☰ Contents

Open Decisions

F verified factP decided planC open challenge

The one page to decide from. Every row waits for a named person; nothing here is a design question the wiki can settle for itself. A taken decision leaves this page and enters the decision register with the next D-number. State of 04.09.2026 — after D142. On 04.09.2026 Vladimir answered A-1–A-7 and B-1–B-5; they left this page as D120–D131 (register § 24). Later on 04.09.2026 he answered A-8, A-9 and A-10 too; they are D132–D134 (register § 25), and the developer-readiness contradictions that surfaced beside them are D135–D142. Nothing waits for a person.

A. Waiting for Vladimir

None open after 04.09.2026. A-1–A-7 (product configurator) became D120–D126 in the morning; A-8–A-10 in the afternoon:

# Was Became
A-8 name the tunnel via host D132 — there is no tunnel. Every connection is direct; CONNECTOR_SCOPES.route.kind ∈ {direct, unreachable}; a closed route is a specific network request, never a hop (Software Architecture § 10.3)
A-9 does an approved write shape expire D133 — yes, by default. P90D from approval (writes.shape_expiry_default); the approver may extend once by at most one day (writes.shape_extension_max); longer is a re-approval (Gating § 4)
A-10 two identity facts to confirm with the customer D134 — read from the estate, not asked. Authority issues one role claim per SRD_SYS.USER_ROLES row and registers clients in OIDC_APPLICATIONS; the six platform roles are LT_USER_ROLES rows Ablera adds; no directory request (Trust and Data § 3). What stays a customer conversation is the security owner's deliberate yes to the write and deploy roles when the first AISA_APPROVER row is created

B. Waiting for the customer or a third party

None open after 04.09.2026: B-1–B-5 were answered by Vladimir on the customer's and DevOps' behalf and are D127–D131 — the countersignature became a signed data-administration agreement (D127), the network request a rolling per-requirement process (D128), the SSH user the estate's deployment account (D129), the deploy-job shape a per-environment rule for a deployment agent (D130), the backup inventory and RPO confirmed (D131).

C. Not decisions — measurements and build items

The rest of what is open needs data, code or a first case rather than a person's judgement, and is tracked in the Challenges Register, which is generated from the wiki and carries the live class counts — they are not restated here, because a hand-maintained count drifts from the generated one (Home). The shape of it: class-A rows waiting on a measurement that can be taken (six of them the one reach probe from the QA host), class-C rows each naming the first event that closes it, and the class-D build items. Regenerated 04.09.2026 after D120–D142: the former class-B rows (A-9, A-10) and the via-host row (A-8) are answered and their C markers turned to P; the reach probe from the QA host remains — it now answers direct or unreachable per target, nothing else (D132). Two items that stood in the decision register's § 6 as needing attention were answered by the measurements of 02.09.2026: the sale-stage question (STAGING and PROD carry zero QT rows — Measurements § DB-1a) and what writes STATUS on the pricing-factor tables (nothing does; it is NULL on every factor row on all three customer environments — Measurements § DB-1c).