The header cited 5ae80d3, but 7a73352 landed 58 seconds earlier, so a reader
applying the convention would ask what changed since 5ae80d3, find that commit
and be unable to tell its substance was already accounted for. Honest about what
was read and misleading about what is covered, which is the failure the
convention exists to prevent.
7a73352 changes documentation and workplans only, no source, and its substance
reached this document as a peer report before being confirmed by reading the
commit. The baseline now names it and records that distinction rather than
smoothing it over: read and told are different, which is the same distinction the
third state draws and the one behind four corrections this week.
Also records why the unreleased fail-closed changes stay a pointer to
docs/operations.md rather than being restated here. That section is built from a
deployed digest, a config resource version and a dated re-check note -- facts
with a short shelf life. SCOPE is a durable claims document, and putting
perishable facts in a durable one is how it drifted 63 commits to begin with.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NV9oijZukGyGbRQGGKnK4P
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 713576@bnt-lap001
Assistant-Session: 384c511d-9bce-4cb8-a676-2aef6c0c8df6
Folds in two points from the custody owner and a peer session that arrived after
the reassessment landed.
Implemented and unproven is a distinct state from both missing and done, and
SCOPE had no words for it. verify-client's predecessor rejection is written and
unit-tested and has never run against a genuinely distinct predecessor, so this
repository holds a receipt that reads like rotation evidence and is not. Both
owners state that limit independently, which is why it belongs in SCOPE rather
than only in a workplan. "There is a test" and "it has been exercised against the
real thing" now read as separate claims wherever SCOPE makes one.
Also records that the two approval clients' live verification was independently
confirmed by the custody owner, and corrects a conflation this repository made:
client-side retrieval of those secrets is unadmitted and stays so, but the
attended operator path is not a client-side read and never required one. That
conflation is what left T02 recorded as waiting on a run that had already
happened.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NV9oijZukGyGbRQGGKnK4P
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 713576@bnt-lap001
Assistant-Session: 384c511d-9bce-4cb8-a676-2aef6c0c8df6
SCOPE.md declared itself reviewed against b989de4, 63 commits behind, with its
limits kept current by appending to bullets. That works until the header asserts
a review date that no longer describes what was reviewed -- the drift this file
exists to prevent, in the document whose only job is to be accurate.
Every claim was rechecked against source rather than carried forward: routes from
the mux registrations, subcommands from the dispatch, flags from the flag sets,
claim behaviour from token.go and userinfo.go. Three were false. Caller commands
omitted verify-client, the container was said to package only keycape (untrue
since KEY-WP-0026), and the issuer API row omitted /readyz. Capabilities that had
reached SCOPE only piecemeal are now in the capability table: the
authorization-code bindings, upstream token verification, readiness and drain, the
human tenant rules, authentication-time assurance, the shared verifier.
The substantive addition is a distinction SCOPE did not draw: source behaviour
and deployed behaviour are different claims with different evidence -- the test
suite and harness runs for one, committed receipts in docs/evidence/ for the
other. What is proven live is narrower and now stated exactly, including that the
issuer pin's pre-pin state did not match, so that risk was real rather than
hypothetical, and that the deployed image predates this revision so several
described behaviours are running nowhere yet.
That distinction is the fix for a repeated error: four times in two days a claim
about current state was written from a workplan paragraph or a partial view
instead of the authoritative artifact. A SCOPE that does not separate "the code
does this" from "this is running" invites the same mistake from the next reader.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NV9oijZukGyGbRQGGKnK4P
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 713576@bnt-lap001
Assistant-Session: 384c511d-9bce-4cb8-a676-2aef6c0c8df6