ops-warden/registry/routing
tegwick a942ce805d docs: record the answered custody authority on the qonto lane
railiance-platform answered the routing question (msg 7c7228ac): steps 1-2
are executed by the platform operator attended, through the governed
openbao-platform-admin-login lane with a unique metadata receipt path, under
founder_required attended OIDC via netkingdom role=platform-admin. Nothing
else in that repo carries write authority against platform/workloads/.

The blocker narrows again -- the AUTHORITY is answered, the ARTIFACT is not.
A two-custodian CAS rotation with a service restart is a distinct
version-guarded operation needing its own reviewed CCR, which is theirs to
write once an owner asks for the rotation. That question is now with
key-cape; ops-warden connected the two and did not ask on their behalf.

Their executable precedent for the identical two-custodian shape is cited so
a rapp-qonto rotation script is not built from a bare `bao kv patch` -- the
provider/consumer consistency reason key-cape gave when declining to ship a
wrapper, which railiance-platform endorsed unprompted.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013EPuTc18FjU5WFqoSEKH3C

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1276224@bnt-lap001
Assistant-Session: 426ec497-e1c4-4dd3-b417-dfce1ca1dbc3
2026-09-10 08:02:10 +02:00
..
catalog.yaml docs: record the answered custody authority on the qonto lane 2026-09-10 08:02:10 +02:00