For current work, start with the AUTH overview and cross-owner dependency contract. This document explains activation custody; historical sequences below do not restart completed work or create another contribution-permission system. The canonical authorization specification and typed runtime catalogue define the registered facts and availability. Verify the current typed registry when implementing rather than treating historical catalogue totals as an activation gate. TASK claim/start and its work-context operations now use canonical authority; that does not activate remaining planned submission, review or recovery operations.
Historical entry evidence is preserved in the original custody record.
This plan applies the merged WS-XINT-001 handoffs to AUTH. It distinguishes:
- feature/resource ownership: ART, REV, CON, project, task, submission, or checker code owns facts, guards, state, and hidden behavior;
- activation custody: one exact AUTH chunk owns
ActionOwner, evaluator integration, and theplannedtoactivetransition; and - transaction ownership: the request route or service command owns one commit after AUTH and all feature participants have staged their evidence and state.
Feature chunks never change availability. AUTH never invents feature facts or performs feature lifecycle mutations.
Trusted entry main after PR #140 contains 74 PermissionIds and 57 ActionIds:
nine active and 48 planned. AUTH-09A adds zero permissions and eight planned
actor/link/service actions, producing 74 PermissionIds and 65 ActionIds: nine
active and 56 planned. Of those planned rows, the same 25 ART actions and 19 REV
actions still carry historical feature-chunk owner values. The two later
custody-transfer chunks change only those owner values; their entry counts,
mappings, and availability must remain identical.
| AUTH activation chunk | Exact ActionIds and current availability |
|---|---|
WS-AUTH-001-ART-02D-INTERNAL |
Active: artifact.verification.execute, artifact.pending_work.scan, artifact.put_attempt.resolve |
WS-AUTH-001-ART-02D-OPERATOR |
Planned: artifact.binding.read, artifact.replica.read, artifact.receipt.read, artifact.verification_job.read, artifact.verification_job.retry, artifact.recovery_attempt.read, artifact.audit.read, operations.artifact_storage_admission.read |
WS-XINT-002-04B |
Active: artifact.guide_source.read |
WS-XINT-002-04A |
Active: artifact.guide_source.ingest |
WS-XINT-002-05A |
Active: artifact.submission_bundle.prepare; registry custody remains historical while replacement implementation chunk WS-ARCH-001-02G supplies the executable PREP boundary |
WS-XINT-002-06A |
Active: artifact.pre_submit.checker_input.materialize |
WS-AUTH-001-ART-05 |
Active on WS-ARCH-001-02H merge: artifact.submission.binding.create; only the fixed artifact-binding service may consume it |
WS-XINT-002-06B |
Planned: artifact.post_submit.checker_input.materialize, artifact.checker_output.write, artifact.checker_output.binding.create |
WS-XINT-002-07A |
Planned: artifact.review_packet.materialize only |
| Future REV-owned activation, not approved for v0.1 | Planned/unavailable: artifact.review_evidence.binding.create |
The table retains historical planning-custody labels, not a literal mapping
of every typed runtime ActionOwner. XINT-06B groups runtime
WS-AUTH-001-ART-06A post-submit materialization and
WS-AUTH-001-ART-06B output write/binding. ARCH-04D2 replaces that grouping for exact input/execute/finalize authority;
output write/bind remains unavailable for the current zero-output catalogue. ARCH-04B hidden input and ARCH-04B2 hidden output custody
and ARCH-04C hidden durable execution/results are delivered; ARCH-04D1 canonical terminal material custody is delivered; ARCH-04D2 exact service authority and ARCH-04E1A source-only facts/types are delivered. ARCH-04E1A adds no AUTH action, route or handler; ARCH-04B2 owns
fresh authority participants internally for each store, recovery and binding
phase; public requests carry selectors and byte sources, never PREP handles.
The CHECKERS zero-slot reservation reader is implemented. Output authority remains deny-only. Production materialization requires real
fixed-service AUTH/PREP and an exact current execution lease. Execute/finalize
use the fixed workstream.checker.post_submit identity and phase-specific receipts. Do not implement an additional XINT-06B lane.
ART-07A1 delivers metadata-only packet types without authority or a resolver. REV-03B normalized packet storage, REV-04A immutable Review source storage, REV-04B FinalAcceptance storage, CON-03C persistence, CON-07 participation and REV-04C hidden shared acceptance/TASK/CON composition are delivered. Hidden routing handlers ARCH-04E1B-B are next. Mandatory exact AUTH receipts, database complete-effect custody, shared audit/outbox and fulfillment-root custody, and both TASK-before- CHECKERS currentness races remain prerequisites of activation at ARCH-04E2-B.
