Close recovery acceptance and reconcile blocked workplans
Some checks are pending
CI Smoke / host-smoke (push) Waiting to run
CI Smoke / container-smoke (push) Waiting to run
Account journey acceptance / journeys (push) Successful in 10s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e38e-e5bb-7b50-968d-a738a0294997
This commit is contained in:
tegwick 2026-09-27 17:54:47 +02:00
parent b73f553c18
commit eca7c54748
9 changed files with 162 additions and 46 deletions

View file

@ -34,16 +34,16 @@
| workplan | USER-WP-0023 | finished | — | workplans/USER-WP-0023-flex-auth-caller-identity.md | | workplan | USER-WP-0023 | finished | — | workplans/USER-WP-0023-flex-auth-caller-identity.md |
| workplan | USER-WP-0024 | finished | — | workplans/USER-WP-0024-security-layer-conformance.md | | workplan | USER-WP-0024 | finished | — | workplans/USER-WP-0024-security-layer-conformance.md |
| workplan | USER-WP-0025 | finished | — | workplans/USER-WP-0025-operator-navigation-and-logout.md | | workplan | USER-WP-0025 | finished | — | workplans/USER-WP-0025-operator-navigation-and-logout.md |
| workplan | USER-WP-0026 | active | — | workplans/USER-WP-0026-account-recovery.md | | workplan | USER-WP-0026 | blocked | — | workplans/USER-WP-0026-account-recovery.md |
| workplan | USER-WP-0027 | active | — | workplans/USER-WP-0027-account-journey-clarity.md | | workplan | USER-WP-0027 | blocked | — | workplans/USER-WP-0027-account-journey-clarity.md |
| workplan | USER-WP-0028 | active | — | workplans/USER-WP-0028-user-journey-acceptance.md | | workplan | USER-WP-0028 | blocked | — | workplans/USER-WP-0028-user-journey-acceptance.md |
| workplan | USER-WP-0029 | finished | — | workplans/USER-WP-0029-tenant-admin-journeys.md | | workplan | USER-WP-0029 | finished | — | workplans/USER-WP-0029-tenant-admin-journeys.md |
| workplan | USER-WP-0030 | finished | — | workplans/USER-WP-0030-platform-admin-journeys.md | | workplan | USER-WP-0030 | finished | — | workplans/USER-WP-0030-platform-admin-journeys.md |
| workplan | USER-WP-0031 | finished | — | workplans/USER-WP-0031-automated-journey-suites.md | | workplan | USER-WP-0031 | finished | — | workplans/USER-WP-0031-automated-journey-suites.md |
| workplan | USER-WP-0032 | finished | — | workplans/USER-WP-0032-platform-service-operations.md | | workplan | USER-WP-0032 | finished | — | workplans/USER-WP-0032-platform-service-operations.md |
| workplan | USER-WP-0033 | finished | — | workplans/USER-WP-0033-authentication-policy.md | | workplan | USER-WP-0033 | finished | — | workplans/USER-WP-0033-authentication-policy.md |
| workplan | USER-WP-0034 | active | — | workplans/USER-WP-0034-access-engine-repository-rename-handoff.md | | workplan | USER-WP-0034 | blocked | — | workplans/USER-WP-0034-access-engine-repository-rename-handoff.md |
| workplan | USER-WP-0035 | active | — | workplans/USER-WP-0035-onboarding-handoff-findings.md | | workplan | USER-WP-0035 | blocked | — | workplans/USER-WP-0035-onboarding-handoff-findings.md |
| workplan | USER-WP-0036 | finished | — | workplans/USER-WP-0036-account-situational-awareness.md | | workplan | USER-WP-0036 | finished | — | workplans/USER-WP-0036-account-situational-awareness.md |
| task | USER-WP-ADHOC-2026-09-06-T01 | done | — | workplans/ADHOC-2026-09-06.md | | task | USER-WP-ADHOC-2026-09-06-T01 | done | — | workplans/ADHOC-2026-09-06.md |
| task | USER-WP-0001-T1 | done | — | workplans/USER-WP-0001-preparation-and-interface-adoption.md | | task | USER-WP-0001-T1 | done | — | workplans/USER-WP-0001-preparation-and-interface-adoption.md |
@ -194,16 +194,16 @@
| task | USER-WP-0025-T02 | done | — | workplans/USER-WP-0025-operator-navigation-and-logout.md | | task | USER-WP-0025-T02 | done | — | workplans/USER-WP-0025-operator-navigation-and-logout.md |
| task | USER-WP-0025-T03 | done | — | workplans/USER-WP-0025-operator-navigation-and-logout.md | | task | USER-WP-0025-T03 | done | — | workplans/USER-WP-0025-operator-navigation-and-logout.md |
| task | USER-WP-0026-T01 | done | — | workplans/USER-WP-0026-account-recovery.md | | task | USER-WP-0026-T01 | done | — | workplans/USER-WP-0026-account-recovery.md |
| task | USER-WP-0026-T02 | progress | — | workplans/USER-WP-0026-account-recovery.md | | task | USER-WP-0026-T02 | done | — | workplans/USER-WP-0026-account-recovery.md |
| task | USER-WP-0026-T03 | todo | — | workplans/USER-WP-0026-account-recovery.md | | task | USER-WP-0026-T03 | wait | — | workplans/USER-WP-0026-account-recovery.md |
| task | USER-WP-0027-T01 | done | — | workplans/USER-WP-0027-account-journey-clarity.md | | task | USER-WP-0027-T01 | done | — | workplans/USER-WP-0027-account-journey-clarity.md |
| task | USER-WP-0027-T02 | done | — | workplans/USER-WP-0027-account-journey-clarity.md | | task | USER-WP-0027-T02 | done | — | workplans/USER-WP-0027-account-journey-clarity.md |
| task | USER-WP-0027-T03 | done | — | workplans/USER-WP-0027-account-journey-clarity.md | | task | USER-WP-0027-T03 | done | — | workplans/USER-WP-0027-account-journey-clarity.md |
| task | USER-WP-0027-T04 | wait | — | workplans/USER-WP-0027-account-journey-clarity.md | | task | USER-WP-0027-T04 | wait | — | workplans/USER-WP-0027-account-journey-clarity.md |
| task | USER-WP-0027-T05 | done | — | workplans/USER-WP-0027-account-journey-clarity.md | | task | USER-WP-0027-T05 | done | — | workplans/USER-WP-0027-account-journey-clarity.md |
| task | USER-WP-0027-T06 | progress | — | workplans/USER-WP-0027-account-journey-clarity.md | | task | USER-WP-0027-T06 | wait | — | workplans/USER-WP-0027-account-journey-clarity.md |
| task | USER-WP-0028-T01 | done | — | workplans/USER-WP-0028-user-journey-acceptance.md | | task | USER-WP-0028-T01 | done | — | workplans/USER-WP-0028-user-journey-acceptance.md |
| task | USER-WP-0028-T02 | todo | — | workplans/USER-WP-0028-user-journey-acceptance.md | | task | USER-WP-0028-T02 | wait | — | workplans/USER-WP-0028-user-journey-acceptance.md |
| task | USER-WP-0028-T03 | wait | — | workplans/USER-WP-0028-user-journey-acceptance.md | | task | USER-WP-0028-T03 | wait | — | workplans/USER-WP-0028-user-journey-acceptance.md |
| task | USER-WP-0029-T01 | done | — | workplans/USER-WP-0029-tenant-admin-journeys.md | | task | USER-WP-0029-T01 | done | — | workplans/USER-WP-0029-tenant-admin-journeys.md |
| task | USER-WP-0029-T02 | done | — | workplans/USER-WP-0029-tenant-admin-journeys.md | | task | USER-WP-0029-T02 | done | — | workplans/USER-WP-0029-tenant-admin-journeys.md |

