railiance-platform/workplans/RPF-WP-0042-informed-decision-sitting-requester.md
repo-manager bb1aa85aea
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
repo.work.assign_missing_identifiers
source: repo-manager
reason: deterministic projection registration

Assistant: grok
Assistant-Session: 01a0a23b-3bf0-7341-b4e5-9dc05f72573a
2026-09-15 02:08:45 +02:00

1.5 KiB

id type title domain repo status flavor owner topic_slug created updated related state_hub_workstream_id
RPF-WP-0042 workplan Allocate Informed Decision sitting-requester custody financials railiance-platform ready implementation grok railiance 2026-09-15 2026-09-15
INFD-WP-0002
8a9a4e03-3500-58bd-ac09-60927dadd6fa

INFD-WP-0002 requested a create-only KeyCape sitting presenter. Platform allocates a new CCR pair. Do not widen CCR-2026-0024, CCR-2026-0025, or platform/workloads/secrets-engine/approval-requester. No apply, secret seed, or sitting POST from allocation.

Allocate the verifier and attended-reader CCR pair

id: RPF-WP-0042-T01
status: done
priority: high
state_hub_task_id: "448af717-0604-56d7-a0fa-e10e1418b2d9"

CCR-2026-0026 (KeyCape ESO verifier) and CCR-2026-0027 (attended OIDC reader) use KV platform/workloads/informed-decision/sitting-requester, field CLIENT_SECRET only. Exact-path policies, Kubernetes ESO role, and net-kingdom-admins reader binding are source-declared. Front door remains non-resolvable. ESO projection is unapplied source.

Attended first provision and exchange proof

id: RPF-WP-0042-T02
status: wait
priority: high
state_hub_task_id: "c6fbf99c-de2b-55be-9f0c-58be9fe7c518"

Requires named owner reviews, KeyCape row informed-decision-sitting-requester, attended CAS=0 custody, exact policy/auth readback, sibling secrets-engine/approval-requester denial, and create-only token-exchange proof. No sitting POST until that proof exists.