internal
Contract adopted
The current account surface is the bootstrap host; Plumage becomes standalone only after the HTTP contract has soaked.
Open surface ->
Access controlled Identity assurance and access context for people, agents, sessions, credentials, and platform grants.
Plumage establishes and verifies identity, then supplies session, service-credential, delegation, and platform-grant context. Products retain their own domain permissions and decide what an identified actor may do.
Plumage records operational evidence about its own identity decisions, but general provenance is not its product. It still bootstraps inside O+K while callers move onto the contract client ahead of a standalone identity data split.
This project has a launch path ready.