Approve a production write

You are the second person. Nothing below runs unless your hardware key signs the challenge this origin issued for exactly this job — the API cannot issue one, and this page never computes one.

What you are approving

envelope
none presented — this link carries no ?envelope= parameter, so there is nothing to approve and nothing was authorized

Honest limit: your key signs the challenge, not this text. If both the API and this origin were compromised, the screen could describe one job while the challenge means another (FR-016). This origin is deployed separately, from its own repository, with credentials the API cannot write to, precisely so that lie requires two independent break-ins — but no screen can promise more than that.

Ceremony

Propose first, approve second — two taps, two challenges, never interchangeable: the stage is inside what your key signs. The proposer cannot approve their own promotion; present a different credential for each stage.

The enrol button exists for a localhost dry run against python3 -m approve.verify. In production, approver credentials come from the root-signed approver manifest (OD-11) and this button is absent.