--- id: ADHOC-2026-08-14 type: workplan title: "Close NK-WP-0025 residuals" domain: infotech repo: net-kingdom status: blocked owner: codex topic_slug: netkingdom created: "2026-08-14" updated: "2026-08-14" state_hub_workstream_id: "f65863fd-1010-4d1e-a8ec-571b9f302d2a" --- # ADHOC-2026-08-14 - NK-WP-0025 residual closeout ## Reconcile Coulomb Social Case B residual records ```task id: ADHOC-2026-08-14-T01 status: done priority: medium state_hub_task_id: "9ee6b15b-efd0-41d1-b38e-ea0061feef69" ``` Update the owning smoke evidence and close or narrow CSOC-IN-0001 and CSOC-IN-0002 now that NK-WP-0025 completed the public registration, OIDC/JIT, repeat-login, collision, redirect, and assurance evidence. ## Protect the canonical LDAP-DN subject contract ```task id: ADHOC-2026-08-14-T02 status: done priority: medium state_hub_task_id: "ec3a0cd4-7c65-49c4-b2a4-b45031d49213" ``` Add focused regression coverage for the canonical LDAP-DN OIDC subject and the reverse normalization used by directory lifecycle and password setup. ## Persist the audit-core multi-tenant sender scope ```task id: ADHOC-2026-08-14-T03 status: wait priority: high state_hub_task_id: "fcd35bde-b458-4226-964f-b2c6d6125c03" ``` Move the live `user-engine` sender registry from its manually minted Secret to the authoritative OpenBao/ExternalSecret path with source-bound write-only scope and `tenants: ["*"]`, without reading or logging its token. 2026-08-14 probe: the live Secret has the correct redacted scope, but `platform/workloads/audit-core/senders` does not exist. ClusterSecretStore `openbao-audit-core` is present and can read only that exact path. The current workstation OpenBao identity returns 403 and credential routing exposes no resolvable write grant. Completion therefore waits for a short-lived platform-admin OpenBao session to perform the documented wrapped migration; the temporary probe ExternalSecret was removed.