View file

@ -2,9 +2,9 @@
Owner: user-engine, with KeyCape/NetKingdom for sign-in and factors, Owner: user-engine, with KeyCape/NetKingdom for sign-in and factors,
tenant-engine for tenant lifecycle, and applications for workload admission. tenant-engine for tenant lifecycle, and applications for workload admission.
Acceptance work: USER-WP-0027; OTP dependency: KEY-WP-0035 and NK-WP-0033. Acceptance work: USER-WP-0027/0028; provider implementation: KEY-WP-0035 (finished).
Reviewed against the portal on 2026-09-13. U01, U09 and U10 were revised on Reviewed against the portal on 2026-09-13. U01, U09 and U10 were revised on
2026-09-26. This is the browser acceptance contract; 2026-09-26; acceptance dependencies were reconciled on 2026-09-27. This is the browser acceptance contract;
headless capability alone does not mean a journey is usable or verified live. headless capability alone does not mean a journey is usable or verified live.
## Common interaction rules ## Common interaction rules
@ -43,16 +43,16 @@ headless capability alone does not mean a journey is usable or verified live.
| ID / intent | Success | Failure and recovery | Current support / acceptance | | ID / intent | Success | Failure and recovery | Current support / acceptance |
|---|---|---|---| |---|---|---|---|
| U01 — Know whether I am signed in | Header and the home page say “Signed in as” the verified identity when an account-site session exists. With no account-site session they say “Not signed in,” unless the sign-in service confirms an existing NetKingdom identity, which is then named before the account site continues. An application may keep its own session. A one-time code is a higher security level, not another sign-in | Expired/unknown cookie shows signed-out state; a query does not invent a session; a failed identity lookup stays signed out; sign in again, or use a different identity | Implemented; automated anonymous/expired/member/operator tests, including the home identity section and a confirmed NetKingdom sign-in with no account-site session | | U01 — Know whether I am signed in | Header and the home page say “Signed in as” the verified identity when an account-site session exists. With no account-site session they say “Not signed in,” unless the sign-in service confirms an existing NetKingdom identity, which is then named before the account site continues. An application may keep its own session. A one-time code is a higher security level, not another sign-in | Expired/unknown cookie shows signed-out state; a query does not invent a session; a failed identity lookup stays signed out; sign in again, or use a different identity | Implemented; automated anonymous/expired/member/operator tests, including the home identity section and a confirmed NetKingdom sign-in with no account-site session |
| U02 — Sign in to my company application | Personal login lands in the intended tenant and application | Wrong credentials stay on provider; denied membership leads to account help with identity switching | Recovery deployed previously; actual fresh-user acceptance waiting on OTP | | U02 — Sign in to my company application | Personal login lands in the intended tenant and application | Wrong credentials stay on provider; denied membership leads to account help with identity switching | Fresh application login confirmed on September 24; second-user, setup-to-welcome and company-workflow acceptance remain VERGABE-WP-0019-T06 |
| U03 — Accept an invitation | Confirm intended tenant/role, accept once, then see next setup step | Expired/used/wrong-person invitation explains next step; admin reissues without duplicates | Service/browser routes exist; live delivery and full browser acceptance pending | | U03 — Accept an invitation | Confirm intended tenant/role, accept once, then see next setup step | Expired/used/wrong-person invitation explains next step; admin reissues without duplicates | Service/browser routes exist; live delivery and full browser acceptance pending |
| U04 — Set or recover my password | Use actual login name, complete single-use setup, return to sign-in | Missing mail or expired link offers admin-assisted new setup link | Password setup reported successful; login name and sign-in address now named at handoff and in the user entry (2026-09-23 run, USER-WP-0035-T01); email delivery unresolved (USER-WP-0035-T02) | | U04 — Set or recover my password | Use actual login name, complete single-use setup, return to sign-in | Missing mail or expired link offers admin-assisted new setup link | Password setup reported successful; login name and sign-in address now named at handoff and in the user entry (2026-09-23 run, USER-WP-0035-T01); email delivery unresolved (USER-WP-0035-T02) |
| U05 — Use password-only access before optional OTP enrollment | Ordinary application permits login when provider confirms no activated factor | Provider unavailable gives recovery, never silently bypasses enrolled OTP | KEY-WP-0035 source tested; live credential/policy gate unresolved | | U05 — Use password-only access before optional OTP enrollment | Ordinary application permits login when provider confirms no activated factor | Provider unavailable gives recovery, never silently bypasses enrolled OTP | Renewable factor-reader and optional policy deployed (KEY-WP-0035/RPF-WP-0040); installed-provider checks pass; attended full U05–U08 acceptance remains USER-WP-0028-T03 |
| U06 — Turn on authenticator codes voluntarily | My account → Sign-in security → provider; confirm identity, scan QR, verify current code, see activation confirmed, test fresh login | Bad code retries; cancellation does not report enabled; interruption can resume safely; support reachable without portal login | Help and configurable provider handoff implemented; provider activation/cancel semantics and live enrollment unverified | | U06 — Turn on authenticator codes voluntarily | My account → Sign-in security → provider; confirm identity, scan QR, verify current code, see activation confirmed, test fresh login | Bad code retries; cancellation does not report enabled; interruption can resume safely; support reachable without portal login | Installed-provider activation/cancellation checks pass (P06); real-user enrollment and verified portal handoff remain USER-WP-0028-T03 |
| U07 — Sign in with an enrolled authenticator | Current code completes login; existing AAL1 session cannot skip OTP | Invalid code explains retry; lost device has a recovery route | Issuer policy tested; real-user enrolled/recovery acceptance pending | | U07 — Sign in with an enrolled authenticator | Current code completes login; existing AAL1 session cannot skip OTP | Invalid code explains retry; lost device has a recovery route | Issuer policy tested; real-user enrolled/recovery acceptance pending |
| U08 — Replace or remove my authenticator | Provider reauthenticates; replacement verified before old factor removed; status and recovery instructions clear | Lost old factor triggers verified recovery, not a bypass link; policy-required MFA cannot be disabled | Required provider journey; not verified/available from portal yet | | U08 — Replace or remove my authenticator | Provider reauthenticates; replacement verified before old factor removed; status and recovery instructions clear | Lost old factor triggers verified recovery, not a bypass link; policy-required MFA cannot be disabled | P04 recovery and P06 replacement guards deployed and verified with disposable provider fixtures; real-person recovery/replacement acceptance remains USER-WP-0028-T03 |
| U09 — See my tenants and usable applications | Account page and home show login state, the tenants and privileges active on this sign-in, and allowed memberships separately. An ordinary sign-in has one active tenant. An administrator, vendor, or multi-hire sign-in may show more than one active tenant when the verified token lists them. A recorded workload membership is an allowed record | An empty allowed list says nothing is recorded. A tenant account or the token tenant is not shown as a membership. A missing catalogue decision is not checked, which is neither access nor a denial | Login state, active sign-in, and allowed memberships are shown (USER-WP-0036). Allow, deny, and unavailable workload decisions remain USER-WP-0026-T03 and USER-WP-0028-T02 | | U09 — See my tenants and usable applications | Account page and home show login state, the tenants and privileges active on this sign-in, and allowed memberships separately. An ordinary sign-in has one active tenant. An administrator, vendor, or multi-hire sign-in may show more than one active tenant when the verified token lists them. A recorded workload membership is an allowed record | An empty allowed list says nothing is recorded. A tenant account or the token tenant is not shown as a membership. A missing catalogue decision is not checked, which is neither access nor a denial | Login state, active sign-in, and allowed memberships are shown (USER-WP-0036). Allow, deny, and unavailable workload decisions remain USER-WP-0026-T03 and USER-WP-0028-T02 |
