--- id: RPF-WP-0042 type: workplan title: "Allocate Informed Decision sitting-requester custody" domain: financials repo: railiance-platform status: ready flavor: implementation owner: grok topic_slug: railiance created: "2026-09-15" updated: "2026-09-15" related: [INFD-WP-0002] state_hub_workstream_id: "8a9a4e03-3500-58bd-ac09-60927dadd6fa" --- INFD-WP-0002 requested a create-only KeyCape sitting presenter. Platform allocates a new CCR pair. Do not widen CCR-2026-0024, CCR-2026-0025, or `platform/workloads/secrets-engine/approval-requester`. No apply, secret seed, or sitting POST from allocation. ## Allocate the verifier and attended-reader CCR pair ```task id: RPF-WP-0042-T01 status: done priority: high state_hub_task_id: "448af717-0604-56d7-a0fa-e10e1418b2d9" ``` CCR-2026-0026 (KeyCape ESO verifier) and CCR-2026-0027 (attended OIDC reader) use KV `platform/workloads/informed-decision/sitting-requester`, field `CLIENT_SECRET` only. Exact-path policies, Kubernetes ESO role, and `net-kingdom-admins` reader binding are source-declared. Front door remains non-resolvable. ESO projection is unapplied source. ## Attended first provision and exchange proof ```task id: RPF-WP-0042-T02 status: wait priority: high state_hub_task_id: "c6fbf99c-de2b-55be-9f0c-58be9fe7c518" ``` Requires named owner reviews, KeyCape row `informed-decision-sitting-requester`, attended CAS=0 custody, exact policy/auth readback, sibling `secrets-engine/approval-requester` denial, and create-only token-exchange proof. No sitting POST until that proof exists.