key-cape/workplans
tegwick d29032d6c4 Record the operator withdrawal and the gate-house tenant conditions
approval-engine answered the presenting-actor question we put to them and the
answer withdrew the client: nobody presents approval-engine-operator. Nothing in
their repository obtains an OAuth token, and scope by scope the bundle never
described a single actor -- approve belongs to the human client, emit is
redundant, and no requester identity was ever settled for create. Annotated as
withdrawn in the example config and the packet rather than deleted, because they
asked for it to stay authenticable under CCR-2026-0018 if a presenter appears.
The separation-of-duties observation is kept because it constrains the
re-request: approve must not travel with the operational scopes.

Raised rather than filed: "do not provision" cannot undo a provision. The client
went live in the 2026-09-09 attended rollout, so the estate now holds a
confidential credential that can create and approve approvals, that nobody
presents, and that no consumer awaits. Standing capability with no counterparty
is a worse resting state than either provisioning it for a named presenter or
disabling it. Disablement is KeyCape's to execute and not KeyCape's to decide
alone, so it goes to the owners rather than into a commit.

Also records GH-DEC-2026-013 conditions (a) and (b) in the tenant contract, both
of which strengthen what we had written about ourselves. Row four is normative,
and in the direction we would not have guessed: a future change preferring the
DIRECTORY is also void, because "the directory won" is still a winner and picking
any winner turns a refusal into a silent cross-tenant assertion. And lifting the
dynamic-registration exclusion now VOIDS the registration-bound shape that day
rather than reopening it for review -- our "must be revisited" was too weak.
The shape is recorded as a declared bounded gap, not the terminal state.

Verification note: the Go suite could not be run green for this commit because a
peer session is mid-edit on token.go and human_tenant_test.go for the §5
provenance work. Every file in this commit is YAML or Markdown; both YAML files
were parsed and the example config's scope set and tenant were asserted unchanged.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016uV8zoCKpA1WRAxsKRYbdH

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1182213@bnt-lap001
Assistant-Session: 966597b9-ae61-46a4-8b9e-1594ab3ec4ad
2026-09-09 23:30:09 +02:00
..
ADHOC-2026-09-05.md Add bounded resource audiences and enforce browser scope grants 2026-09-05 00:41:17 +02:00
ADHOC-2026-09-07.md chore(consistency): register KEY-WP-0017 and ADHOC-2026-09-07 [auto] 2026-09-07 00:23:58 +02:00
KEY-WP-0001-keycape-implementation.md Add bounded resource audiences and enforce browser scope grants 2026-09-05 00:41:17 +02:00
KEY-WP-0002-container-image-gitea.md Add bounded resource audiences and enforce browser scope grants 2026-09-05 00:41:17 +02:00
KEY-WP-0003-bootstrap-console-oidc-mfa-login.md Normalize agent instructions and workplan frontmatter (STATE-WP-0067) 2026-06-22 23:16:27 +02:00
KEY-WP-0004-binky-hedgehog-tenant-onboarding.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:13:23 +02:00
KEY-WP-0005-iam-profile-core-claims.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:13:23 +02:00
KEY-WP-0006-client-credentials-service-tokens.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:13:23 +02:00
KEY-WP-0007-user-engine-portal-oidc-client.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:13:23 +02:00
KEY-WP-0008-registration-handoff-and-client-mfa-policy.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:13:23 +02:00
KEY-WP-0009-provider-capabilities-and-service-identities.md Close the KEY-WP-0009 handoff gap and deliver the two blocked admissions 2026-09-08 10:22:52 +02:00
KEY-WP-0010-openbao-operator-loopback-callback.md chore(registrar): assign State Hub identifiers 2026-08-23 13:19:35 +02:00
KEY-WP-0011-live-secret-exposure-recovery.md security: rotate exposed KeyCape credentials 2026-08-23 14:26:36 +02:00
KEY-WP-0012-userinfo-canonical-subject-resolution.md repo.work.assign_missing_identifiers 2026-09-01 01:36:20 +02:00
KEY-WP-0013-approval-engine-resource-audience.md Record the operator withdrawal and the gate-house tenant conditions 2026-09-09 23:30:09 +02:00
KEY-WP-0014-native-credential-lane-handoff.md Record the custody owner's confirmations and guard a receipt against misreading 2026-09-09 20:05:40 +02:00
KEY-WP-0015-scope-intent-assessment.md Align approval registrations to the tenant:platform decision 2026-09-06 22:30:32 +02:00
KEY-WP-0016-authorization-code-protocol-hardening.md chore(consistency): register KEY-WP-0016 and refresh work records [auto] 2026-09-06 22:44:55 +02:00
KEY-WP-0017-canonical-model-and-discovery-conformance.md chore(consistency): register KEY-WP-0017 and ADHOC-2026-09-07 [auto] 2026-09-07 00:23:58 +02:00
KEY-WP-0018-export-completeness-evidence.md chore(consistency): register KEY-WP-0018 and refresh work records [auto] 2026-09-07 08:47:00 +02:00
KEY-WP-0019-upstream-provider-token-verification.md Record what the consolidated verifier's tests actually establish 2026-09-07 09:05:16 +02:00
KEY-WP-0020-migration-contract-preservation.md chore(consistency): register KEY-WP-0020 and refresh work records [auto] 2026-09-07 13:49:40 +02:00
KEY-WP-0021-snapshot-attribute-validation.md chore(consistency): register KEY-WP-0021 [auto] 2026-09-07 23:23:38 +02:00
KEY-WP-0022-replacement-harness-and-external-conformance.md chore(consistency): register KEY-WP-0022 [auto] 2026-09-07 23:32:51 +02:00
KEY-WP-0023-live-migration-proof.md chore(consistency): register KEY-WP-0023 [auto] 2026-09-08 08:55:52 +02:00
KEY-WP-0024-tenant-roles-opt-in-wiring.md chore(consistency): register KEY-WP-0024 [auto] 2026-09-08 09:00:39 +02:00
KEY-WP-0025-runtime-lifecycle-and-readiness.md chore(consistency): register KEY-WP-0025 [auto] 2026-09-08 09:44:33 +02:00
KEY-WP-0026-packaging-bootstrap-and-credential-handling.md chore(consistency): register KEY-WP-0026 [auto] 2026-09-08 09:52:42 +02:00
KEY-WP-0027-rollout-readiness-and-live-state.md docs(identity): record verified live upstream issuer and completed cleanup 2026-09-08 23:50:54 +02:00
KEY-WP-0028-browser-client-field-validation.md Record the stale-claim correction alongside the others 2026-09-09 16:41:10 +02:00
KEY-WP-0029-scope-reassessment.md chore(consistency): register KEY-WP-0029 [auto] 2026-09-09 20:07:24 +02:00
KEY-WP-0030-tenant-precondition-guard.md Make the static-registration precondition a checked condition 2026-09-09 23:23:48 +02:00