Runtime owner WS-XINT-002-07 retains catalogue custody. The only approved
v0.1 availability transition is 07A packet materialization. Evidence binding
remains planned and unavailable pending a separate REV-owned intent.
WS-AUTH-001-ART-CUSTODY historically transferred 25 rows. WS-XINT-002-01
reconciles the live catalogue by removing the six unused multi-step upload rows
and registering three end-to-end bundle/review rows. The resulting 22 rows have
exact action cardinalities 3/8/2/1/1/1/1/3/1/1 in the table order above. The
OPERATOR suffix denotes only future activation custody; it grants no Operator
entitlement. Fourteen actions remain planned after the three ART foundation
service actions, artifact.guide_source.ingest, the two fixed-service guide
binding/read actions, artifact.submission_bundle.prepare, and fixed-service
artifact.submission.binding.create activate. The independently
gated artifact.verification_job.retry
remains planned and
cannot be activated by read/status proof. The historical transfer added no
migration because owner and availability are typed metadata. WS-XINT-002-01
historically reconciled PostgreSQL parity through migration 0036, now folded
into the v0.1 baseline. At that historical boundary, the closed registry contained
fifteen service identities: fourteen action-bearing identities with twenty-three
matrix memberships plus the target-only workstream.compensation.adapter.
AUTH-OUTBOX-01 registered the dispatcher; AUTH-OUTBOX-02 activates only its shared
delivery mechanics with exact phase audit custody. ARCH-03C1 separately registers
the assignment reconciler and its exact feature authority. The current registry
has seventeen identities, sixteen action-bearing identities and twenty-five
memberships. ARCH-03C2 completes atomic producer publication and the sole
assignment-invalidation handler registration with enforced prefork delivery.
CP01A registered four initially unavailable adapter-binding actions and CP01B
registered five initially unavailable ContributionPolicy actions; neither
changes fixed-service identity or matrix membership. CP01C corrects only the
unavailable adapter-binding resource facts before CP02. It does not change
catalogue custody, action identifiers, fixed-service identity, availability,
or matrix membership. CP03A establishes that target-only identity and owner
eligibility without a service-action matrix row; all four binding actions
were activated by CP03B. CP05 activates exactly the five policy actions for
human Finance Authority through explicit AUTH composition, retaining CP01B
registration custody. CP05A exposes the public human Finance policy routes;
fixed-service policy authority remains unavailable.
The canonical current planning table is
review_authorization_action_custody.md.
It supersedes the historical placeholder grouping below for future planning,
while leaving runtime ActionOwner, permission, mapping, and availability
unchanged until each exact XINT-003 activation wave.
| AUTH activation chunk | Exact planned ActionIds |
|---|---|
WS-AUTH-001-REV-05 |
review.queue.read, review.queue.inspect |
WS-AUTH-001-REV-06 |
review.claim, review.release, review.decline_preference, review.preference_expiry.run, review.lease_expiry.run |
WS-AUTH-001-REV-07 |
review.context.read, review.chain.read, review.finding_evidence.ingest |
WS-AUTH-001-REV-08 |
review.decision |
WS-AUTH-001-REV-09A |
review.finding_response_evidence.ingest |
WS-AUTH-001-REV-11 |
review.lease.force_release, review.queue.routing.override, review.queue.routing.correct, review.queue.close, review.reconcile.run |
WS-AUTH-001-REV-12 |
review.artifact_reference.reconcile, review.projection.rebuild |
WS-XINT-003-08A |
review.revision_context.repair, review.revision_obligation.close, review.revision_context.legacy_close |
WS-XINT-003-08B |
review.lifecycle.activation.manage |
WS-AUTH-001-REV-CUSTODY atomically transfers these 19 rows with exact owner
cardinalities 2/5/3/1/1/5/2 in the table order above. The seven historical
REV runtime owner values remain registered for those actions until their exact
activation waves replace them. It changes no mapping or availability and
adds no migration. All 19 actions remain planned and unavailable; these AUTH
custodian labels grant no reviewer, Operator, or service authority. The four
approved lifecycle actions remain planned and unavailable. The shared PREP
foundation is already complete; its existence grants no lifecycle authority.
