Draft execution-attribution and workload-step-up amendments; route remaining tasks
Some checks are pending
CI Smoke / host-smoke (push) Waiting to run
CI Smoke / container-smoke (push) Waiting to run

- playbook-capability-contract_v0.2.md (proposed): adds the
  execution-attribution receipt field list (NK-WP-0040-T01).
- iam-profile_v0.4.md (proposed): adds the workload-requested step-up
  contract (acr_values, no-factor refusal, assurance.level to flex-auth)
  (NK-WP-0042-T01).
- Route the remaining externally-owned decisions (NK-WP-0040-T02 to
  audit-core/Railiance, NK-WP-0042-T02 to user-engine, NK-WP-0039-T04 to
  flex-auth/tenant-engine) and mark those workplans blocked.

Assistant: claude-code
Assistant-Model: sonnet
Assistant-Process: 321494@bnt-lap001
Assistant-Session: 2c8a5cd1-573e-4bae-ab2b-29bc6c8ed4e9
This commit is contained in:
tegwick 2026-09-27 23:59:51 +02:00
parent 8ad58baa3f
commit b808da601d
5 changed files with 534 additions and 8 deletions

View file

@ -4,7 +4,7 @@ type: workplan
title: "Define an execution-attribution receipt for Railiance runs"
domain: infotech
repo: net-kingdom
status: ready
status: blocked
flavor: planning
owner: claude-code
topic_slug: netkingdom
@ -25,7 +25,7 @@ execution** to its actor chain, artifact and result.
```task
id: NK-WP-0040-T01
status: todo
status: done
priority: medium
state_hub_task_id: "9d02685a-a3d9-5b9f-b09e-aef1f196a97f"
```
@ -46,11 +46,20 @@ fields:
The receipt must never embed bearer credentials. Unknown attribution is kept
explicit, not inferred. Start from the field list in railiance-clock's review.
**Done 2026-09-27.** Drafted as
`canon/standards/playbook-capability-contract_v0.2.md` (status `proposed`,
supersedes v0.1, which stays `accepted` and normative until this is
accepted). It adds an "Execution Attribution Receipt (proposed)" section
with every field above, explicit non-goals (no fourth IAM principal type,
not a decision record, not a substitute for responsibility claims), and the
never-embed-credentials / no-inferred-attribution rules. Emission, custody,
schema, and validator are explicitly left to T02.
## Agree the evidence holder and schema with audit-core and Railiance
```task
id: NK-WP-0040-T02
status: todo
status: wait
priority: medium
state_hub_task_id: "963120c1-7c72-5806-942b-6f49e4c66e54"
```
@ -59,3 +68,10 @@ audit-core holds evidence (layer model §3.3, Evidence role). Railiance
executes and emits. Agree who emits, who holds and how the receipt is
validated. Add a schema under `canon/schemas/` and a validator beside the
existing playbook-capability tooling.
**Waiting 2026-09-27.** Routed to audit-core (evidence-holder/schema
agreement) and Railiance (emitter confirmation) via State Hub messages
`48eb1101-a577-40c0-bbaa-39df02198155` and
`4f1c67bc-8de2-483f-bcac-dbdf107ce95a`. NetKingdom adds the schema and
validator once both reply; nothing here can be finished unilaterally
without pre-empting their agreement.