# Exact metered requester extension — awaiting operator approval Existing work: RPF-WP-0035-T06, SECRETS-WP-0009-T03, REINAH-WP-0003-T06. This proposal does not change CCR-2026-0025's admitted scope until the operator explicitly approves it. No additional task or workplan is created. Reviewed command: scripts/create-metered-approval-requests.sh, invoking the adjacent Python script with --clock-trust-file and --mandate. The command freezes SHA-256 22e640428e3a7ae8fc2363cf193db98381cd94e4be7ab009bc6703658d6fc544 of secrets-engine/docs/proposals/glas-metered-tool-renewal-20260927/native-pdp-inputs.json. Exactly six unsigned requests: apply, verify, exec for each of `glas-claude-agent-dev-anthropic` and `activity-core-metered-worker-token`. The provider requires human control; the companion retains ordinary approval. The requester keeps approval:create only, the same exact KV reader, subject, audience, tenant, and 15-minute token limit. It verifies excess scopes and sibling reads are denied; client bytes remain in memory; Warden revokes its reader. It neither approves nor consumes requests and never retrieves either workload credential. It writes non-secret native receipts and refuses to overwrite a partial receipt or retry an uncertain create. Planned IDs persist before POST. Four requester tests plus two existing token-time tests pass. Dry-run lists exactly six records. Actual creation still requires explicit operator mandate, fresh admitted Railiance Clock interval and attended reader execution. Native review and consume/backend admission remain after creation. The current human review HTTP adapter admits human-control records only: companion ordinary approval needs its own supported approver path; do not relabel it human-control or use the retired combined operator client to bypass that boundary.