{ "id": "decision:0f9c98f14545c42d", "contract_version": "flex-auth.decision-record.v1", "request_id": "check:secrets-engine-adoption-proof", "effect": "allow", "reason": "catalog_lane_policy_matched", "matched_policy_version": "v2", "matched_rule": "catalog_lane_policy_matched", "resource": { "id": "catalog:glas-claude-agent-dev-anthropic", "type": "secret-catalog-lane", "system": "secrets-engine", "tenant": "tenant:platform", "attributes": { "auth_targets": [], "fields": [ "api_key" ], "policy_targets": [], "stage": "prod" } }, "subject": { "id": "secrets-engine", "type": "service", "tenant": "tenant:platform", "attributes": { "description": "secrets-engine's own service identity, the single calling identity for the twelve gated catalog-lane actions it sends to POST /v1/check. Because it is the only subject, the package has no action_not_granted branch (FLEX-WP-0021-T02); registering a second identity is the revisit trigger.", "display_name": "secrets-engine service principal", "groups": [ "group:secrets-engine-lane-operators" ], "organization_relation": "ServiceProvider", "roles": [ "Operator" ] } }, "binding": { "tenant": "tenant:platform", "subject": { "id": "secrets-engine", "type": "service", "tenant": "tenant:platform", "attributes": { "description": "secrets-engine's own service identity, the single calling identity for the twelve gated catalog-lane actions it sends to POST /v1/check. Because it is the only subject, the package has no action_not_granted branch (FLEX-WP-0021-T02); registering a second identity is the revisit trigger.", "display_name": "secrets-engine service principal", "groups": [ "group:secrets-engine-lane-operators" ], "organization_relation": "ServiceProvider", "roles": [ "Operator" ] } }, "action": "rotate", "resource": { "id": "catalog:glas-claude-agent-dev-anthropic", "type": "secret-catalog-lane", "system": "secrets-engine", "tenant": "tenant:platform", "attributes": { "auth_targets": [], "fields": [ "api_key" ], "policy_targets": [], "stage": "prod" } }, "context": { "purpose": "live-adoption-proof" }, "request_digest": "sha256:c37f2fe78205758b27d081e8fb90a9446aa4bd5a571b337d343621955705013c" }, "lifetime": { "kind": "ttl", "ttl": "15m", "not_before": "2026-09-06T22:19:09Z", "expires_at": "2026-09-06T22:34:09Z" }, "diagnostics": { "action": "rotate", "matched_relationship": "", "policy_package": "secrets-engine.catalog-lane.lifecycle", "policy_status": "ready", "registry_resource": false, "registry_subject": true }, "provenance": { "evaluator": "flex-auth/local", "mode": "standalone", "policy_package": "secrets-engine.catalog-lane.lifecycle", "policy_version": "v2", "policy_package_digest": "sha256:bd11c5fe77ce6439c65fea225ad6b71d2110efc5e7b5bc9b499c59cd0a53b8b4", "registry_snapshot_digest": "sha256:f5a309bc0b36721fd6d9ad7f53eb21222162bc2eac62a0ab0802a9a1d51340bb", "input_claim_digests": { "context": "sha256:098626d19cdacbc5abebada472e73b2fa328dfd5f8506cb50e63ac6767f87e3a" }, "decision_time": "2026-09-06T22:19:09Z" }, "caring": { "profile": "caring-0.4.0-rc2", "conformance_findings": [ { "code": "CARING-DESCRIPTOR-MISSING", "severity": "warning", "message": "no CARING descriptor matched the request", "fields": [ "caring_context" ] } ] } }