key-cape/docs
tegwick a4e2751ab5 Make the registration-bound tenant caveat a condition, not a paragraph
informed-decision replied on KEY-WP-0013-T05 asking for one thing that is ours:
the caveat under which a registration-bound human tenant is safe should be a
condition of the capability, so a future change to registration policy has to
confront it, rather than reasoning left in a message. They will hold the approver
registration, so they are the party that inherits the risk.

The contract now states it as a condition rather than a caveat, in a form that
says removing the paragraph is not the decision, and points at the test that
enforces it.

I also wrote a guard test for this and then deleted it: tests/profile has
asserted registration_endpoint's absence all along, and a peer session was
concurrently writing a better guard that asserts both halves together -- the
capability still issuing, and the endpoint still absent -- so whichever is
removed first the failure points at the other. That connection is the whole
value, and a third assertion of the same fact would have been the duplication
this repository keeps correcting. The contract cites theirs.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016uV8zoCKpA1WRAxsKRYbdH

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1182213@bnt-lap001
Assistant-Session: 966597b9-ae61-46a4-8b9e-1594ab3ec4ad
2026-09-09 23:23:41 +02:00
..
adr feat: implement T01-T04 — Go module, canonical model, LDAP validator, error taxonomy 2026-03-13 01:27:54 +01:00
evidence docs: close live approval service registration gate 2026-09-09 02:18:12 +02:00
approval-clients-deployment.patch.yaml docs(keycape): prepare pinned approval-client rollout and recovery 2026-09-08 17:03:59 +02:00
approval-clients-rollout.md docs: close live approval service registration gate 2026-09-09 02:18:12 +02:00
approval-engine-auth-contract.md Let a human token carry the zone it is issued into, without relabelling anyone 2026-09-09 14:40:36 +02:00
approval-engine-provisioning-request.yaml Record the custody owner's confirmations and guard a receipt against misreading 2026-09-09 20:05:40 +02:00
authorization-code-bindings.md Document the authorization-code bindings for relying parties 2026-09-07 00:17:56 +02:00
native-authentication.md Ship the live-registration check both blocked tasks depend on 2026-09-08 14:30:43 +02:00
openbao-service-auth-contract.md Implement KeyCape provider and service identity contracts 2026-08-23 13:10:13 +02:00
operations.md Record the custody owner's confirmations and guard a receipt against misreading 2026-09-09 20:05:40 +02:00
qonto-runtime-identity-contract.md Define Qonto runtime identity contract 2026-07-26 13:34:56 +02:00
tenant-claim-contract.md Make the registration-bound tenant caveat a condition, not a paragraph 2026-09-09 23:23:41 +02:00
upstream-issuer-proof.md docs(identity): record verified live upstream issuer and completed cleanup 2026-09-08 23:50:54 +02:00