| U10 — Change tenant or account | Explicit reauthentication confirms the new tenant. Other allowed tenants stay inactive until that sign-in. Switching does not claim to end sessions an application already has | Denied tenant leaves a clear recovery route; stale shared identity can be cleared. A portal control does not mark a second tenant active by itself | Reauthentication handoff is the only tenant switch; real multi-identity acceptance pending | | U10 — Change tenant or account | Explicit reauthentication confirms the new tenant. Other allowed tenants stay inactive until that sign-in. Switching does not claim to end sessions an application already has | Denied tenant leaves a clear recovery route; stale shared identity can be cleared. A portal control does not mark a second tenant active by itself | Account switching confirmed by the founder on September 24 with fresh issuer sequences (USER-WP-0026-T02); multi-user workload acceptance remains VERGABE-WP-0019-T06 |
| U11 — Sign out | Confirmation states scope; portal session ends; correct signed-out controls appear | CSRF rejection retains session; shared-provider failure explains remaining scope and retry | Portal automated tests; prior shared logout browser checks; current real-user acceptance pending | | U11 — Sign out | Confirmation states scope; portal session ends; correct signed-out controls appear | CSRF rejection retains session; shared-provider failure explains remaining scope and retry | Automated scope/CSRF tests, live shared-logout checks and September 24 attended account-switch receipt complete USER-WP-0026-T02; existing application JWTs are not revoked |
| U12 — Recover from denied access or service outage | Plain explanation, reference for support, and account/help navigation | No automatic login loop; no private claims/codes echoed; safe retry only | HTML browser denial/recovery implemented; JSON API semantics retained | | U12 — Recover from denied access or service outage | Plain explanation, reference for support, and account/help navigation | No automatic login loop; no private claims/codes echoed; safe retry only | HTML browser denial/recovery implemented; JSON API semantics retained |
| U13 — Update my profile and finish onboarding | Saved values and required steps are confirmed; external steps reflect provider evidence | Validation keeps safe input; provider-owned steps cannot be manually faked complete | Existing routes; form-preservation and external completion UX acceptance pending | | U13 — Update my profile and finish onboarding | Saved values and required steps are confirmed; external steps reflect provider evidence | Validation keeps safe input; provider-owned steps cannot be manually faked complete | Existing routes; form-preservation and external completion UX acceptance pending |
@ -63,7 +63,7 @@ headless capability alone does not mean a journey is usable or verified live.
| T01 — Enter the right tenant administration | Header shows identity; managed tenant is explicit; only permitted admin navigation | Non-admin/cross-tenant request denied with account recovery | Existing authorization/navigation tests; broader browser matrix pending | | T01 — Enter the right tenant administration | Header shows identity; managed tenant is explicit; only permitted admin navigation | Non-admin/cross-tenant request denied with account recovery | Existing authorization/navigation tests; broader browser matrix pending |
| T02 — Invite someone with the right role | Review name, email, tenant and role; show invitation state and next action | Duplicate, wrong address, expired invite: inspect, correct/reissue or expire without making a second account | Invitation routes and checks exist; delivery/preview usability pending | | T02 — Invite someone with the right role | Review name, email, tenant and role; show invitation state and next action | Duplicate, wrong address, expired invite: inspect, correct/reissue or expire without making a second account | Invitation routes and checks exist; delivery/preview usability pending |
| T03 — Prepare an account that can actually log in | Distinguish profile, directory login name, invitation, password setup, and tenant access; admin can give the correct login name | Partial provisioning shows what exists and retry reconciles it; never show display name as login implicitly | Create-login/setup-link routes exist; login name and sign-in address presented in the user entry (USER-WP-0035-T01); lifecycle state view pending | | T03 — Prepare an account that can actually log in | Distinguish profile, directory login name, invitation, password setup, and tenant access; admin can give the correct login name | Partial provisioning shows what exists and retry reconciles it; never show display name as login implicitly | Create-login/setup-link routes exist; login name and sign-in address presented in the user entry (USER-WP-0035-T01); lifecycle state view pending |
| T04 — Help someone who cannot sign in | Identify affected tenant/account; distinguish password, OTP, membership, and outage; give safe recovery step | No access to passwords, OTP seed or current codes; provider failure has support reference/escalation | Password setup and help page exist; verified lost-factor recovery/provider status pending | | T04 — Help someone who cannot sign in | Identify affected tenant/account; distinguish password, OTP, membership, and outage; give safe recovery step | No access to passwords, OTP seed or current codes; provider failure has support reference/escalation | P04 recovery and provider status implemented/deployed; tenant admins escalate to authorized platform recovery; real-person lost-factor acceptance remains USER-WP-0028-T03 |
| T05 — Grant/change/revoke application access | Review exact tenant/application/role; apply authorized change; confirm effective result | Policy denial or stale version explains reason and refresh; no silent broad grant | Service capabilities vary; consolidated browser application-access management pending | | T05 — Grant/change/revoke application access | Review exact tenant/application/role; apply authorized change; confirm effective result | Policy denial or stale version explains reason and refresh; no silent broad grant | Service capabilities vary; consolidated browser application-access management pending |
| T06 — Suspend/reactivate/remove a tenant account | Confirm target and scope; show resulting state and whether access propagation is pending | Stale or failed operation leaves truthful state; retry after readback; shared identity in other tenants preserved | Existing lifecycle routes; confirmation/propagation UX and cross-tenant browser drills pending | | T06 — Suspend/reactivate/remove a tenant account | Confirm target and scope; show resulting state and whether access propagation is pending | Stale or failed operation leaves truthful state; retry after readback; shared identity in other tenants preserved | Existing lifecycle routes; confirmation/propagation UX and cross-tenant browser drills pending |
| T07 — Track incomplete onboarding | See invited, identity missing, password pending, OTP problem, and access denied as distinct actionable states | Stale/unknown provider state is labelled; administrator gets the correct owner/action | Headless diagnostics exist; consolidated browser status and retry workflow pending | | T07 — Track incomplete onboarding | See invited, identity missing, password pending, OTP problem, and access denied as distinct actionable states | Stale/unknown provider state is labelled; administrator gets the correct owner/action | Headless diagnostics exist; consolidated browser status and retry workflow pending |
@ -119,8 +119,9 @@ delivery readout, onboarding follow-up, tenant audit, and platform delivery retr
## Acceptance and remaining work ## Acceptance and remaining work
USER-WP-0027 tracks the matrix and role-based usability gaps. KEY-WP-0035 tracks USER-WP-0027 tracks the matrix and role-based usability gaps. KEY-WP-0035
OTP policy/provider rollout. USER-WP-0026 retains authoritative workload catalogue completed OTP policy/provider rollout; USER-WP-0028-T03 retains attended OTP
acceptance. Credential custody is no longer a blocker. USER-WP-0026 retains authoritative workload catalogue
work. Do not close these based solely on this document or a unit-test pass. work. Do not close these based solely on this document or a unit-test pass.
Run every journey with an ordinary member, tenant admin, and platform operator as Run every journey with an ordinary member, tenant admin, and platform operator as
@ -133,3 +134,11 @@ Automated portal coverage: test_account_clarity.py, test_account_recovery.py,
test_portal_navigation.py and existing test_web.py authorization/lifecycle tests. test_portal_navigation.py and existing test_web.py authorization/lifecycle tests.
Automated issuer coverage: KEY-WP-0035 optional MFA tests. Actual provider OTP, Automated issuer coverage: KEY-WP-0035 optional MFA tests. Actual provider OTP,
notification delivery and multi-user workload acceptance remain separate evidence. notification delivery and multi-user workload acceptance remain separate evidence.
September 27 reconciliation: the credential/policy deployment gate above passed
under RPF-WP-0040 and P06; it is still a prerequisite for any future handoff
configuration. KEY-WP-0034 and the September 24 attended receipt close the prior
account-switch wait. Mail infrastructure is available, but provider setup-link
delivery and invited-person receipt remain USER-WP-0035-T02. See
[evidence review](evidence/2026-09-27-loose-ends-review.md) for the exact evidence
and remaining owner dependencies.

