key-cape/workplans
tegwick 5f516a0fbb
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 44s
Make the static-registration precondition a checked condition
informed-decision asked for the caveat under which a registration-bound human
tenant is safe to be a condition of the capability rather than reasoning in a
message, so a future change to registration policy has to confront it. They were
right that it was only prose: the contract stated it, a separate test asserted
registration_endpoint is absent, and nothing connected the two -- so a session
adding dynamic registration would have seen a test about discovery metadata, not
a warning about relabelling users.

The test asserts both halves together: that a client-declared tenant is issued,
and that dynamic registration is not advertised. Whichever is removed first, the
failure points at the other. The message carries the reasoning rather than the
observation -- anyone able to register a client could relabel the users who log in
through it -- and names the two ways out.

Verified in both directions rather than assumed: advertising a
registration_endpoint fails it with the escalation message, and neutering
humanTenant fails it with the message saying to remove the guard along with the
capability it protects.

This is not a vote on the tenant question. It makes one option's precondition
checkable; if option 1 lands, the capability and this guard are removed together.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NV9oijZukGyGbRQGGKnK4P

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 713576@bnt-lap001
Assistant-Session: 384c511d-9bce-4cb8-a676-2aef6c0c8df6
2026-09-09 23:23:48 +02:00
..
ADHOC-2026-09-05.md Add bounded resource audiences and enforce browser scope grants 2026-09-05 00:41:17 +02:00
ADHOC-2026-09-07.md chore(consistency): register KEY-WP-0017 and ADHOC-2026-09-07 [auto] 2026-09-07 00:23:58 +02:00
KEY-WP-0001-keycape-implementation.md Add bounded resource audiences and enforce browser scope grants 2026-09-05 00:41:17 +02:00
KEY-WP-0002-container-image-gitea.md Add bounded resource audiences and enforce browser scope grants 2026-09-05 00:41:17 +02:00
KEY-WP-0003-bootstrap-console-oidc-mfa-login.md Normalize agent instructions and workplan frontmatter (STATE-WP-0067) 2026-06-22 23:16:27 +02:00
KEY-WP-0004-binky-hedgehog-tenant-onboarding.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:13:23 +02:00
KEY-WP-0005-iam-profile-core-claims.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:13:23 +02:00
KEY-WP-0006-client-credentials-service-tokens.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:13:23 +02:00
KEY-WP-0007-user-engine-portal-oidc-client.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:13:23 +02:00
KEY-WP-0008-registration-handoff-and-client-mfa-policy.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:13:23 +02:00
KEY-WP-0009-provider-capabilities-and-service-identities.md Close the KEY-WP-0009 handoff gap and deliver the two blocked admissions 2026-09-08 10:22:52 +02:00
KEY-WP-0010-openbao-operator-loopback-callback.md chore(registrar): assign State Hub identifiers 2026-08-23 13:19:35 +02:00
KEY-WP-0011-live-secret-exposure-recovery.md security: rotate exposed KeyCape credentials 2026-08-23 14:26:36 +02:00
KEY-WP-0012-userinfo-canonical-subject-resolution.md repo.work.assign_missing_identifiers 2026-09-01 01:36:20 +02:00
KEY-WP-0013-approval-engine-resource-audience.md Record the custody owner's confirmations and guard a receipt against misreading 2026-09-09 20:05:40 +02:00
KEY-WP-0014-native-credential-lane-handoff.md Record the custody owner's confirmations and guard a receipt against misreading 2026-09-09 20:05:40 +02:00
KEY-WP-0015-scope-intent-assessment.md Align approval registrations to the tenant:platform decision 2026-09-06 22:30:32 +02:00
KEY-WP-0016-authorization-code-protocol-hardening.md chore(consistency): register KEY-WP-0016 and refresh work records [auto] 2026-09-06 22:44:55 +02:00
KEY-WP-0017-canonical-model-and-discovery-conformance.md chore(consistency): register KEY-WP-0017 and ADHOC-2026-09-07 [auto] 2026-09-07 00:23:58 +02:00
KEY-WP-0018-export-completeness-evidence.md chore(consistency): register KEY-WP-0018 and refresh work records [auto] 2026-09-07 08:47:00 +02:00
KEY-WP-0019-upstream-provider-token-verification.md Record what the consolidated verifier's tests actually establish 2026-09-07 09:05:16 +02:00
KEY-WP-0020-migration-contract-preservation.md chore(consistency): register KEY-WP-0020 and refresh work records [auto] 2026-09-07 13:49:40 +02:00
KEY-WP-0021-snapshot-attribute-validation.md chore(consistency): register KEY-WP-0021 [auto] 2026-09-07 23:23:38 +02:00
KEY-WP-0022-replacement-harness-and-external-conformance.md chore(consistency): register KEY-WP-0022 [auto] 2026-09-07 23:32:51 +02:00
KEY-WP-0023-live-migration-proof.md chore(consistency): register KEY-WP-0023 [auto] 2026-09-08 08:55:52 +02:00
KEY-WP-0024-tenant-roles-opt-in-wiring.md chore(consistency): register KEY-WP-0024 [auto] 2026-09-08 09:00:39 +02:00
KEY-WP-0025-runtime-lifecycle-and-readiness.md chore(consistency): register KEY-WP-0025 [auto] 2026-09-08 09:44:33 +02:00
KEY-WP-0026-packaging-bootstrap-and-credential-handling.md chore(consistency): register KEY-WP-0026 [auto] 2026-09-08 09:52:42 +02:00
KEY-WP-0027-rollout-readiness-and-live-state.md docs(identity): record verified live upstream issuer and completed cleanup 2026-09-08 23:50:54 +02:00
KEY-WP-0028-browser-client-field-validation.md Record the stale-claim correction alongside the others 2026-09-09 16:41:10 +02:00
KEY-WP-0029-scope-reassessment.md chore(consistency): register KEY-WP-0029 [auto] 2026-09-09 20:07:24 +02:00
KEY-WP-0030-tenant-precondition-guard.md Make the static-registration precondition a checked condition 2026-09-09 23:23:48 +02:00