The completed front-loaded readiness waves are:
| XINT-003 wave | AUTH-only result |
|---|---|
WS-XINT-003-02C |
Complete unavailable REV catalogue, four additive actions, six exact fixed-service identities, static matrix, and database parity |
WS-XINT-003-02D |
Complete typed fail-closed REV PREP/read integration contracts; no lifecycle behavior or availability change |
The exact activation-wave replacement is:
| XINT-003 wave | Registered planned REV ActionIds |
|---|---|
WS-XINT-003-03A |
review.queue.read |
WS-XINT-003-03B |
review.claim |
WS-XINT-003-03C |
review.release, review.decline_preference |
WS-XINT-003-03D |
review.preference_expiry.run, review.lease_expiry.run |
WS-XINT-003-04 |
review.context.read, review.chain.read |
WS-XINT-003-06 |
review.decision |
WS-XINT-003-07 |
No availability change; extend the already XINT-002-owned preparation/Submission evaluators with the closed human-review revision context |
WS-XINT-003-08A |
review.queue.inspect, review.lease.force_release, review.queue.routing.override, review.queue.routing.correct, review.queue.close, review.revision_context.repair, review.revision_obligation.close, review.revision_context.legacy_close |
WS-XINT-003-08B |
review.reconcile.run, review.artifact_reference.reconcile, review.projection.rebuild, review.lifecycle.activation.manage |
Evidence-upload actions remain future-intent-required and unavailable; they are not activated by 04 or 07. XINT-002-owned ART actions and shared submission actions are excluded.
The following values are registered planned runtime actions, not active authority:
| Registration chunk | Future activation chunk | Proposed ActionId -> PermissionId |
|---|---|---|
WS-XINT-003-02C |
WS-XINT-003-08A / WS-XINT-003-08B |
review.revision_context.repair -> project.task.manage; review.revision_context.legacy_close -> operations.reconcile.run; review.revision_obligation.close -> project.task.manage; review.lifecycle.activation.manage -> operations.reconcile.run |
WS-XINT-003-02C delivered availability-neutral AUTH readiness:
it registered these four actions and the exact fixed-service identities/matrix
before REV lifecycle implementation. WS-XINT-003-02D then published the
closed identifier/digest-based PREP/read contracts. Neither chunk loads or
implements REV lifecycle state, and the real kernel continues to deny every
unavailable action. REV later supplies canonical facts, guards, loaders,
composers, transaction revalidation, and hidden behavior; matching XINT waves
activate only after that integrated proof.
Registration requires typed plus PostgreSQL audit mapping parity. The migration
number was allocated from trusted main when 02C started. The registration migration
takes a writer-blocking downgrade lock and refuses without mutation when any
decision, audit, idempotency, or linked evidence references an added ActionId.
Its proof includes populated refusal, empty safe downgrade, re-upgrade, and
fresh replay.
Counts are derived from trusted main when a gate executes. REV registration
adds exactly four planned actions and zero active actions. WS-XINT-002-01
registers review-evidence binding under runtime owner WS-XINT-002-07; planned
and unavailable. It may remain named in the closed
workstream.artifact.binding static matrix, but 07A does not activate or extend
it. Any activation requires a separate approved REV-owned intent.
WS-AUTH-001-PREP delivered a session-bound, action-bound, opaque, single-use,
nonserializable prepared authority handle:
AUTH locks canonical current authority
-> feature locks its records
-> feature recomposes final typed facts
-> AUTH evaluates exactly once and stages decision evidence
-> feature participants flush
-> route or service command commits once
Reads retain AuthorizationService.require(). Mutations must not evaluate
against stale pre-lock facts or let dependency teardown commit shared state.
Every activation chunk requires an immutable merged feature SHA and exact
manifest containing its action list, resource composer, facts, guards, primary
surface declarations, transaction owner, revalidation proof, and real-kernel
action_unavailable proof before activation. The AUTH chunk then integrates
only those evaluators, changes only those actions to active, proves the exact
availability delta, and preserves all unrelated rows.
An activation entry in this map is a non-executable placeholder until that manifest exists. Its later preimplementation contract must enumerate exact allowed feature files, route/command and transaction tests, generated manifest delta, allow/deny/revalidation/rollback matrix, PostgreSQL concurrency cases, focused behavior regressions for every changed boundary, and the full backend suite with complete execution evidence. Coverage percentages are diagnostic, not activation or merge criteria. Generic “as applicable” proof or AUTH-only tests cannot authorize activation.
