Proposed, not for auto-merge — this is your ratification checkpoint (ADR 0023). Drafted while you were away, from the deep claude/anthropic analysis you asked for.
The finding that shaped it: the vendor-agnostic licence layer already exists in mesh-control/internal/licences (licence(name, vendor, serves) + licence_holder(... sealed)). So this ADR is an additive generalisation, not a rebuild.
What 0050 decides:
model-access stays one consumer-facing, vendor-blind provision (extends 0024/0027); the vendor-specific lifecycle moves into a per-vendor adapter keyed by licence.vendor — Anthropic becomes one adapter, exactly as cloudflare-dns is one registrar for public-dns.
Adapter capabilities are optional (shape static-key|refreshable-grant, accept, refresh, identity, usage, deliver) so a static-key vendor implements almost nothing.
The crux — a bounded carve-out: a refreshable OAuth credential can't be both sealed-so-the-mesh-can't-read-it and centrally rotated. For refreshable-grant vendors only, the manager node holds the refresh token encrypted-at-rest (bounded three ways: refreshable-grant only, refresh token only, manager node only); static-key vendors — the majority — keep the full sealing guarantee. Rejected alternatives recorded.
vendor field (not "provider", to avoid the provider-pin clash); usage normalised to (licence, consumer, period, metric, value)+raw; explicit per-consumer binding, refuse-if-unchosen; Anthropic first, anthropic-api-key the proving static-key case.
Also amends 03-DESIGN/01-to-be/14-model-access.md with the generalisation (prose + diagram). Checks pass (index current; 50 records). Full analysis: CLAUDE-VENDOR-AGNOSTIC-ANALYSIS.md in the code workspace.
noxflow was skipped per your instruction (needs rethinking).
**Proposed, not for auto-merge — this is your ratification checkpoint (ADR 0023).** Drafted while you were away, from the deep claude/anthropic analysis you asked for.
**The finding that shaped it:** the vendor-agnostic licence layer *already exists* in `mesh-control/internal/licences` (`licence(name, vendor, serves)` + `licence_holder(... sealed)`). So this ADR is an *additive* generalisation, not a rebuild.
**What 0050 decides:**
- `model-access` stays one consumer-facing, **vendor-blind** provision (extends 0024/0027); the vendor-specific lifecycle moves into a per-vendor **adapter keyed by `licence.vendor`** — Anthropic becomes one adapter, exactly as `cloudflare-dns` is one registrar for `public-dns`.
- Adapter capabilities are optional (`shape` static-key|refreshable-grant, `accept`, `refresh`, `identity`, `usage`, `deliver`) so a static-key vendor implements almost nothing.
- **The crux — a bounded carve-out:** a refreshable OAuth credential can't be both sealed-so-the-mesh-can't-read-it *and* centrally rotated. For refreshable-grant vendors only, the manager node holds the refresh token encrypted-at-rest (bounded three ways: refreshable-grant only, refresh token only, manager node only); static-key vendors — the majority — keep the full sealing guarantee. Rejected alternatives recorded.
- `vendor` field (not "provider", to avoid the provider-pin clash); usage normalised to `(licence, consumer, period, metric, value)`+raw; explicit per-consumer binding, refuse-if-unchosen; Anthropic first, `anthropic-api-key` the proving static-key case.
Also amends `03-DESIGN/01-to-be/14-model-access.md` with the generalisation (prose + diagram). Checks pass (index current; 50 records). Full analysis: `CLAUDE-VENDOR-AGNOSTIC-ANALYSIS.md` in the code workspace.
**noxflow** was skipped per your instruction (needs rethinking).
https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
Turn the completed vendor-agnostic analysis into HQ design. The model-access
provision stays one vendor-blind interface (extends 0024/0027); the
vendor-specific lifecycle moves into a per-vendor adapter keyed by the licence's
`vendor` field, mirroring registrar-scoped public-dns providers (0044), named at
the consumer's real coupling per 0040.
The crux is the sealing-vs-central-rotation carve-out: for refreshable-grant
vendors only, the manager node holds the refresh token encrypted at rest (a
bounded, declared exception), access tokens sealed per holder, refresh stripped
on delivery. Static-key vendors keep full sealing.
Amend 03-DESIGN/01-to-be/14-model-access.md with the adapter generalisation as a
proposed section (prose + diagram, no code); regenerate the decision index.
Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Proposed, not for auto-merge — this is your ratification checkpoint (ADR 0023). Drafted while you were away, from the deep claude/anthropic analysis you asked for.
The finding that shaped it: the vendor-agnostic licence layer already exists in
mesh-control/internal/licences(licence(name, vendor, serves)+licence_holder(... sealed)). So this ADR is an additive generalisation, not a rebuild.What 0050 decides:
model-accessstays one consumer-facing, vendor-blind provision (extends 0024/0027); the vendor-specific lifecycle moves into a per-vendor adapter keyed bylicence.vendor— Anthropic becomes one adapter, exactly ascloudflare-dnsis one registrar forpublic-dns.shapestatic-key|refreshable-grant,accept,refresh,identity,usage,deliver) so a static-key vendor implements almost nothing.vendorfield (not "provider", to avoid the provider-pin clash); usage normalised to(licence, consumer, period, metric, value)+raw; explicit per-consumer binding, refuse-if-unchosen; Anthropic first,anthropic-api-keythe proving static-key case.Also amends
03-DESIGN/01-to-be/14-model-access.mdwith the generalisation (prose + diagram). Checks pass (index current; 50 records). Full analysis:CLAUDE-VENDOR-AGNOSTIC-ANALYSIS.mdin the code workspace.noxflow was skipped per your instruction (needs rethinking).
https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF