--- id: RPF-WP-0034 type: workplan title: "Design State Hub preflight signing custody" domain: financials repo: railiance-platform status: blocked owner: codex created: "2026-09-05" updated: "2026-09-05" --- # Design State Hub preflight signing custody ## Prepare the platform design ```task id: RPF-WP-0034-T01 status: done priority: high ``` Reviewed owner source and the current platform CCR contract. Delivered `docs/credential-lane-designs/state-hub-preflight-signing.md` with proposed exact scope, custody, lifecycle, implementation gaps, approval requirements and positive/negative acceptance evidence. This is a completed design deliverable, not a live lane or approval. No secrets accessed, production objects changed or owner messages sent. ## Obtain owner inputs and implement the approved lane ```task id: RPF-WP-0034-T02 status: wait priority: high ``` Confirm exact primary deployment and delivery identity; approve the writer and read CCR; implement dedicated ESO/API-only delivery and a concrete rotation fence. Provision only in an approved window, prove preflight signing without executing a rename, and record API/ESO health and negative access evidence. Review the linked design and pin current source revisions before implementation. Do not interpret this workplan or a proposed coordinate as live authorization.