# Sitting-requester reader session CCR-2026-0027 admits only `platform/workloads/informed-decision/sitting-requester`. The contained Warden login uses `informed-decision-sitting-requester-workload-kv-read`. Its owner command checks exact reader policies, sibling denial of `secrets-engine/approval-requester`, and a create-only KeyCape token exchange. It does not POST sittings and never prints the client secret. Use the current source catalog explicitly: `WARDEN_ROUTING_CATALOG=/home/worsch/ops-warden/registry/routing/catalog.yaml` The reviewed child is `/home/worsch/railiance-platform/scripts/prove-sitting-requester-exchange.sh`. OpenBao is reached through `http://127.0.0.1:18200`. Warden self-revokes after the child exits.