id: CCR-2026-0027 kind: credential-change-request schema_version: 1 request_type: workload-kv-read title: Informed Decision sitting-requester attended operator reader status: proposed created: '2026-09-15' updated: '2026-09-15' requester: agent: grok reason: INFD-WP-0002-T03 requested a create-only sitting presenter whose binding.actor is informed-decision. Allocate a new CCR pair. Do not widen CCR-2026-0024, CCR-2026-0025 or platform/workloads/secrets-engine/approval-requester. review: required: true required_approvers: - platform-operator - key-cape-owner comments: - at: '2026-09-15' reviewer: operator instruction in Grok session decision: allocated comment: Operator selected allocation of the sitting-requester CCR pair. Source only. No OpenBao apply, no secret seed, and no sitting POST from this allocation. target: domain: financials tenant: platform workload: informed-decision environment: production purpose: create-only sitting requester attended operator reader; approval:create only; subject informed-decision; audience approval-engine. openbao: mount: platform kv_path: platform/workloads/informed-decision/sitting-requester fields: - CLIENT_SECRET policy_name: workload-kv-read-informed-decision-sitting-requester-client policy_file: openbao/policies/workload-kv-read-informed-decision-sitting-requester-client.hcl auth: method: oidc mount: netkingdom role: informed-decision-sitting-requester-workload-kv-read allowed_redirect_uris: - https://bao.coulomb.social/ui/vault/auth/netkingdom/oidc/callback - http://localhost:8250/oidc/callback - http://127.0.0.1:8250/oidc/callback oidc_scopes: - openid - profile - email - groups user_claim: sub groups_claim: groups bound_claims: groups: - net-kingdom-admins bound_claims_confirmed: true policies: - workload-kv-read-informed-decision-sitting-requester-client ttl: 15m access_frontdoor: type: ops-warden catalog_id: informed-decision-sitting-requester-login selector: Informed Decision create-only sitting requester command: warden access informed-decision-sitting-requester-login --exec -- resolvable: false readiness: pending-review delivery: surface: operator-workstation target: Contained attended reader session; secret stays in memory for native requester exchange; no retained file or raw output. risk: classification: high notes: - Credential authenticates only the separate approval:create sitting requester. Human disposition remains on the public PKCE client informed-decision-approver. - Do not widen CCR-2026-0024/0025 or secrets-engine/approval-requester. - Bound group is net-kingdom-admins, matching CCR-2026-0019/0025 operator binding. verification: positive: - Exact path read of CLIENT_SECRET for the attended operator identity only. - Sibling secrets-engine/approval-requester and parent listing denied. negative: - Approval and consume scopes refused at token exchange; wrong secret refused. - Sibling KV paths and parent listing denied. activation_conditions: - Attended platform authority, CAS=0 custody, exact policy/auth readback and synchronized verifier delivery. - Separate reader verification and no human entry synthesized. - No sitting POST until exchange proof exists. lifecycle: deactivate: Disable the informed-decision-sitting-requester KeyCape registration and detach only these two sitting-requester reader roles. Preserve CCR-2026-0024/0025 and existing consumer/verifier lanes. rotate: Rotate through KeyCape and platform using a new version with predecessor refusal proof. compromised: Disable sitting-requester issuance first; revoke sessions and rotate under attended owner authority. state_hub: workplan_id: RPF-WP-0042 task_id: RPF-WP-0042-T01 related_request: CCR-2026-0026 related_workplan: INFD-WP-0002