net-kingdom/workplans/NK-WP-0040-execution-attribution-receipt.md
tegwick a7a4db5a89
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 4s
Record A11 r2/A12 r3 assent and the railiance-clock owner review
- A11 r2 approved; A12 r3 approved by operator decision (supersedes the
  2026-09-21 deferral of A12 r2). Flip notice will name eight checkers.
- railiance-clock review: identity vocabulary confirmed without a new
  principal type; Tooling now, PIP only once a sample API is consumed;
  execution-attribution gap assigned to NK-WP-0040 (proposed).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 299762@bnt-lap001
Assistant-Session: d3d3cea1-869c-44f1-be2a-3d6d3550e72e
2026-09-23 20:08:46 +02:00

1.8 KiB

id type title domain repo status flavor owner topic_slug created updated related
NK-WP-0040 workplan Define an execution-attribution receipt for Railiance runs infotech net-kingdom proposed planning claude-code netkingdom 2026-09-23 2026-09-23
RCLK-WP-0002

Raised by the railiance-clock identity review (history/2026-09-23-railiance-clock-identity-and-layer-review.md, Ruling 1). IAM Profile v0.3 defines who acts: human, service and agent principals, and delegation. Playbook Capability Contract v0.1 defines what is selected and who is responsible. No NetKingdom contract defines the record that ties one execution to its actor chain, artifact and result.

Draft the receipt fields as a Playbook Capability Contract amendment

id: NK-WP-0040-T01
status: todo
priority: medium

Draft a v0.2 amendment that adds an execution-attribution receipt with these fields:

  • issuer and subject of the initiating actor
  • delegation reference (actor_sub/act.sub) when present
  • executing workload binding and runtime principal
  • tenant and environment
  • run ID
  • source commit and artifact digest
  • target inventory reference and action
  • decision and approval IDs
  • attributed time interval, with its clock source and bound when one exists

The receipt must never embed bearer credentials. Unknown attribution is kept explicit, not inferred. Start from the field list in railiance-clock's review.

Agree the evidence holder and schema with audit-core and Railiance

id: NK-WP-0040-T02
status: todo
priority: medium

audit-core holds evidence (layer model §3.3, Evidence role). Railiance executes and emits. Agree who emits, who holds and how the receipt is validated. Add a schema under canon/schemas/ and a validator beside the existing playbook-capability tooling.