# Custodian Brief — tenant-engine **Domain:** infotech **Last synced:** 2026-08-29 10:02 UTC **State Hub:** http://127.0.0.1:8000 *(adjust if running on a remote machine)* ## Active Workstreams ### Align tenant-engine with the accepted security layer model Progress: 0/6 done | workplan_id: `43ad25c6-7149-53d1-8012-817a061ace92` **Open tasks:** - · T01 — Machine-readable layer declaration and conformance check `f46944d8` - · T02 — PEP write-path: decision records and published fail-closed stance `62659305` - · T03 — PIP claim freshness, and prove live-lookup is not cyclic `7815548c` - · T04 — Externalize mutation evidence to audit-core `cfab6837` - · T05 — Remove or authorize the unfiltered event-read interface `7540049b` - · T06 — Request the boundary-contract amendment `ffd2cc53` ### Bring tenant-engine under the staged-promotion contract Progress: 0/4 done | workplan_id: `e9da1c15-7beb-48d9-97ab-b657fdf9366e` **Open tasks:** - · T01 - Write and validate `railiance/app.toml` `0231e4d1` - · T02 - Reconcile the deployment shape with the contract `5f2ad011` - · T03 - Record current production as the stable baseline `c4b79dc1` - · T04 - Hand the pattern back to the fleet `b816a862` --- ## MCP Orientation (when available) If the state-hub MCP server is reachable, call: `get_domain_summary("infotech")` This provides richer cross-domain context. If the MCP call fails, use this file as your orientation source.