{"actor_user_id_captured":false,"approved_external_account_path":"Workshop SSO","blockers":["workshop_sso_not_proven","tenant_boundary_not_proven","read_only_role_not_proven","session_runtime_missing","release_approval_missing"],"contract_hash":"9db08051fc05d237075279ead4ec2d7e35001ee8a9c1e614f1db07b9e2ec6e3f","counts":{"blocked_checks":4,"passed_checks":0,"required_checks":4,"required_claims":8},"customer_account_created":false,"customer_operates_peterman":false,"customer_self_service_allowed":false,"customer_surface_created":false,"customer_visible":false,"external_send_performed":false,"generated_at":"2026-09-26T16:09:22.989546+00:00","internal_use_only":true,"linked_audit_contract_hash":"b17e31fe62c13e138ef9f58217becd2734d8beb7286ac4b826397a3044cf3f27","next_action":"Use Workshop SSO as the approved external account path once provider details are supplied; keep Peterman internal-use only and do not expose customer visibility output until real Workshop SSO, tenant, read-only role, release approval, redaction review, and audit binding are proved.","operator_gate":"identity_tenant_contract_only_no_session_created","pii_captured":false,"product":"Peterman","production_audit_log_written":false,"provider_details_available":false,"provider_wiring_performed":false,"read_only_role_proven":false,"release_ready":false,"request_id_captured":false,"required_checks":[{"id":"workshop_sso_session","label":"Workshop SSO session","proof_needed":"Signed-in Workshop session with non-secret user id and session expiry.","status":"missing"},{"id":"tenant_boundary","label":"Tenant boundary","proof_needed":"Tenant id matched to the approved customer surface and release approval.","status":"missing"},{"id":"read_only_role","label":"Read-only customer role","proof_needed":"Role check proves the customer can view only the approved read-only surface.","status":"missing"},{"id":"audit_context_binding","label":"Audit context binding","proof_needed":"Audit event can bind user id, tenant id, request id, route, and receipt hash without storing secrets.","status":"missing"}],"required_claims":["workshop_user_id","tenant_id","role","read_only_customer_role","session_id","session_expires_at","approved_surface_receipt_hash","release_approval_hash"],"secrets_captured":false,"session_cookie_created":false,"session_id_captured":false,"session_runtime_installed":false,"status":"local_workshop_identity_tenant_contract","tenant_boundary_proven":false,"tenant_id_captured":false,"workshop_sso_followon":{"approved_external_account_path":"Workshop SSO","current_truth":"Peterman stays internal-use only with local route guard and receipt trail as the active proof","customer_operates_peterman":false,"do_not_do_yet":["Do not create a new auth vendor or paid account","Do not request or store secrets in this slice","Do not let customers operate Peterman","Do not expose a read-only customer output until the signed-in Workshop session, tenant boundary, read-only role, audit binding, redaction review, and release approval are proved"],"follow_on_truth":"Workshop SSO is the approved external authenticated account path for approved read-only outputs, but provider details are not present in this repo slice","new_vendor_or_paid_account_required":false,"preserve_local_trails":true,"proof_needed_next":["Workshop SSO issuer or auth gateway URL","client/application identifier or approved local callback contract","redirect/callback path","non-secret user id claim","tenant id claim","read-only output entitlement claim","session expiry claim"],"provider_details_available":false,"provider_wiring_performed":false,"slice_date":"060626"},"workshop_sso_proven":false}
