# Proposed non-secret admission packet. This is not executable authorization. status: awaiting-custody-admission owner: key-cape resource_audience: approval-engine issuer: https://kc.coulomb.social registration_source: config/service-clients.example.yaml requests: - client_id: secrets-engine-approval subject: service:secrets-engine tenant: tenant:coulomb scopes: [approval:read, approval:consume] lifetime: 15m proposed_openbao_path: platform/workloads/secrets-engine/approval-client field: client_secret proposed_kubernetes_secret: sso/keycape-secrets-engine-approval-client kubernetes_key: client-secret keycape_environment: KEYCAPE_SECRETS_ENGINE_APPROVAL_CLIENT_SECRET custody_owner: railiance-platform consumer: secrets-engine - client_id: approval-engine-operator subject: service:approval-engine-operator tenant: tenant:coulomb scopes: [approval:create, approval:read, approval:approve, approval:revoke, approval:supersede, approval:observe, approval:emit] lifetime: 15m proposed_openbao_path: platform/workloads/approval-engine/operator-client field: client_secret proposed_kubernetes_secret: sso/keycape-approval-engine-operator-client kubernetes_key: client-secret keycape_environment: KEYCAPE_APPROVAL_ENGINE_OPERATOR_CLIENT_SECRET custody_owner: railiance-platform consumer: approval-engine-operator human_registration: status: awaiting-exact-callback scopes: [openid, approval:approve] mfa_required: true client_type: public verification: - Validate the new signature against deployed JWKS and all exact claim bindings. - Reject wrong secrets, operator consume, PEP lifecycle scopes, and human consume. - Check KeyCape and consumer readiness without emitting secrets or tokens. - Preserve existing registrations and signing key; record versions and image digest. blockers: - Admit exact custody paths, field delivery, consumer identities and lifecycle authority. - Resolve attended first-provision authority through the custody owner. - Supply exact human client ID and callback URI.