key-cape/workplans
tegwick cb25ec2a8d Correct the T02 claim-contract record: the attended run already happened
A peer session recorded that T02's claim contract is unproven and waits on an
attended keycape verify-client run. The restraint behind that was right -- it
declined to read a client secret, which the provisioning packet does not admit --
but the conclusion was not: the attended run had already happened at
2026-09-09T00:10Z and its receipt is committed in this repo.

docs/evidence/2026-09-09-keycape-verifier-admission.json records, per client:
live_jwks_signature_verified, exact_claims_verified, excess_scope_denied and
wrong_secret_denied all true, lifetime 900s, run by a pinned verifier in an
attended owner process, with credential_values_emitted and
client_side_read_admitted both false. So it was run, and run the admitted way.
T02's status: done is correct and does not revert to wait.

The peer's paragraph is kept rather than deleted, with the correction appended
after it, so the record shows what was concluded and why it was wrong. The error
was reading "not admitted for me" as "not done by anyone" without checking
docs/evidence/ -- the third instance in two days of inferring repository state
from a partial view instead of reading it.

Also records what the receipt itself declines to claim, which nobody should
overstate later: real predecessor rotation and wall-clock expiry were not
exercised. Predecessor rejection is implemented and unit-tested in verify-client
but has never run against a real rotation, which remains KEY-WP-0014-T04 and
still has no admitted execution authority.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016uV8zoCKpA1WRAxsKRYbdH

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1182213@bnt-lap001
Assistant-Session: 966597b9-ae61-46a4-8b9e-1594ab3ec4ad
2026-09-09 16:38:20 +02:00
..
ADHOC-2026-09-05.md Add bounded resource audiences and enforce browser scope grants 2026-09-05 00:41:17 +02:00
ADHOC-2026-09-07.md chore(consistency): register KEY-WP-0017 and ADHOC-2026-09-07 [auto] 2026-09-07 00:23:58 +02:00
KEY-WP-0001-keycape-implementation.md Add bounded resource audiences and enforce browser scope grants 2026-09-05 00:41:17 +02:00
KEY-WP-0002-container-image-gitea.md Add bounded resource audiences and enforce browser scope grants 2026-09-05 00:41:17 +02:00
KEY-WP-0003-bootstrap-console-oidc-mfa-login.md Normalize agent instructions and workplan frontmatter (STATE-WP-0067) 2026-06-22 23:16:27 +02:00
KEY-WP-0004-binky-hedgehog-tenant-onboarding.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:13:23 +02:00
KEY-WP-0005-iam-profile-core-claims.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:13:23 +02:00
KEY-WP-0006-client-credentials-service-tokens.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:13:23 +02:00
KEY-WP-0007-user-engine-portal-oidc-client.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:13:23 +02:00
KEY-WP-0008-registration-handoff-and-client-mfa-policy.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:13:23 +02:00
KEY-WP-0009-provider-capabilities-and-service-identities.md Close the KEY-WP-0009 handoff gap and deliver the two blocked admissions 2026-09-08 10:22:52 +02:00
KEY-WP-0010-openbao-operator-loopback-callback.md chore(registrar): assign State Hub identifiers 2026-08-23 13:19:35 +02:00
KEY-WP-0011-live-secret-exposure-recovery.md security: rotate exposed KeyCape credentials 2026-08-23 14:26:36 +02:00
KEY-WP-0012-userinfo-canonical-subject-resolution.md repo.work.assign_missing_identifiers 2026-09-01 01:36:20 +02:00
KEY-WP-0013-approval-engine-resource-audience.md Correct the T02 claim-contract record: the attended run already happened 2026-09-09 16:38:20 +02:00
KEY-WP-0014-native-credential-lane-handoff.md Answer the approver-client questions, and fix what checking them turned up 2026-09-09 14:25:38 +02:00
KEY-WP-0015-scope-intent-assessment.md Align approval registrations to the tenant:platform decision 2026-09-06 22:30:32 +02:00
KEY-WP-0016-authorization-code-protocol-hardening.md chore(consistency): register KEY-WP-0016 and refresh work records [auto] 2026-09-06 22:44:55 +02:00
KEY-WP-0017-canonical-model-and-discovery-conformance.md chore(consistency): register KEY-WP-0017 and ADHOC-2026-09-07 [auto] 2026-09-07 00:23:58 +02:00
KEY-WP-0018-export-completeness-evidence.md chore(consistency): register KEY-WP-0018 and refresh work records [auto] 2026-09-07 08:47:00 +02:00
KEY-WP-0019-upstream-provider-token-verification.md Record what the consolidated verifier's tests actually establish 2026-09-07 09:05:16 +02:00
KEY-WP-0020-migration-contract-preservation.md chore(consistency): register KEY-WP-0020 and refresh work records [auto] 2026-09-07 13:49:40 +02:00
KEY-WP-0021-snapshot-attribute-validation.md chore(consistency): register KEY-WP-0021 [auto] 2026-09-07 23:23:38 +02:00
KEY-WP-0022-replacement-harness-and-external-conformance.md chore(consistency): register KEY-WP-0022 [auto] 2026-09-07 23:32:51 +02:00
KEY-WP-0023-live-migration-proof.md chore(consistency): register KEY-WP-0023 [auto] 2026-09-08 08:55:52 +02:00
KEY-WP-0024-tenant-roles-opt-in-wiring.md chore(consistency): register KEY-WP-0024 [auto] 2026-09-08 09:00:39 +02:00
KEY-WP-0025-runtime-lifecycle-and-readiness.md chore(consistency): register KEY-WP-0025 [auto] 2026-09-08 09:44:33 +02:00
KEY-WP-0026-packaging-bootstrap-and-credential-handling.md chore(consistency): register KEY-WP-0026 [auto] 2026-09-08 09:52:42 +02:00
KEY-WP-0027-rollout-readiness-and-live-state.md docs(identity): record verified live upstream issuer and completed cleanup 2026-09-08 23:50:54 +02:00
KEY-WP-0028-browser-client-field-validation.md Record live custody admission and re-verify the new rule against it 2026-09-09 14:44:38 +02:00