Runtime Phase 1 implementation: /runtime/admin-control-plane/ — role registry + masking + assist/view-as + approval queue + audit event model (spec live · enforcement not bound).
Runtime Phase 2a · Policy Engine Service: /runtime/admin-control-plane-service/ — HTTP boundary · 7 endpoints (access · mask · assist · viewas · sensitive · batch · health) · 24/24 canonical examples pass · decision-only · dev-mode (no JWT · no WORM sink · no admin UI yet).
Runtime Phase 2b: /runtime/admin-control-plane-service/phase-2b.html — additive · Bearer JWT resolver + file-backed approval store (8 rows) + TTL enforcement + audit sink BOUNDARY (
POST /api/policy/audit/preview) · parity 24/24 preserved · rationale at admin-control-plane-phase-2b.html (still dev-mode · no JWKS · no Postgres · no Kafka · no mutation).