Draft execution-attribution and workload-step-up amendments; route remaining tasks
Some checks are pending
CI Smoke / host-smoke (push) Waiting to run
CI Smoke / container-smoke (push) Waiting to run

- playbook-capability-contract_v0.2.md (proposed): adds the
  execution-attribution receipt field list (NK-WP-0040-T01).
- iam-profile_v0.4.md (proposed): adds the workload-requested step-up
  contract (acr_values, no-factor refusal, assurance.level to flex-auth)
  (NK-WP-0042-T01).
- Route the remaining externally-owned decisions (NK-WP-0040-T02 to
  audit-core/Railiance, NK-WP-0042-T02 to user-engine, NK-WP-0039-T04 to
  flex-auth/tenant-engine) and mark those workplans blocked.

Assistant: claude-code
Assistant-Model: sonnet
Assistant-Process: 321494@bnt-lap001
Assistant-Session: 2c8a5cd1-573e-4bae-ab2b-29bc6c8ed4e9
This commit is contained in:
tegwick 2026-09-27 23:59:51 +02:00
parent 8ad58baa3f
commit b808da601d
5 changed files with 534 additions and 8 deletions

View file

@ -4,7 +4,7 @@ type: workplan
title: "Let workloads require MFA for all or part of their features"
domain: infotech
repo: net-kingdom
status: backlog
status: blocked
flavor: planning
owner: claude-code
topic_slug: netkingdom
@ -24,7 +24,7 @@ applies first.
```task
id: NK-WP-0042-T01
status: todo
status: done
priority: medium
state_hub_task_id: "d66a6347-b714-5cca-aeb5-7121328f4dec"
```
@ -40,11 +40,23 @@ Specify:
Record it as an IAM Profile amendment. key-cape owns the implementation.
**Done 2026-09-27.** Drafted as `canon/standards/iam-profile_v0.4.md`
(status `proposed`, supersedes v0.3, which stays `accepted` and normative
until this is accepted). The new "Workload-Requested Step-Up (proposed)"
section specifies `acr_values` carrying an `assurance.level` value
(`aal2`/`aal3`) as the step-up request, `max_age` as an optional additive
freshness request that must never stand in for strength alone, the two
conforming no-factor refusal shapes (inline enrollment detour or an
explicit `error=mfa_required`-class refusal, never silent AAL1), and that
flex-auth keeps reading the issued `assurance.level` with no new claim.
The exact enrollment/recovery UX is left to T02, which this section names
explicitly.
## Agree the user-facing step-up and enrollment journey
```task
id: NK-WP-0042-T02
status: todo
status: wait
priority: medium
state_hub_task_id: "4e51585d-2b57-56d4-84c1-314041d26bcf"
```
@ -54,3 +66,9 @@ user sees when a feature needs MFA and they have none. That includes the
enrollment detour, the return to the feature, and recovery. It must be
accepted from a user's perspective before any workload turns the requirement
on.
**Waiting 2026-09-27.** Routed to user-engine via State Hub message
`892fd489-113d-4108-8048-727f4b0ed048`, referencing the T01 contract and
asking for a proposed pilot workload and U06 touchpoints. This is a
UX/product agreement across two repos and a pilot workload owner; NetKingdom
cannot decide it unilaterally.