The n8n close-out: what it covers, what it excludes, and what authority the register carries
Date: 2026-08-16
Status: open
Supersedes: none — extends docs/decisions/2026-08-12-ptv-sr-0015-automation-plane-boundary.md
Superseded-by: none — current
Terminal state of this record: one measurement that refutes a fatal
invariant, one new register, two corrected instruments, and a queue of five
acts no agent may perform. It closes nothing in the estate.
Context
Section titled “Context”PTV-SR-0015 was ratified with an amendment reading materially conforming by
role, with three qualifications. The second qualification was that the write
refusal is inferred, never measured; the negative test was deferred to P5 as
F-11. PTV-CHK-0034, INV-3’s standing instrument and alert: page, has been
blocked since 2026-08-12.
Meanwhile three sibling apexes each held unclassified n8n items — mary-wiki runs the instance, devarno-cloud purged 22 of 24 workflows and owes a credential audit, arno-host has four workflows it decided to retire and never confirmed undeployed. Nobody had written those down in one place.
The operator directed this work to run before the P3 verification round, so the round would classify F-11 against a measured result rather than an inference.
What was done
Section titled “What was done”- F-11 was measured.
HAB_E2E_KEYcreated a workflow athab.so1.io(POST /api/v1/workflows→200) and deleted it with the same key (DELETE→200,GET→404). Recorded verbatim inPTV-FND-0028. INV-3 is refuted, not unproven. The key lists zero workflows, which reads as narrowing under any read-only probe — community edition scopes visibility by project ownership and does not scope capability by role at the public API. estate.yamlNG-01 —status:staysnon-conforming;evidence:was rewritten, because it asserted role-narrowing that is measured false. That divergence was the D-19 failure mode the non-governance block exists to prevent, and it happened to read in PETROVA’s favour.checks.yamlPTV-CHK-0034 — staysblocked.blocked_on:grew: three write-capable credentials, not two, and no read-only key is mintable on the present instance. The plan anticipated this shrinking on a refusal.docs/PETROVA-N8N-CLOSEOUT.md(PTV-AUT-0002) — sixteen rows across four apexes, each with an owner and a discharge condition.
What this deliberately excludes
Section titled “What this deliberately excludes”- Every credential act. Revocation, rotation, and
chmodare owner-only.hab.so1.iois one host serving three apexes; a credential act on it is an estate act, not a PETROVA one, and revoking either key may break mary-wiki’s SPUTNIK transport or devarno-cloud’spipeline-dispatch. That dependency is unverified and belongs to the apex owning each flow. - Any write to a sibling apex’s repository. The mary-wiki, devarno-cloud and arno-host rows are classification, not adoption.
- The P3 verification round and the instrument review preceding it
(
PTV-FND-0026input 1). Both stay queued, unchanged by this session. - The positive control. The plan called for a second write with
HAB_2_SOL_V4to distinguish a real refusal from a path error. The negative test did not refuse, and a200carrying a server-assignedidcannot be a path error, so the control would have added an unnecessary write to a shared production instance to prove what the result already establishes. Reasoning inPTV-FND-0028§2.
The register’s authority
Section titled “The register’s authority”PTV-AUT-0002 is status: proposed. FLIGHT ratifies; it proposes. It is a
companion to PTV-AUT-0001 and does not replace it, and PTV-AUT-0001 §0.1
remains the boundary law that binds both. The register confers no authority over
sibling apexes and creates no obligation on them; it records what PETROVA
observed so the items stop being invisible.
Consequence for P4
Section titled “Consequence for P4”docs/findings/20260811-2027-ptv-scf-0001-credential-scope.md:281 holds P4 until
a read-only n8n API key exists. PTV-FND-0028 establishes that none can be
minted on the present instance. P4 is therefore gated not on work but on a
ruling: enterprise scope model, separate instance, or a recorded permanent
exception (N8N-05).
Sign-off
Section titled “Sign-off”- Subagent: PTV-SCF-0001 P4 (session 2026-08-16)
- Human: FLIGHT<alex@devarno.com:2026-09-22> — that the measured refutation of INV-3 is accepted,
that
PTV-CHK-0034correctly staysblockedon a larger reason than before, thatPTV-AUT-0002’s sibling-apex rows are classification and not adoption, and that the five owner-only acts are acknowledged as outstanding