View file

@ -0,0 +1,42 @@
# Loose-end review — 2026-09-27
Reviewed all 37 workplan files: 32 finished and five active. No ready,
proposed, backlog or already-blocked workplans were present. The five open
workplans are now blocked; no task or workplan was created.
## Completed existing task
USER-WP-0026-T02 is done. The immutable release and anonymous browser evidence
in `railiance-apps/docs/evidence/2026-09-12-account-recovery-live.md` is now
supplemented by `key-cape/docs/evidence/2026-09-24-fresh-login-and-account-switch.md`.
The founder confirmed fresh login/account switching; issuer telemetry records
three fresh portal authentication/token-issuance sequences following an MFA
failure. KEY-WP-0034-T02 is also done. U10 now reflects this evidence.
Application JWTs may outlive provider logout. The receipt does not complete the
second-user/company-workflow pilot in VERGABE-WP-0019-T06.
## Remaining blockers
| Workplan / tasks | Current dependency and resumption condition |
| --- | --- |
| USER-WP-0026-T03, USER-WP-0028-T02 | Application/authorization owners must establish the supported workload catalogue, registered HTTPS entry points, identity/tenant/action mapping, authoritative decisions and scoped grant/revocation contract. Local application records, memberships and the PDP evaluator do not supply fleet admission. |
| USER-WP-0027-T04, USER-WP-0028-T03 | Attended real-user OTP enrollment, cancellation, replacement/lost-factor recovery and fresh-login acceptance; verified portal setup handoff. KEY-WP-0035 and RPF-WP-0040 already delivered credential custody, renewal and optional policy. P04/P06 prove the implementation using disposable installed-provider fixtures. NK-WP-0033's separate incident also closed on September 23. |
| USER-WP-0027-T06 | Full matrix depends on the preceding application/OTP work, setup-link delivery and VERGABE-WP-0019-T06 second-user/setup-to-workflow acceptance. |
| USER-WP-0034-T02 | FLEX-WP-0020 section 8 still waits for the renamed canonical checkout. `/home/worsch/access-engine` is absent; `/home/worsch/flex-auth/docs/iam-profile-consumption.md` exists. Keep the current source link until registration. |
| USER-WP-0035-T02 | The provider-owned password-setup link still needs a supported delivery handoff and intended-person receipt evidence. EMAIL-WP-0004 and P05 delivered the mail service; its invitation outbox adapter is not a setup-link delivery contract. |
The review corrects stale missing-credential and missing-mail-infrastructure
claims rather than requesting replacement secrets or rebuilding working provider
features. Existing tasks retain all remaining work. No production configuration
or real account was changed, and no email was sent.
## Validation
- `make test`: 264 tests run, eight optional integration skips, no failures;
layer conformance passed.
- `make test-journeys`: 66 tests passed, no skips. The report remains incomplete
for U02–U09, T02, T04 and T05; account switching U10 is no longer a blocker.
- `git diff --check`: passed.
Local tests validate the implementation and journey mappings. They do not
substitute for the external acceptance evidence listed above.

