A cross-repo trace showed nothing writes the provisioner's grant-request files, nothing reads its sealed credentials, and no consumer unseals — while the mesh already mints and delivers provider/consumer credentials asymmetrically with no shared key. The fix is to drop the symmetric seal and have providers consume the mesh-minted password, a breaking provider-contract change that wants an ADR. Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF