 +89,14 @@ predecessor, so the repository holds a receipt that reads like rotation evidence and is not. Both owners state that limit independently, which is why it belongs in SCOPE rather than only in a workplan. +One perishable-fact boundary, decided rather than defaulted: the unreleased +fail-closed startup changes are described in `docs/operations.md` and only +pointed at from SCOPE. That section is built from a deployed image digest, a +config resource version and a dated "re-check if it changed" — facts with a short +shelf life. SCOPE is a durable claims document, and putting perishable facts in a +durable one is how it drifted 63 commits in the first place. The pointer stays a +pointer. + One framing correction worth propagating, from the custody owner: client-side retrieval of those secrets is unadmitted and remains so, but the attended operator path is not a client-side read and never required one. Conflating the