View file

@ -20,7 +20,7 @@
"test_web.PortalApplicationTests.test_expired_browser_session_and_provider_outage_fail_closed", "test_web.PortalApplicationTests.test_expired_browser_session_and_provider_outage_fail_closed",
"test_account_recovery.AccountRecoveryTests.test_failed_callback_has_clean_recovery_and_no_loop" "test_account_recovery.AccountRecoveryTests.test_failed_callback_has_clean_recovery_and_no_loop"
], ],
"remaining": "KEY-WP-0035: actual no-factor/enrolled login needs provider credential and policy rollout." "remaining": "Fresh application login was confirmed on 2026-09-24 (KeyCape fresh-login/account-switch receipt). VERGABE-WP-0019-T06 still owns second-user, setup-to-welcome and company-workflow acceptance."
}, },
{ {
"id": "U03", "id": "U03",
@ -48,7 +48,7 @@
"tests": [ "tests": [
"test_account_clarity.AccountClarityTests.test_otp_help_is_available_without_portal_login_and_never_claims_activation" "test_account_clarity.AccountClarityTests.test_otp_help_is_available_without_portal_login_and_never_claims_activation"
], ],
"remaining": "Portal boundary only. KEY-WP-0035 owns factor presence/AAL2 enforcement; live enrollment, cancel, replacement and lost-factor recovery await approved provider credential/contract." "remaining": "KEY-WP-0035/RPF-WP-0040 credential and optional-policy rollout are complete; P04/P06 installed-provider fixtures cover enrollment, cancellation, recovery/replacement and old-session MFA. USER-WP-0028-T03 retains attended real-user OTP acceptance and verified portal setup handoff."
}, },
{ {
"id": "U06", "id": "U06",
@ -57,7 +57,7 @@
"tests": [ "tests": [
"test_account_clarity.AccountClarityTests.test_otp_help_is_available_without_portal_login_and_never_claims_activation" "test_account_clarity.AccountClarityTests.test_otp_help_is_available_without_portal_login_and_never_claims_activation"
], ],
"remaining": "Portal boundary only. KEY-WP-0035 owns factor presence/AAL2 enforcement; live enrollment, cancel, replacement and lost-factor recovery await approved provider credential/contract." "remaining": "KEY-WP-0035/RPF-WP-0040 credential and optional-policy rollout are complete; P04/P06 installed-provider fixtures cover enrollment, cancellation, recovery/replacement and old-session MFA. USER-WP-0028-T03 retains attended real-user OTP acceptance and verified portal setup handoff."
}, },
{ {
"id": "U07", "id": "U07",
@ -66,7 +66,7 @@
"tests": [ "tests": [
"test_account_clarity.AccountClarityTests.test_otp_help_is_available_without_portal_login_and_never_claims_activation" "test_account_clarity.AccountClarityTests.test_otp_help_is_available_without_portal_login_and_never_claims_activation"
], ],
"remaining": "Portal boundary only. KEY-WP-0035 owns factor presence/AAL2 enforcement; live enrollment, cancel, replacement and lost-factor recovery await approved provider credential/contract." "remaining": "KEY-WP-0035/RPF-WP-0040 credential and optional-policy rollout are complete; P04/P06 installed-provider fixtures cover enrollment, cancellation, recovery/replacement and old-session MFA. USER-WP-0028-T03 retains attended real-user OTP acceptance and verified portal setup handoff."
}, },
{ {
"id": "U08", "id": "U08",
@ -75,12 +75,12 @@
"tests": [ "tests": [
"test_account_clarity.AccountClarityTests.test_otp_help_is_available_without_portal_login_and_never_claims_activation" "test_account_clarity.AccountClarityTests.test_otp_help_is_available_without_portal_login_and_never_claims_activation"
], ],
"remaining": "Portal boundary only. KEY-WP-0035 owns factor presence/AAL2 enforcement; live enrollment, cancel, replacement and lost-factor recovery await approved provider credential/contract." "remaining": "KEY-WP-0035/RPF-WP-0040 credential and optional-policy rollout are complete; P04/P06 installed-provider fixtures cover enrollment, cancellation, recovery/replacement and old-session MFA. USER-WP-0028-T03 retains attended real-user OTP acceptance and verified portal setup handoff."
}, },
{ {
"id": "U09", "id": "U09",
"role": "user", "role": "user",
"implementation": "partial", "implementation": "external-blocked",
"tests": [ "tests": [
"test_account_recovery.AccountRecoveryTests.test_account_workload_list_is_scoped_to_current_user", "test_account_recovery.AccountRecoveryTests.test_account_workload_list_is_scoped_to_current_user",
"test_account_awareness.AccountAwarenessTests.test_token_tenant_without_membership_is_active_and_not_allowed", "test_account_awareness.AccountAwarenessTests.test_token_tenant_without_membership_is_active_and_not_allowed",
@ -88,17 +88,17 @@
"test_account_awareness.AccountAwarenessTests.test_recorded_workload_stays_allowed_and_unchecked", "test_account_awareness.AccountAwarenessTests.test_recorded_workload_stays_allowed_and_unchecked",
"test_account_awareness.AccountAwarenessTests.test_exception_role_shows_every_tenant_the_sign_in_lists" "test_account_awareness.AccountAwarenessTests.test_exception_role_shows_every_tenant_the_sign_in_lists"
], ],
"remaining": "USER-WP-0036 shows login state, the active sign-in, and allowed memberships. USER-WP-0028-T02/USER-WP-0026-T03 still own authoritative allow, deny, and unavailable workload decisions." "remaining": "USER-WP-0036 shows login state, the active sign-in, and allowed memberships. USER-WP-0028-T02/USER-WP-0026-T03 still own authoritative allow, deny, and unavailable workload decisions. Integration waits on an owner-supported workload catalogue/admission and scoped grant/revocation contract; membership is not effective authorization."
}, },
{ {
"id": "U10", "id": "U10",
"role": "user", "role": "user",
"implementation": "external-blocked", "implementation": "implemented",
"tests": [ "tests": [
"test_account_clarity.AccountClarityTests.test_wrong_shared_identity_recovery_does_not_claim_a_known_session", "test_account_clarity.AccountClarityTests.test_wrong_shared_identity_recovery_does_not_claim_a_known_session",
"test_portal_navigation.PortalNavigationTests.test_navigation_does_not_leak_between_operator_member_and_anonymous" "test_portal_navigation.PortalNavigationTests.test_navigation_does_not_leak_between_operator_member_and_anonymous"
], ],
"remaining": "Authenticated multi-identity/tenant switching must be verified against live issuer." "remaining": "Account switching confirmed by the founder and fresh portal issuer sequences on 2026-09-24; see key-cape/docs/evidence/2026-09-24-fresh-login-and-account-switch.md and USER-WP-0026-T02. Application sessions may outlive provider logout; multi-user workload acceptance remains VERGABE-WP-0019-T06."
}, },
{ {
"id": "U11", "id": "U11",
@ -170,16 +170,16 @@
"test_journey_roles.UserJourneys.test_password_handoff_names_actual_login_and_failure_can_retry", "test_journey_roles.UserJourneys.test_password_handoff_names_actual_login_and_failure_can_retry",
"test_journey_roles.TenantAdminJourneys.test_provider_failure_retains_local_state_and_retry_recovers" "test_journey_roles.TenantAdminJourneys.test_provider_failure_retains_local_state_and_retry_recovers"
], ],
"remaining": "Provider-owned lost-factor recovery still unverified; password setup assistance is supported." "remaining": "P04 recovery and provider status are implemented and deployed, with installed-provider fixture evidence. Real-person lost-factor recovery remains USER-WP-0028-T03; tenant administrators must use the authorized platform recovery path."
}, },
{ {
"id": "T05", "id": "T05",
"role": "tenant_admin", "role": "tenant_admin",
"implementation": "partial", "implementation": "external-blocked",
"tests": [ "tests": [
"test_journey_roles.TenantAdminJourneys.test_invalid_role_cannot_create_partial_account" "test_journey_roles.TenantAdminJourneys.test_invalid_role_cannot_create_partial_account"
], ],
"remaining": "Tenant roles are managed; authoritative application-specific grant/revoke integration remains USER-WP-0028-T02." "remaining": "Tenant roles are managed; authoritative application-specific grant/revoke integration remains USER-WP-0028-T02. Integration waits on an owner-supported workload catalogue/admission and scoped grant/revocation contract; membership is not effective authorization."
}, },
{ {
"id": "T06", "id": "T06",

