Joining the CAB
If an invitation email for the Change Advisory Board landed in your inbox, someone in your organization (the CAB chair) has added you to the board that reviews and authorizes sensitive changes in Churchill. See CAB overview.
Joining takes a few minutes in your browser: confirm you are the intended recipient, create a signing passkey, and, during initial setup, approve the genesis baseline. The passkey you create is both your signing key and your dashboard sign-in, so finishing this flow also gives you console access.
There are two variants of the flow, and the page shows the right one automatically:
- Genesis invitation, during initial CAB setup: three steps, ending with baseline approval.
- Post-seal invitation, when the chair admits you to an active board: two steps. There is no baseline to approve, and your registration completes the admission.
Before you start
Section titled “Before you start”- The link is yours alone. It carries your personal invitation, and it exists only in your email. Do not forward it.
- It expires after 7 days. If it has lapsed, ask your chair to resend the invitation.
- Only your newest link works. A resent invitation retires any earlier link, so always open the most recent email.
- Your private key never leaves your device. Churchill records only the public key and its fingerprint.
For a genesis invitation, you can close the page and reopen the link at any point. It resumes wherever you left off. A post-seal link is spent the moment your passkey registers.
Step 1: confirm your identity
Section titled “Step 1: confirm your identity”The page opens with the name, role, and email address your chair set for you. Check that this is you, then select Confirm identity.
If it is not you, select the Not you? link beside the identity card. It opens an email to the chair so they can correct the invitation. If you were not expecting an invitation at all, ignore it.
Step 2: create your signing passkey
Section titled “Step 2: create your signing passkey”Select Create passkey. Your device or browser prompts you to create a WebAuthn passkey. The device creates and holds the key. Only the public key and its fingerprint are registered with Churchill.
The page states the double duty in as many words: “This passkey is also your dashboard sign-in.” Once the CAB is active, you sign in to the console with this passkey. There is no password on the account.
If you were removed from the CAB and later re-invited, an authenticator that offers your old key is refused. Removed keys stay dead. Create a new passkey instead.
For a post-seal invitation, this step completes the flow. The page confirms “You’re on the Change Advisory Board.” and offers Go to sign-in. The remaining sections below apply to genesis invitations.
Step 3: approve the genesis baseline
Section titled “Step 3: approve the genesis baseline”The final step shows the canonical baseline: a sha256: hash over the full member roster, approved unanimously. Select View manifest to expand the roster your hash covers, with every member’s name and registration state.
Before you can approve, tick the acknowledgement: “I’ve verified the baseline hash and the {n}-member roster. I approve this baseline as {your name} and authorize my passkey to sign it.”
Then select Approve baseline & join CAB. Your device asks you to confirm with your passkey. The assertion signs a challenge the control plane builds over the genesis baseline, so you approve exactly the roster and hash the page shows.
If the roster changes after you approve
Section titled “If the roster changes after you approve”Approvals sign the current baseline hash. If another member registers a key after you approved, the hash changes and your earlier approval no longer counts. The page tells you plainly (“Approvals sign the current baseline hash.”) and asks you to approve the current baseline through the same link, with one more passkey confirmation. If the change lands at the exact moment you approve, the page fetches the fresh hash and asks again automatically.
After you approve
Section titled “After you approve”The page confirms your approval and shows a live tracker of the approvals. Genesis approval is unanimous, so every member must sign. The tracker updates on its own, and you can close the page at any time.
Once every member has approved, the chair seals the baseline, the CAB goes active, and your invitation link retires. Nothing more is needed from you.
If your link does not work
Section titled “If your link does not work”The page shows one of three cards instead of the steps:
- “This invite link has expired”: invitation links are time-limited. Ask your chair to resend your invitation. The new email carries a fresh link.
- “This invite link is no longer valid”: the link was revoked, replaced by a newer invitation email, or the ceremony is already complete. Ask your chair for a fresh invitation if you still need one.
- “This invitation has been retired”: you had already finished your part. Invitations retire when the chair seals the baseline, so if the ceremony completed, you are done. If the roster changed instead, your chair will be in touch.
What being a member means
Section titled “What being a member means”Once the baseline seals, you are a signing member of the board:
- You will be asked to sign again. Future change requests, such as new applications and re-baselines after authorized changes, need CAB approval, and your receipt is part of the quorum. See Approvals.
- Your fingerprint is on the roster. Your key’s fingerprint appears wherever the board’s membership is shown, including the sealed baseline manifest.
- You can sign in to the console. Your passkey is your dashboard sign-in as well as your signing key. Guard the device that holds it: it is your seat on the board.