railiance-platform/workplans/RPF-WP-0034-state-hub-preflight-signing-design.md
codex 193b1276f3 Document credential lane designs and adopt fast projection sync
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
2026-09-05 10:41:56 +02:00

40 lines
1.3 KiB
Markdown

---
id: RPF-WP-0034
type: workplan
title: "Design State Hub preflight signing custody"
domain: financials
repo: railiance-platform
status: blocked
owner: codex
created: "2026-09-05"
updated: "2026-09-05"
---
# Design State Hub preflight signing custody
## Prepare the platform design
```task
id: RPF-WP-0034-T01
status: done
priority: high
```
Reviewed owner source and the current platform CCR contract. Delivered
`docs/credential-lane-designs/state-hub-preflight-signing.md` with proposed exact scope, custody, lifecycle, implementation gaps,
approval requirements and positive/negative acceptance evidence. This is a
completed design deliverable, not a live lane or approval. No secrets accessed,
production objects changed or owner messages sent.
## Obtain owner inputs and implement the approved lane
```task
id: RPF-WP-0034-T02
status: wait
priority: high
```
Confirm exact primary deployment and delivery identity; approve the writer and read CCR; implement dedicated ESO/API-only delivery and a concrete rotation fence. Provision only in an approved window, prove preflight signing without executing a rename, and record API/ESO health and negative access evidence.
Review the linked design and pin current source revisions before implementation.
Do not interpret this workplan or a proposed coordinate as live authorization.