Operator ran into an extended, opaque troubleshooting session in
informed-decision: the decision overview uses a 12h MFA-freshness
window while opening a memo to review/approve uses a strict 900s
window, so the overview kept working while every review page silently
refused, with no session-status visibility and no logout affordance
in that app's UI to diagnose or recover from it.
Requests a reusable account/session-status component (identity,
assurance freshness, logout) that informed-decision, vergabe-teilnahme
and other consumer UIs can mount, built against user-engine's
identity/assurance model. Notes USER-WP-0036 as directly reusable
prior art, and flags -- as a remark, not a decision -- that the actual
component likely belongs in a distinct small repository rather than in
headless user-engine itself or vendored per consumer, to avoid
coupling every consumer's frontend build to user-engine's release
cycle.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: sonnet
Assistant-Process: 169987@bnt-lap001
Assistant-Session: 322ef1ef-9048-4021-8570-b6d6f6347999
Authelia rejects the cluster address. Keep the connection inside the cluster and name login.coulomb.social, which matches the session cookie domain.
Assistant: grok
Assistant-Session: 01a0d25d-d358-7e13-b84a-d007fbb7e34f
The account site said "Not signed in" while Authelia still had a session, and Sign in reused that identity. Ask Authelia who the session cookie is, show that name, and send a fresh sign-in only when a different identity is requested.
Assistant: grok
Assistant-Session: 01a0d25d-d358-7e13-b84a-d007fbb7e34f
Say "Signed in as" the identity, and describe a one-time code as a
higher security level of the NetKingdom sign-in rather than another
sign-in. The account site keeps its own session.
Assistant: grok
Assistant-Session: 01a0d25d-d358-7e13-b84a-d007fbb7e34f
Updated by fix-consistency on 2026-09-26:
- update .custodian-brief.md for user-engine
Assistant: grok
Assistant-Session: 01a0d25d-d358-7e13-b84a-d007fbb7e34f
USER-WP-0036 keeps the token tenant off the membership list and leaves workload decisions unchecked until the catalogue reports them.
Assistant: grok
Assistant-Session: 01a0d25d-d358-7e13-b84a-d007fbb7e34f
fix-consistency registered the account situational-awareness plan and its three tasks.
Assistant: grok
Assistant-Session: 01a0d25d-d358-7e13-b84a-d007fbb7e34f
Updated by fix-consistency on 2026-09-26:
- update .custodian-brief.md for user-engine
Assistant: grok
Assistant-Session: 01a0d25d-d358-7e13-b84a-d007fbb7e34f
The account page currently presents the token tenant as membership. This plan separates login state, active sign-in, and allowed memberships.
Assistant: grok
Assistant-Session: 01a0d25d-d358-7e13-b84a-d007fbb7e34f
Updated by fix-consistency on 2026-09-25:
- update .custodian-brief.md for user-engine
Assistant: grok
Assistant-Session: 01a0d25d-d358-7e13-b84a-d007fbb7e34f
Login name and sign-in address are now named at the handoff and in the
tenant-admin user entry. Setup-link delivery stays unresolved, so U04
remains external-blocked.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 58902@bnt-lap001
Assistant-Session: 7ac7f865-2dc5-4aa7-8eb7-27a342109c2f
Updated by fix-consistency on 2026-09-23:
- update .custodian-brief.md for user-engine
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 58902@bnt-lap001
Assistant-Session: 7ac7f865-2dc5-4aa7-8eb7-27a342109c2f
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 58902@bnt-lap001
Assistant-Session: 7ac7f865-2dc5-4aa7-8eb7-27a342109c2f
Updated by fix-consistency on 2026-09-23:
- update .custodian-brief.md for user-engine
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 58902@bnt-lap001
Assistant-Session: 7ac7f865-2dc5-4aa7-8eb7-27a342109c2f
From the 2026-09-23 operator run: recipients try the email address, and the
admin user entry gave no sign-in address to pass on.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 58902@bnt-lap001
Assistant-Session: 7ac7f865-2dc5-4aa7-8eb7-27a342109c2f
Updated by fix-consistency on 2026-09-22:
- update .custodian-brief.md for user-engine
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 58902@bnt-lap001
Assistant-Session: 7ac7f865-2dc5-4aa7-8eb7-27a342109c2f
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 58902@bnt-lap001
Assistant-Session: 7ac7f865-2dc5-4aa7-8eb7-27a342109c2f
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 58902@bnt-lap001
Assistant-Session: 7ac7f865-2dc5-4aa7-8eb7-27a342109c2f
Updated by fix-consistency on 2026-09-22:
- update .custodian-brief.md for user-engine
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 58902@bnt-lap001
Assistant-Session: 7ac7f865-2dc5-4aa7-8eb7-27a342109c2f
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 58902@bnt-lap001
Assistant-Session: 7ac7f865-2dc5-4aa7-8eb7-27a342109c2f
VALIDATED_AGAINST names v0.7 at net-kingdom@66dc491 as amended by
GH-DEC-2026-017/020/021 (gate-house@39d9287). The version detector adopts
ops-warden's estate reference: identity-bearing standard:/companion: values
carrying a version token are pins; keys naming neither are not reached.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 58902@bnt-lap001
Assistant-Session: 7ac7f865-2dc5-4aa7-8eb7-27a342109c2f
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 58902@bnt-lap001
Assistant-Session: 7ac7f865-2dc5-4aa7-8eb7-27a342109c2f
Updated by fix-consistency on 2026-09-22:
- update .custodian-brief.md for user-engine
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 58902@bnt-lap001
Assistant-Session: 7ac7f865-2dc5-4aa7-8eb7-27a342109c2f
Remaining T02/T04/T05 residuals are external and already owned by
USER-WP-0027-T04/T06 and USER-WP-0028-T02.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 58902@bnt-lap001
Assistant-Session: 7ac7f865-2dc5-4aa7-8eb7-27a342109c2f
INTENT.md's standard: path drops _v0.7.md; a version inside the path is a
standard version under A12 r2. The conformance checker now rejects a
version in any key or value of INTENT.md frontmatter and layer.yaml
(standard_version, companion_version, versioned standard/companion paths),
leaves schema_version and pep-stance.yaml alone, and prints VALIDATED_AGAINST
and SCOPE on every run, following kings-guard. Tests fail if a versioned
standard: path or companion_version returns.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
layer.yaml drops standard_version (A12) and is marked derived: true,
derived_from: INTENT.md (A11); INTENT.md frontmatter already carries the
governing layer: Engine and no standard_version. The checker changes in
the same commit: standard_version is no longer required and its presence
is now malformed, the derived marking is required, the layer is compared
against the closed four-token vocabulary after an ASCII fold (A9), and a
divergence between INTENT.md and layer.yaml that survives the fold is
reported. Nothing is re-spelled: Engine and engine both stand. The tests
assert the fold rather than equality. pep-stance.yaml is untouched.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
Set flavor on open workplans from origin/prose/status. Copy existing
depends_on aliases only. Do not promote residuals.
Assistant: grok
Assistant-Session: 01a09dc1-b21e-77e1-919e-fcad2f82b267