--- id: RPF-WP-0042 type: workplan title: "Allocate Informed Decision sitting-requester custody" domain: financials repo: railiance-platform status: active flavor: implementation owner: grok topic_slug: railiance created: "2026-09-15" updated: "2026-09-15" related: [INFD-WP-0002] state_hub_workstream_id: "8a9a4e03-3500-58bd-ac09-60927dadd6fa" --- INFD-WP-0002 requested a create-only KeyCape sitting presenter. Platform allocates a new CCR pair. Do not widen CCR-2026-0024, CCR-2026-0025, or `platform/workloads/secrets-engine/approval-requester`. No apply, secret seed, or sitting POST from allocation. ## Allocate the verifier and attended-reader CCR pair ```task id: RPF-WP-0042-T01 status: done priority: high state_hub_task_id: "448af717-0604-56d7-a0fa-e10e1418b2d9" ``` CCR-2026-0026 (KeyCape ESO verifier) and CCR-2026-0027 (attended OIDC reader) use KV `platform/workloads/informed-decision/sitting-requester`, field `CLIENT_SECRET` only. Exact-path policies, Kubernetes ESO role, and `net-kingdom-admins` reader binding are source-declared. Front door remains non-resolvable. ESO projection is unapplied source. ## Attended first provision and exchange proof ```task id: RPF-WP-0042-T02 status: progress priority: high state_hub_task_id: "c6fbf99c-de2b-55be-9f0c-58be9fe7c518" ``` Operator approved CCR-2026-0026/0027 on 2026-09-15. Source registration is in `key-cape/config/service-clients.example.yaml`. Live apply is the silent helper `scripts/provision-sitting-requester.sh` through `openbao-attended-exec.py`. No sitting POST until exchange proof exists. Do not widen CCR-2026-0024/0025. 2026-09-15 attended attempt failed before command handoff: `revocation could not be confirmed`. Public Ingress is already absent, and the shell still had `BAO_ADDR=https://bao.coulomb.social`. The wrapper now pins the operator tunnel. Retry that same helper; do not treat this attempt as custody. Retry 2026-09-15T18:28:25Z succeeded: receipt `applied`, phase `keycape_ready`, KV version 1, ESO Ready/SecretSynced, KeyCape single Ready replica, CCRs applied. No sitting POST. Remaining: create-only token-exchange proof (positive create scope, refuse approve/consume, sibling path deny). Evidence: `docs/evidence/2026-09-15-sitting-requester-provision.json`. Exchange proof uses reader lane `informed-decision-sitting-requester-login` and `scripts/prove-sitting-requester-exchange.sh`. It does not POST sittings. 2026-09-15T18:47Z reader login reached a helper-backed session; the child failed at `preflight` with no failure class. A first browser sign-in did not complete. Retry records a named failure class, reads KV through `bao`, and overwrites a failed receipt only.