View file

@ -4,12 +4,12 @@ type: workplan
title: "Account recovery and visible identity and access" title: "Account recovery and visible identity and access"
domain: communication domain: communication
repo: user-engine repo: user-engine
status: active status: blocked
flavor: implementation flavor: implementation
owner: codex owner: codex
topic_slug: user-engine topic_slug: user-engine
created: "2026-09-12" created: "2026-09-12"
updated: "2026-09-12" updated: "2026-09-27"
state_hub_workstream_id: "0aea0a52-13f9-515b-bda8-665f8a4f2d5e" state_hub_workstream_id: "0aea0a52-13f9-515b-bda8-665f8a4f2d5e"
--- ---
@ -37,7 +37,7 @@ MFA downgrade, global JWT revocation claim or inferred workload entitlements.
```task ```task
id: USER-WP-0026-T02 id: USER-WP-0026-T02
status: progress status: done
priority: high priority: high
state_hub_task_id: "ad5b0a77-d8ec-5e07-9a9e-2fa231a6f792" state_hub_task_id: "ad5b0a77-d8ec-5e07-9a9e-2fa231a6f792"
``` ```
@ -49,11 +49,19 @@ logout. Related: USER-WP-0025-T03 and VERGABE-WP-0019-T06.
Source verification: 182 tests passed with three optional integration skips; layer conformance passed. Immutable publication and live checks are in progress. Source verification: 182 tests passed with three optional integration skips; layer conformance passed. Immutable publication and live checks are in progress.
2026-09-27: closed against the completed release and attended owner evidence.
The 2026-09-12 release receipt is supplemented by
`key-cape/docs/evidence/2026-09-24-fresh-login-and-account-switch.md`:
the founder confirmed fresh login and account switching, and the issuer recorded
three fresh portal authentication/token-issuance sequences after an MFA failure.
KEY-WP-0034-T02 is done. Existing application JWTs may still outlive provider
logout. This does not accept the remaining multi-user Vergabe pilot.
## Discover workload access from authoritative application records ## Discover workload access from authoritative application records
```task ```task
id: USER-WP-0026-T03 id: USER-WP-0026-T03
status: todo status: wait
priority: high priority: high
state_hub_task_id: "95e9a6d4-7e57-5483-97c5-3f4a45bb6767" state_hub_task_id: "95e9a6d4-7e57-5483-97c5-3f4a45bb6767"
``` ```
@ -74,3 +82,11 @@ checks and six fresh anonymous Chromium checks pass, including actual provider
logout POST and return to the portal without test overrides. Real-user identity logout POST and return to the portal without test overrides. Real-user identity
switching is still awaiting operator evidence; no authenticated/MFA acceptance switching is still awaiting operator evidence; no authenticated/MFA acceptance
is inferred. Detailed receipt: railiance-apps/docs/evidence/2026-09-12-account-recovery-live.md. is inferred. Detailed receipt: railiance-apps/docs/evidence/2026-09-12-account-recovery-live.md.
2026-09-27: blocked on an owner-supported workload catalogue/admission and
scoped grant/revocation contract. The access-engine policy evaluator and local
user-engine application/membership records do not establish that contract.
Need registered HTTPS entry points, exact identity/tenant/action mapping,
authoritative allow/deny/unavailable results, and scoped mutation/readback
semantics from the application and authorization owners. Continues jointly with
USER-WP-0028-T02; no local grant inference or substitute catalogue was added.

View file

@ -4,12 +4,12 @@ type: workplan
title: "Clear account state and complete user, tenant-admin and platform-admin journeys" title: "Clear account state and complete user, tenant-admin and platform-admin journeys"
domain: communication domain: communication
repo: user-engine repo: user-engine
status: active status: blocked
flavor: implementation flavor: implementation
owner: codex owner: codex
topic_slug: communication topic_slug: communication
created: "2026-09-13" created: "2026-09-13"
updated: "2026-09-22" updated: "2026-09-27"
state_hub_workstream_id: "455300ca-ec1e-569e-a584-a8dcda2595cf" state_hub_workstream_id: "455300ca-ec1e-569e-a584-a8dcda2595cf"
--- ---
@ -76,6 +76,18 @@ recovery and fresh login; resolve privileged portal policy. Only then configure
USER_ENGINE_MFA_MANAGEMENT_URL and accept U05–U08/P04–P06. Do not fake a status from USER_ENGINE_MFA_MANAGEMENT_URL and accept U05–U08/P04–P06. Do not fake a status from
assurance claims, redirect return parameters or manual step completion. assurance claims, redirect return parameters or manual step completion.
2026-09-27: the missing credential/policy blocker above is superseded.
KEY-WP-0035 finished on September 14; RPF-WP-0040 delivered the renewable
factor-reader lane. NK-WP-0033 closed its separate historical incident on
September 23. P04 recovery and P06 optional policy are implemented and deployed;
see `docs/evidence/2026-09-13-p04-recovery.md` and
`docs/evidence/2026-09-13-p06-authentication-policy.md`.
Installed-provider fixtures prove activation, cancellation, old-session MFA and
