From e0aa5cff6ba3ace2924982506860409213ad3c45 Mon Sep 17 00:00:00 2001 From: tegwick Date: Sat, 12 Sep 2026 10:50:35 +0200 Subject: [PATCH] Record live rejected-login recovery verification Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c --- workplans/VERGABE-WP-0019-invited-company-pilot.md | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/workplans/VERGABE-WP-0019-invited-company-pilot.md b/workplans/VERGABE-WP-0019-invited-company-pilot.md index 92225db..a544261 100644 --- a/workplans/VERGABE-WP-0019-invited-company-pilot.md +++ b/workplans/VERGABE-WP-0019-invited-company-pilot.md @@ -285,3 +285,12 @@ tenant, principal, signature, CSRF and account-admission boundaries remain. Validation: 126 application tests passed using an isolated in-memory database. KEY-WP-0034 owns provider recovery/sign-out; USER-WP-0026 owns account visibility. Publication and attended live recovery verification are in progress. + +### Live recovery rollout — 2026-09-12 + +Recovery is deployed in KeyCape 4d8b8fe, User Engine e54b6ee and Vergabe c067993 +(Helm revision 3). All three are Ready. Six provider checks, eleven product +checks and six fresh anonymous Chromium checks pass, including actual provider +logout POST and return to the portal without test overrides. Real-user identity +switching is still awaiting operator evidence; no authenticated/MFA acceptance +is inferred. Detailed receipt: railiance-apps/docs/evidence/2026-09-12-account-recovery-live.md.