net-kingdom/workplans/NK-WP-0040-execution-attribution-receipt.md
tegwick 9383b94019 Reconcile infrastructure workplans and retire stale flex-auth references
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e77d-47a4-7771-8e34-7339c7fac0e4
2026-09-28 12:40:03 +02:00

94 lines
3.8 KiB
Markdown

---
id: NK-WP-0040
type: workplan
title: "Define an execution-attribution receipt for Railiance runs"
domain: infotech
repo: net-kingdom
status: blocked
flavor: planning
owner: claude-code
topic_slug: netkingdom
created: "2026-09-23"
updated: "2026-09-28"
related: [RCLK-WP-0002]
state_hub_workstream_id: "e2533f3a-aa43-59b3-bff3-8e64b6149487"
---
Raised by the railiance-clock identity review
(`history/2026-09-23-railiance-clock-identity-and-layer-review.md`, Ruling 1).
IAM Profile v0.3 defines who acts: human, service and agent principals, and
delegation. Playbook Capability Contract v0.1 defines what is selected and who
is responsible. No NetKingdom contract defines the record that ties **one
execution** to its actor chain, artifact and result.
## Draft the receipt fields as a Playbook Capability Contract amendment
```task
id: NK-WP-0040-T01
status: done
priority: medium
state_hub_task_id: "9d02685a-a3d9-5b9f-b09e-aef1f196a97f"
```
Draft a v0.2 amendment that adds an execution-attribution receipt with these
fields:
- issuer and subject of the initiating actor
- delegation reference (`actor_sub`/`act.sub`) when present
- executing workload binding and runtime principal
- tenant and environment
- run ID
- source commit and artifact digest
- target inventory reference and action
- decision and approval IDs
- attributed time interval, with its clock source and bound when one exists
The receipt must never embed bearer credentials. Unknown attribution is kept
explicit, not inferred. Start from the field list in railiance-clock's review.
**Done 2026-09-27.** Drafted as
`canon/standards/playbook-capability-contract_v0.2.md` (status `proposed`,
supersedes v0.1, which stays `accepted` and normative until this is
accepted). It adds an "Execution Attribution Receipt (proposed)" section
with every field above, explicit non-goals (no fourth IAM principal type,
not a decision record, not a substitute for responsibility claims), and the
never-embed-credentials / no-inferred-attribution rules. Emission, custody,
schema, and validator are explicitly left to T02.
## Agree the evidence holder and schema with audit-core and Railiance
```task
id: NK-WP-0040-T02
status: wait
priority: medium
state_hub_task_id: "963120c1-7c72-5806-942b-6f49e4c66e54"
```
audit-core holds evidence (layer model §3.3, Evidence role). Railiance
executes and emits. Agree who emits, who holds and how the receipt is
validated. Add a schema under `canon/schemas/` and a validator beside the
existing playbook-capability tooling.
**Waiting 2026-09-27.** Routed to audit-core (evidence-holder/schema
agreement) and Railiance (emitter confirmation) via State Hub messages
`48eb1101-a577-40c0-bbaa-39df02198155` and
`4f1c67bc-8de2-483f-bcac-dbdf107ce95a`. NetKingdom adds the schema and
validator once both reply; nothing here can be finished unilaterally
without pre-empting their agreement.
## Infrastructure review — 2026-09-28
Use accepted IAM Profile v0.3 and Playbook Capability Contract v0.1 as the
current baseline. Proposed IAM v0.4 and Playbook v0.2 are not deployed
capabilities. RCLK-WP-0002 still explicitly names this receipt as its dependency
on September 28. T02 remains `wait` for emitter and evidence-holder agreement.
Require the agreed schema to preserve unknown actor/delegation and clock
bounds explicitly, correlate decision/approval/run/artifact identities, and
distinguish durable receipt ingestion from attribution proof. Reuse audit-core
sender custody and reconciliation contracts rather than create another audit
sink. Acceptance needs an actual Railiance-emitted receipt and audit-core
readback, plus invalid/missing attribution cases; schema validation alone
cannot establish end-to-end attribution.
Evidence and cross-plan priorities: [estate review](../history/2026-09-28-open-workplan-infrastructure-review.md).