recovery/replacement; they do not prove a real invited person's full OTP journey.
Remaining gate: attended U05–U08 enrollment/cancel/replacement/lost-factor and
fresh-login acceptance, plus verified portal setup handoff configuration. No new
credential request is required to resolve the historical blocker.
## Close tenant and platform administrator usability gaps ## Close tenant and platform administrator usability gaps
```task ```task
@ -103,7 +115,7 @@ It does not accept those journeys.
```task ```task
id: USER-WP-0027-T06 id: USER-WP-0027-T06
status: progress status: wait
priority: high priority: high
state_hub_task_id: "550886ca-f916-5637-9639-b4134b0da939" state_hub_task_id: "550886ca-f916-5637-9639-b4134b0da939"
``` ```
@ -120,3 +132,11 @@ USER-WP-0030 (platform admin), and USER-WP-0031 (automated acceptance). These
are live workplans, not residuals parked only in the journey document. are live workplans, not residuals parked only in the journey document.
Implemented admin journeys and automated suites are deployed; see docs/evidence/2026-09-13-journey-release.md and its machine-readable report. Full acceptance remains incomplete for the named integration/provider gaps. Implemented admin journeys and automated suites are deployed; see docs/evidence/2026-09-13-journey-release.md and its machine-readable report. Full acceptance remains incomplete for the named integration/provider gaps.
2026-09-27: blocked on the remaining acceptance dependencies, not ongoing
local implementation. USER-WP-0026-T02 now closes account-switch verification.
USER-WP-0035-T02 retains setup-link delivery; USER-WP-0028-T03 retains actual
OTP journeys; USER-WP-0026-T03/USER-WP-0028-T02 retain authoritative workload
access. VERGABE-WP-0019-T06 still needs the second user and setup-to-workflow
acceptance. Automated coverage remains an implementation check, not full live
acceptance. See `docs/evidence/2026-09-27-loose-ends-review.md`.

View file

@ -4,12 +4,12 @@ type: workplan
title: "User account journeys and recovery" title: "User account journeys and recovery"
domain: communication domain: communication
repo: user-engine repo: user-engine
status: active status: blocked
flavor: implementation flavor: implementation
owner: codex owner: codex
topic_slug: communication topic_slug: communication
created: "2026-09-13" created: "2026-09-13"
updated: "2026-09-13" updated: "2026-09-27"
state_hub_workstream_id: "145df9d5-a7e9-5d20-8280-9d3ea069838b" state_hub_workstream_id: "145df9d5-a7e9-5d20-8280-9d3ea069838b"
--- ---
@ -31,13 +31,19 @@ U01–U04/U10–U13: preserve safe profile input on validation failure; confirm
```task ```task
id: USER-WP-0028-T02 id: USER-WP-0028-T02
status: todo status: wait
priority: high priority: high
state_hub_task_id: "5d1bf977-034d-5448-b4fb-5a8b630af6ba" state_hub_task_id: "5d1bf977-034d-5448-b4fb-5a8b630af6ba"
``` ```
U09 and T05: integrate a supported catalogue/admission source and scoped grants/revocation. Do not present static links or membership as effective authorization. Continues USER-WP-0026-T03; establish provider contract before deployment. U09 and T05: integrate a supported catalogue/admission source and scoped grants/revocation. Do not present static links or membership as effective authorization. Continues USER-WP-0026-T03; establish provider contract before deployment.
2026-09-27: blocked on the provider-owned catalogue/admission and scoped
application grant/revocation contract described in USER-WP-0026-T03. Current
membership CRUD and PDP evaluation cannot supply fleet-wide admission or mutate
application-owned grants. Resume integration after owners identify the supported
source, entry-point registry, identity/action mapping and mutation contract.
## Complete optional OTP onboarding with provider evidence ## Complete optional OTP onboarding with provider evidence
```task ```task
@ -54,3 +60,11 @@ Validation: 210 database-enabled regression tests passed with no skips,
including independent-connection last-admin protection and nested bootstrap including independent-connection last-admin protection and nested bootstrap
rollback. Thirteen isolated Chromium checks passed. Provider OTP and application rollback. Thirteen isolated Chromium checks passed. Provider OTP and application
access integration remain explicitly open; no complete-journey claim is inferred. access integration remain explicitly open; no complete-journey claim is inferred.
2026-09-27: credential custody and optional-policy rollout are complete
(KEY-WP-0035, RPF-WP-0040); NK-WP-0033 is also finished. The earlier missing-
credential dependency is superseded. P04/P06 installed-provider evidence covers
enrollment/cancellation, recovery/replacement and old-session enforcement.
The remaining blocker is attended real-user U05–U08 acceptance and verified
portal setup handoff, not another service token. See USER-WP-0027-T04 and
`docs/evidence/2026-09-13-p06-authentication-policy.md`.

