Adapt USER-WP-0021 and USER-WP-0023 to published policy-nexus contracts
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Build and Publish Container Image / build-and-push (push) Successful in 1m1s

IAM Profile v0.3 and Tenancy Posture v0.1 are now live on
policy.coulomb.social. Close the portal expansion workplan against those
documents, keep the flex-auth live A2 probe waiting, and forward optional
tenant_roles to flex-auth without authorizing from them locally.
This commit is contained in:
tegwick 2026-08-19 09:51:08 +02:00
parent 166788228d
commit f762161d84
13 changed files with 109 additions and 10 deletions

View file

@ -4,7 +4,7 @@ description: >
tenant, membership, profile, lifecycle, and evidence-facing context.
status: candidate
owner: codex
updated: "2026-06-05"
updated: "2026-08-19"
implements:
- identity-canon conceptual model as an implementation-facing domain facade
@ -25,9 +25,10 @@ produces:
- Access Grant or grant-like membership fact
consumes:
- NetKingdom IAM Profile claims
- NetKingdom IAM Profile v0.3 claims
- verified issuer and subject identifiers
- assurance and principal type claims
- optional tenant_roles forwarded to flex-auth only
- authorization decisions and obligations
- policy, control, review, exception, and evidence references
- lifecycle task references from downstream task systems