key-cape/docs
tegwick 7a73352368 Record the custody owner's confirmations and guard a receipt against misreading
railiance-platform replied on all three open threads. Recording what they add
rather than what we already knew.

T02: they reached the same reading of the verifier receipt independently and add
human_client_consume_denied: true for both clients, confirm the verifier ran
twice (activation and post-rollout) at generation 38 with the signing key
unchanged, and state T02 can close against that receipt. They also correct our
framing, rightly: the packet says client-side retrieval is unadmitted, which
stays true, but the attended operator path is not a client-side read and never
required one. This task had been treating those as the same constraint.

T04: the live approval clients mean this repo now holds a committed receipt that
looks like rotation evidence and is not. Both owners independently state the same
two gaps -- no real predecessor rotation, no observed wall-clock expiry. Recorded
in T04 rather than only in T02, because verify-client's predecessor rejection is
now implemented and unproven, which is a different state from missing or done,
and T04 is where that distinction belongs.

Answered their open question on CCR-2026-0020, which has no named presenting
actor. As issuer: the registration carries both approval:create and
approval:approve, so one presenter can create an entry and approve it. That is a
separation-of-duties property of the holder, not a defect in the token -- KeyCape
issues the grants approval-engine asked for. Recorded both shapes KeyCape can
support, and that who holds it is approval-engine's decision and the doctrine
question gate-house's, not ours.

Also narrowed the operations note: the deployed config has not been written since
the activation, so the inspected state is the state that will boot.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016uV8zoCKpA1WRAxsKRYbdH

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1182213@bnt-lap001
Assistant-Session: 966597b9-ae61-46a4-8b9e-1594ab3ec4ad
2026-09-09 20:05:40 +02:00
..
adr feat: implement T01-T04 — Go module, canonical model, LDAP validator, error taxonomy 2026-03-13 01:27:54 +01:00
evidence docs: close live approval service registration gate 2026-09-09 02:18:12 +02:00
approval-clients-deployment.patch.yaml docs(keycape): prepare pinned approval-client rollout and recovery 2026-09-08 17:03:59 +02:00
approval-clients-rollout.md docs: close live approval service registration gate 2026-09-09 02:18:12 +02:00
approval-engine-auth-contract.md Let a human token carry the zone it is issued into, without relabelling anyone 2026-09-09 14:40:36 +02:00
approval-engine-provisioning-request.yaml Record the custody owner's confirmations and guard a receipt against misreading 2026-09-09 20:05:40 +02:00
authorization-code-bindings.md Document the authorization-code bindings for relying parties 2026-09-07 00:17:56 +02:00
native-authentication.md Ship the live-registration check both blocked tasks depend on 2026-09-08 14:30:43 +02:00
openbao-service-auth-contract.md Implement KeyCape provider and service identity contracts 2026-08-23 13:10:13 +02:00
operations.md Record the custody owner's confirmations and guard a receipt against misreading 2026-09-09 20:05:40 +02:00
qonto-runtime-identity-contract.md Define Qonto runtime identity contract 2026-07-26 13:34:56 +02:00
tenant-claim-contract.md Let a human token carry the zone it is issued into, without relabelling anyone 2026-09-09 14:40:36 +02:00
upstream-issuer-proof.md docs(identity): record verified live upstream issuer and completed cleanup 2026-09-08 23:50:54 +02:00