You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Foundation dependency: #87 (which builds on closed #86)
Outcome
Complete the production admin API after the owner approves production staff identity/break-glass behavior in #20 and final credential/high-risk controls in #28. #87 supplies the decision-free API-principal, Bearer credential, API convention, OpenAPI, rate, operation, and parity foundation with credential lifecycle adapters kept test-only and absent from runtime.
Register production credential create/rotate/revoke operations only after Decision: Confirm high-risk action approvals and reauthentication #28 defines the final high-risk catalog, authentication-freshness/API-equivalent evidence, explicit confirmation, replay/stale-revision behavior, and any dual-approval rule.
Finalize production credential administration, effective roles/scopes, retention/cleanup/monitoring, audit review, and operation/cancellation policy across Studio and admin API.
Approved Decision: Confirm high-risk action approvals and reauthentication #28 credential lifecycle policy is registered in production for create/rotate/revoke with exact scope/count/impact, fresh-authentication/API-equivalent evidence, confirmation, concurrency, idempotency, audit, cancellation, and any approved dual approval.
Every production management capability has exact Studio/admin-API permission, service, object/field policy, schema, concurrency/idempotency/rate, audit, and result parity.
Production credentials remain one-time/non-recoverable, bounded, revocable, monitored, retained/cleaned up per approved policy, and secret-free in every persistence/log/audit/artifact path.
Final OpenAPI 3.1 and resolver parity cover every production admin operation and contain no fixture/legacy-auth drift.
Full security, PostgreSQL concurrency, compatibility, accessibility, browser, operational, and production-identity acceptance suites pass.
Dependencies
Implementation/completion depends on #87, #20, and #28, plus #32 for the shared final Studio high-risk/identity controls. Domain operations depend on their owning services.
Delivery convention
Follow _docs/PROCESS.md. No production credential lifecycle route may be enabled merely because #87 closes; this issue requires fresh PM/QA acceptance after the owner decisions are resolved.
Parent epic: #7
Normative spec: 06 — Studio and admin API
Decision dependencies: #20, #28
Foundation dependency: #87 (which builds on closed #86)
Outcome
Complete the production admin API after the owner approves production staff identity/break-glass behavior in #20 and final credential/high-risk controls in #28. #87 supplies the decision-free API-principal, Bearer credential, API convention, OpenAPI, rate, operation, and parity foundation with credential lifecycle adapters kept test-only and absent from runtime.
Scope
Non-goals
Acceptance criteria
Dependencies
Implementation/completion depends on #87, #20, and #28, plus #32 for the shared final Studio high-risk/identity controls. Domain operations depend on their owning services.
Delivery convention
Follow
_docs/PROCESS.md. No production credential lifecycle route may be enabled merely because #87 closes; this issue requires fresh PM/QA acceptance after the owner decisions are resolved.