WS-ARCH-001-CP03 is split/non-executable. CP03A is the prerequisite executable
contract for the closed adapter target identity and real owner eligibility; it
activates no action. CP03B is the activation executable contract. CP02 provides
the immutable hidden feature manifest, transaction custody, recovery behavior,
and deny-default composition. After CP03A merges, CP03B may activate only:
compensation.adapter_binding.read
compensation.adapter_binding.create
compensation.adapter_binding.suspend
compensation.adapter_binding.resume
All four are active on CP03B merge. They admit only an active human Finance Authority covering the exact project, use the existing request-scoped read and opaque PREP protocols, add no service identity or route, and do not activate ContributionPolicy, retirement, fulfillment, callback, delivery, dispatcher, or reconciliation authority.
WS-AUTH-001-ART-02D-INTERNAL requires the exact merged ART-02C2 verification,
resolution, and scanner behavior plus ART-02C3 recovery/fencing foundations and
any ART-02D resource-composer dependency. ART-02D does not own the internal
behavior. Within WS-AUTH-001-ART-02D-OPERATOR,
artifact.verification_job.retry requires its own evaluator, guards, behavior
tests, and explicit availability assertion; passing the seven read/status cases
does not authorize retry.
Service actions use the exact fixed-service identities and closed matrix installed unavailable by 02C plus controlled canonical admission. REV does not need to publish hidden job behavior before those fail-closed identity contracts exist. REV later publishes exact timer, expiry, reconciliation, projection, artifact-reference, and release-control manifests before the matching action can become active. No catch-all review service exists.
review.decision additionally requires the merged flush-only CON participant
and one rollback-safe REV+CON transaction. Review-evidence binding additionally
requires ART and REV to define the in-process/service boundary, two independent
authorization decisions and evidence records, exact lock order, and one
transaction owner. Human authority cannot be silently converted into service
authority.
WS-AUTH-001-XINT planning reconciliation
-> repair and re-review PR #132 / AUTH-09A on trusted main
-> AUTH-09B -> 09C -> 09D -> 09E
-> WS-AUTH-001-ART-CUSTODY
-> WS-AUTH-001-REV-CUSTODY
-> WS-AUTH-001-PREP
-> AUTH-10 through AUTH-15 core cutovers
-> feature-gated registration and activation chunks as their manifests merge
-> AUTH-16 aggregate conformance and live proof
For ART dependencies, replace the generic final two steps with the exact WS-XINT-002 sequence: complete registration, prepared feature boundaries, fixed internal services, guide, submission, checker, review artifact access, and end-to-end conformance. AUTH-14 and AUTH-15 are not alternate activation paths.
Use the linked current cross-owner plan for remaining activation boundaries. Distinct initiatives may proceed concurrently in separate branches/worktrees. Serialize or rebase overlapping catalogue, matrix, composition and migration edits; do not impose a global single-active AUTH chunk rule. Hidden feature behavior stays unavailable until its exact activation is implemented and verified. Each PR uses the normal evidence, review and human merge workflow; planning records do not introduce an additional administrator checkpoint.
REV-12A1 provides
immutable disabled generation-zero storage and caller-root transaction locking.
It does not activate review.lifecycle.activation.manage or an acceptance writer.
AUTH's scalar activation contract binds its inherited phase to current_phase;
generation zero requires disabled. Those facts do not prove adjacency or grant
authority. Hidden AUTH preparation and nominal caller-session receipt projection
are delivered before CON-07
flush-only participant proof. Mandatory persisted source/FinalAcceptance custody
accompanies the first genuine allowed consequence at 04E2-B, before production
composition or consumption; no standalone allow is committed. Authorized
REV transitions and real obligation/cutoff proof remain required before live
shared acceptance, without requiring live human-review queues first.
ARCH-04E1B-A adds immutable TASK routing-request and future source-ID reservation, with caller-owned rollback and current-completion replay checks. It does not construct acceptance-source commitments or consume receipt-shaped values as AUTH evidence. ARCH-04E2-A strict preparation and nominal fixed-router adapter are delivered through canonical PREP, but the planned action denies before a handle or receipt exists. Persisted source projection, actual immutable AUTH-event/service-actor verification and atomic publication remain required before consequence activation.