Commit Graph
3 Commits
Author SHA1 Message Date
jochen 479b8fe72d Revised: the Anthropic licence manager is a module holding a seat, and the agent's configuration lives in its managed directory
The operator's directions, taken during review: the host is module-agnostic and never writes a
vendor's file or anything under a home; the controller has no part; a real licence manager doles out
the correct licence in every situation; it talks to the agent module on every node over the bus; the
seat is named for the vendor, since the agent is coupled to an Anthropic grant, not to "a model".

- ADR 0178 rewritten: `claude-licence-manager` holds the mesh seat `anthropic-licence-manager`, owns
  the licences, grants (encrypted with a key the vault made for it), bindings per touchpoint, usage
  and audit; one rotation source under a lease; tokens travel module to module sealed to each node's
  module key on request/reply, never as an event; the agent module alone writes what the agent reads;
  the exception to ADR 0113 stated and bounded. Dated mechanism notes on ADR 0050 and 0113.
- To-be 37 (new): the manager — its store, the two licence kinds, keeping a grant alive, the hand-over,
  who gets which licence with the predecessor's fallbacks, adoption with the identity guard, verbs.
- To-be 36 rewritten: the mesh's part of the agent's configuration lives in the agent's machine-wide
  managed directory (settings, tool servers, instruction file), owned whole by the module and written
  by its code; the home is found except the credentials file; the API-key licence through the
  key-helper writes nothing under the home; the console as a node-scoped provision; MCP servers as
  settings with an `mcp_configure` tool; the six predecessor files removed by the operator.
- Records 0169–0171 renumbered to 0176–0178 after main gained 0169–0175 today.
2026-10-02 16:54:48 +02:00
jschoubben 860d512e91 Accept ADR 0050 — model access is vendor-agnostic
Verified and ratified: model-access stays one vendor-blind provision; per-vendor
adapter keyed by licence.vendor (mirrors public-dns registrar providers); the
sealing-vs-central-rotation carve-out bounded to refreshable-grant vendors /
refresh token / manager node only. Status proposed -> accepted; index regenerated
(records + index checks pass); design doc note updated.

Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
2026-09-05 21:42:20 +02:00
jschoubben 3a9b47918d ADR 0050 (proposed) — model access is vendor-agnostic; amend 14-model-access
Turn the completed vendor-agnostic analysis into HQ design. The model-access
provision stays one vendor-blind interface (extends 0024/0027); the
vendor-specific lifecycle moves into a per-vendor adapter keyed by the licence's
`vendor` field, mirroring registrar-scoped public-dns providers (0044), named at
the consumer's real coupling per 0040.

The crux is the sealing-vs-central-rotation carve-out: for refreshable-grant
vendors only, the manager node holds the refresh token encrypted at rest (a
bounded, declared exception), access tokens sealed per holder, refresh stripped
on delivery. Static-key vendors keep full sealing.

Amend 03-DESIGN/01-to-be/14-model-access.md with the adapter generalisation as a
proposed section (prose + diagram, no code); regenerate the decision index.

Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
2026-09-05 13:43:01 +02:00