Register the tenant-provenance gap in 13 (GH-DEC-2026-013)
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

One row, no doctrine change. key-cape has no adapter populating the
directory user tenant, so a client registration supplies a human
principal's tenant. gate-house ruled that admissible as a declared
bounded gap rather than as the answer, on the ground that its
distinguishing case fails closed: where registration and directory
disagree, issuance is refused rather than resolved either way.

Registered here because condition 3 of that ruling requires it — a
transitional shape not held in a register becomes the permanent answer
by nobody minding it. Intended owner is left unnamed per 13's own rule
that an intended owner is a proposal to a repository rather than an
assignment onto it.

The standard stays proposed and this changes no normative text.

21 tests pass.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012viPor8WJNCbV64ipwewrm

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1754332@bnt-lap001
Assistant-Session: 9c8ac536-ff5e-46a3-8ab1-a548bde25fc0
This commit is contained in:
tegwick 2026-09-09 23:20:22 +02:00
parent 64394e99b9
commit f9e1611cc7

View file

@ -1319,6 +1319,7 @@ register distinguishes proposed from assented.
| Stance-map register had no implementation | declared-contact | ops-warden, access-engine | gate-house | resolved in §13.1 |
| Registry-snapshot digest in decision provenance | declared-contact | flex-auth | flex-auth | self-declared |
| Decision-record authenticity — a PEP cannot attribute a decision to `access-engine` (§6.4 obligation 1); unsigned envelope, plain-HTTP pins | declared-contact | flex-auth | flex-auth | self-declared (`FLEX-DEC-2026-010`, `FLEX-WP-0024`) |
| Human principal's tenant is unresolvable from the directory, so a client registration supplies it (`GH-DEC-2026-013`) | declared-contact | key-cape | directory adapter — unnamed | proposed |
| Approval storage and lifecycle | — | flex-auth | approval-engine | assigned (§9.4) |
| Approval evidence | — | gate-house | audit-core | **assented** (`AUDIT-IN-0001`) |
| Approval evidence custody stronger than the shipped bound — WORM, object lock, transparency log | unowned-capability | audit-core | — | unassigned |