Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e77d-47a4-7771-8e34-7339c7fac0e4
94 lines
3.8 KiB
Markdown
94 lines
3.8 KiB
Markdown
---
|
|
id: NK-WP-0040
|
|
type: workplan
|
|
title: "Define an execution-attribution receipt for Railiance runs"
|
|
domain: infotech
|
|
repo: net-kingdom
|
|
status: blocked
|
|
flavor: planning
|
|
owner: claude-code
|
|
topic_slug: netkingdom
|
|
created: "2026-09-23"
|
|
updated: "2026-09-28"
|
|
related: [RCLK-WP-0002]
|
|
state_hub_workstream_id: "e2533f3a-aa43-59b3-bff3-8e64b6149487"
|
|
---
|
|
|
|
Raised by the railiance-clock identity review
|
|
(`history/2026-09-23-railiance-clock-identity-and-layer-review.md`, Ruling 1).
|
|
IAM Profile v0.3 defines who acts: human, service and agent principals, and
|
|
delegation. Playbook Capability Contract v0.1 defines what is selected and who
|
|
is responsible. No NetKingdom contract defines the record that ties **one
|
|
execution** to its actor chain, artifact and result.
|
|
|
|
## Draft the receipt fields as a Playbook Capability Contract amendment
|
|
|
|
```task
|
|
id: NK-WP-0040-T01
|
|
status: done
|
|
priority: medium
|
|
state_hub_task_id: "9d02685a-a3d9-5b9f-b09e-aef1f196a97f"
|
|
```
|
|
|
|
Draft a v0.2 amendment that adds an execution-attribution receipt with these
|
|
fields:
|
|
|
|
- issuer and subject of the initiating actor
|
|
- delegation reference (`actor_sub`/`act.sub`) when present
|
|
- executing workload binding and runtime principal
|
|
- tenant and environment
|
|
- run ID
|
|
- source commit and artifact digest
|
|
- target inventory reference and action
|
|
- decision and approval IDs
|
|
- attributed time interval, with its clock source and bound when one exists
|
|
|
|
The receipt must never embed bearer credentials. Unknown attribution is kept
|
|
explicit, not inferred. Start from the field list in railiance-clock's review.
|
|
|
|
**Done 2026-09-27.** Drafted as
|
|
`canon/standards/playbook-capability-contract_v0.2.md` (status `proposed`,
|
|
supersedes v0.1, which stays `accepted` and normative until this is
|
|
accepted). It adds an "Execution Attribution Receipt (proposed)" section
|
|
with every field above, explicit non-goals (no fourth IAM principal type,
|
|
not a decision record, not a substitute for responsibility claims), and the
|
|
never-embed-credentials / no-inferred-attribution rules. Emission, custody,
|
|
schema, and validator are explicitly left to T02.
|
|
|
|
## Agree the evidence holder and schema with audit-core and Railiance
|
|
|
|
```task
|
|
id: NK-WP-0040-T02
|
|
status: wait
|
|
priority: medium
|
|
state_hub_task_id: "963120c1-7c72-5806-942b-6f49e4c66e54"
|
|
```
|
|
|
|
audit-core holds evidence (layer model §3.3, Evidence role). Railiance
|
|
executes and emits. Agree who emits, who holds and how the receipt is
|
|
validated. Add a schema under `canon/schemas/` and a validator beside the
|
|
existing playbook-capability tooling.
|
|
|
|
**Waiting 2026-09-27.** Routed to audit-core (evidence-holder/schema
|
|
agreement) and Railiance (emitter confirmation) via State Hub messages
|
|
`48eb1101-a577-40c0-bbaa-39df02198155` and
|
|
`4f1c67bc-8de2-483f-bcac-dbdf107ce95a`. NetKingdom adds the schema and
|
|
validator once both reply; nothing here can be finished unilaterally
|
|
without pre-empting their agreement.
|
|
|
|
## Infrastructure review — 2026-09-28
|
|
|
|
Use accepted IAM Profile v0.3 and Playbook Capability Contract v0.1 as the
|
|
current baseline. Proposed IAM v0.4 and Playbook v0.2 are not deployed
|
|
capabilities. RCLK-WP-0002 still explicitly names this receipt as its dependency
|
|
on September 28. T02 remains `wait` for emitter and evidence-holder agreement.
|
|
|
|
Require the agreed schema to preserve unknown actor/delegation and clock
|
|
bounds explicitly, correlate decision/approval/run/artifact identities, and
|
|
distinguish durable receipt ingestion from attribution proof. Reuse audit-core
|
|
sender custody and reconciliation contracts rather than create another audit
|
|
sink. Acceptance needs an actual Railiance-emitted receipt and audit-core
|
|
readback, plus invalid/missing attribution cases; schema validation alone
|
|
cannot establish end-to-end attribution.
|
|
|
|
Evidence and cross-plan priorities: [estate review](../history/2026-09-28-open-workplan-infrastructure-review.md).
|