# session-ledger summaries rotated 2026-07-28 (GA-R4 rule 3 / F1 -- oldest-first)

Moved VERBATIM from `docs/session-ledger.md` at the skill-repackage session close, to
restore the 300-line cap (the live ledger reached 310 after that close summary was
written). This is the oldest still-live entry -- the 2026-07-26 D-137 post-close
addendum. It still points at its own archived full body; only the summary moved.
Status is in `docs/CURRENT-STATE.md` ONLY; this file is history.

## POST-CLOSE ADDENDUM 2026-07-26 -- D-137 ADOPTED (GA-R4; 07-18/07-21 addendum precedent)
- The 2026-07-25 close bookend landed early by design; this addendum records the work that
  followed it rather than re-opening the entry.
- Operator asked for a better mint/save method + "a durable rule ... so credentials aren't
  misplaced or lost". Committee review (5 lenses) run; the operator's own insight drove the
  design: a discovery sweep can NEVER detect a credential that was never minted -- absence
  is invisible to discovery -- so an expected-state credential MATRIX is the missing half.
- **D-137 ADOPTED 2026-07-26**, all five sub-rulings RULED individually (GA-R5, each pushed
  before the next was asked): enforcement = blocking in preflight; manifests DERIVED from
  the matrix; --remote bounded to declared locations; D-137 is the policy authority
  (SEC-009 demotes to a pointer); identity conflation FOLDED IN as the one-identity-one-
  principal invariant. (SUPERSEDED SAME-DAY: implementation was built, committee-audited and
  remediated later on 2026-07-26 -- see CURRENT-STATE, which is the status authority. This
  line is kept as the narrative record of where the session stood at the time.)
- Research: 3 read-only agents. Capture `docs/audit/creds-creation-points-20260725.md` --
  55 MINT sites, and **12 declared secrets have NO mint command anywhere** (`ssh-keygen`
  = ZERO hits repo-wide), plus three credential dirs outside the SEC-009 convention.
- **SEC-021/-022/-023 OPENED** (rows 16 -> 19): a consolidated dc0 credential ABSENT from
  its recorded location; two UNAUDITED shadow *-creds/ stores on the headend; sprawl-glob
  blind spots incl. a PREDICTED Stage-5 admin-openrc exposure. All logged-not-actioned.
- NEXT as recorded at the time: build per `docs/D-137-implementation-plan.md`. THAT HAPPENED
  in the same-day successor session (tiers 1-3 built, six-lens committee audit, remediation,
  preflight P5 wired, SEC-009 demoted). Current status: CURRENT-STATE only.
- Status ONLY in CURRENT-STATE.md. Detail: docs/archive/changelogs/changelog-20260725-maas-admin-recovery.md.