View file

@ -4,12 +4,12 @@ type: workplan
title: "Follow the flex-auth to access-engine repository rename (FLEX-WP-0020 handoff)" title: "Follow the flex-auth to access-engine repository rename (FLEX-WP-0020 handoff)"
domain: communication domain: communication
repo: user-engine repo: user-engine
status: active status: blocked
flavor: implementation flavor: implementation
owner: claude-code owner: claude-code
topic_slug: user-engine topic_slug: user-engine
created: "2026-09-22" created: "2026-09-22"
updated: "2026-09-22" updated: "2026-09-27"
related: [FLEX-WP-0020] related: [FLEX-WP-0020]
state_hub_workstream_id: "0b948be1-ad75-5548-b4eb-aabc8e3ae6cc" state_hub_workstream_id: "0b948be1-ad75-5548-b4eb-aabc8e3ae6cc"
--- ---
@ -53,3 +53,9 @@ registered. Then change `wiki/ArchitectureBlueprint.md:14` from
access-engine path, confirm the target file exists there, and reply on the access-engine path, confirm the target file exists there, and reply on the
FLEX-WP-0020 handoff thread with the commit. Leave historical workplans and FLEX-WP-0020 handoff thread with the commit. Leave historical workplans and
evidence unchanged. evidence unchanged.
2026-09-27: rechecked the owner workplan and filesystem. FLEX-WP-0020 §8
remains wait; `/home/worsch/access-engine` does not exist, while
`/home/worsch/flex-auth/docs/iam-profile-consumption.md` remains present.
The existing reference is still correct. Blocked until the renamed canonical
checkout is registered; runtime vocabulary remains unchanged.

View file

@ -4,12 +4,12 @@ type: workplan
title: "Onboarding handoff findings from the 2026-09-23 operator run" title: "Onboarding handoff findings from the 2026-09-23 operator run"
domain: communication domain: communication
repo: user-engine repo: user-engine
status: active status: blocked
flavor: implementation flavor: implementation
owner: claude-code owner: claude-code
topic_slug: user-engine topic_slug: user-engine
created: "2026-09-23" created: "2026-09-23"
updated: "2026-09-23" updated: "2026-09-27"
related: [USER-WP-0027, USER-WP-0028, NK-WP-0036, NK-WP-0041] related: [USER-WP-0027, USER-WP-0028, NK-WP-0036, NK-WP-0041]
state_hub_workstream_id: "35aa6adf-255a-5705-9294-a50d98e45f00" state_hub_workstream_id: "35aa6adf-255a-5705-9294-a50d98e45f00"
--- ---
@ -60,3 +60,12 @@ governed transactional mail lane (`email-connect` plus the OpenBao delivery
token) that SCOPE records as operator-owned; U04 and T02 in token) that SCOPE records as operator-owned; U04 and T02 in
`tests/journey-coverage.json` stay `external-blocked` until then. Do not `tests/journey-coverage.json` stay `external-blocked` until then. Do not
substitute a portal-rendered link for delivery evidence. substitute a portal-rendered link for delivery evidence.
2026-09-27: the generic missing-mail-lane description above is superseded
by EMAIL-WP-0004 and USER-WP-0032/P05: the authenticated mail lane exists and
live non-sending SMTP/store checks passed. That adapter handles invitation
outbox events, not the provider's single-use password-setup link. Closing this
task still needs an owner-supported setup-link delivery handoff and evidence of
receipt by the intended person; a generic SMTP success is insufficient.
The latest attended onboarding record still uses out-of-band handoff. No message
was sent and no setup-link secret was copied into an event or work record.