--- id: RPF-WP-0042 type: workplan title: "Allocate Informed Decision sitting-requester custody" domain: financials repo: railiance-platform status: ready flavor: implementation owner: grok topic_slug: railiance created: "2026-09-15" updated: "2026-09-15" related: [INFD-WP-0002] --- INFD-WP-0002 requested a create-only KeyCape sitting presenter. Platform allocates a new CCR pair. Do not widen CCR-2026-0024, CCR-2026-0025, or `platform/workloads/secrets-engine/approval-requester`. No apply, secret seed, or sitting POST from allocation. ## Allocate the verifier and attended-reader CCR pair ```task id: RPF-WP-0042-T01 status: done priority: high ``` CCR-2026-0026 (KeyCape ESO verifier) and CCR-2026-0027 (attended OIDC reader) use KV `platform/workloads/informed-decision/sitting-requester`, field `CLIENT_SECRET` only. Exact-path policies, Kubernetes ESO role, and `net-kingdom-admins` reader binding are source-declared. Front door remains non-resolvable. ESO projection is unapplied source. ## Attended first provision and exchange proof ```task id: RPF-WP-0042-T02 status: wait priority: high ``` Requires named owner reviews, KeyCape row `informed-decision-sitting-requester`, attended CAS=0 custody, exact policy/auth readback, sibling `secrets-engine/approval-requester` denial, and create-only token-exchange proof. No sitting POST until that proof exists.