Approve a production write
You are the second person. Nothing below runs unless your hardware key signs the challenge this origin issued for exactly this job — the API cannot issue one, and this page never computes one.
What you are approving
- envelope
- none presented — this link carries no
?envelope=parameter, so there is nothing to approve and nothing was authorized
Honest limit: your key signs the challenge, not this text. If both the API and this origin were compromised, the screen could describe one job while the challenge means another (FR-016). This origin is deployed separately, from its own repository, with credentials the API cannot write to, precisely so that lie requires two independent break-ins — but no screen can promise more than that.
Ceremony
Propose first, approve second — two taps, two challenges, never interchangeable: the stage is inside what your key signs. The proposer cannot approve their own promotion; present a different credential for each stage.
The enrol button exists for a localhost dry run against
python3 -m approve.verify. In production, approver credentials come from the
root-signed approver manifest (OD-11) and this button is absent.