key-cape/history
tegwick 66ca76cb9c Name the third state SCOPE had no vocabulary for
Folds in two points from the custody owner and a peer session that arrived after
the reassessment landed.

Implemented and unproven is a distinct state from both missing and done, and
SCOPE had no words for it. verify-client's predecessor rejection is written and
unit-tested and has never run against a genuinely distinct predecessor, so this
repository holds a receipt that reads like rotation evidence and is not. Both
owners state that limit independently, which is why it belongs in SCOPE rather
than only in a workplan. "There is a test" and "it has been exercised against the
real thing" now read as separate claims wherever SCOPE makes one.

Also records that the two approval clients' live verification was independently
confirmed by the custody owner, and corrects a conflation this repository made:
client-side retrieval of those secrets is unadmitted and stays so, but the
attended operator path is not a client-side read and never required one. That
conflation is what left T02 recorded as waiting on a run that had already
happened.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NV9oijZukGyGbRQGGKnK4P

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 713576@bnt-lap001
Assistant-Session: 384c511d-9bce-4cb8-a676-2aef6c0c8df6
2026-09-09 20:09:01 +02:00
..
2026-09-05-011726-scope-intent-assessment.md Establish the live state and find a rollout precondition for G10 2026-09-08 11:41:42 +02:00
2026-09-09-scope-reassessment.md Name the third state SCOPE had no vocabulary for 2026-09-09 20:09:01 +02:00
KEY-WP-0011-live-secret-exposure-recovery.md ops: restart identity provisioner during keycape rotation 2026-08-23 14:42:44 +02:00
KEY-WP-0011-rotated-credentials-2026-08-23-final.tar.age security: rotate exposed KeyCape credentials 2026-08-23 14:26:36 +02:00