40 lines
2.1 KiB
Markdown
40 lines
2.1 KiB
Markdown
|
|
# Platform approval audit sender
|
||
|
|
|
||
|
|
Source return for `APPROVAL-WP-0002-T01/T04` and `AUDIT-WP-0009-T09`,
|
||
|
|
2026-09-08. This records the existing platform store's required registration;
|
||
|
|
it neither provisions a credential nor admits another tenant.
|
||
|
|
|
||
|
|
| Field | Required value |
|
||
|
|
| --- | --- |
|
||
|
|
| Sender and permitted source | `approval-engine` (exact) |
|
||
|
|
| Tenants | `["tenant:platform"]` (exact) |
|
||
|
|
| Write / read | `true` / `false` |
|
||
|
|
| Evidence kind | `load-bearing` |
|
||
|
|
| Completeness trade | none |
|
||
|
|
| Secret policy | `redact` |
|
||
|
|
| Consumer mount | Secret `approval-engine/approval-engine-audit`, key `audit-token` |
|
||
|
|
|
||
|
|
The accepted platform tenant decision is already implemented in the Engine
|
||
|
|
default, production CLI and deployment arguments. The audit envelope carries
|
||
|
|
that same store tenant without normalization. This is the tenant list Audit
|
||
|
|
Core requested; neither `platform`, `tenant:coulomb`, nor `*` is required.
|
||
|
|
A future store serving another tenant needs a separate registration review.
|
||
|
|
|
||
|
|
Choose `redact` explicitly: the receiver should retain a legitimate revocation
|
||
|
|
record with an accidentally secret-shaped field removed, rather than reject
|
||
|
|
the event and leave its delivery pending. Approval payloads must still contain
|
||
|
|
no credentials. Redaction findings do not excuse a producer defect.
|
||
|
|
Audit Core's scope overlay does not set this field; the protected sender
|
||
|
|
registry entry must explicitly carry `secret_policy: redact` when provisioned.
|
||
|
|
|
||
|
|
The transactional outbox emits issuance, use, supersession and revocation;
|
||
|
|
heartbeat uses the same durable drain. Its atomicity and retry contract remain
|
||
|
|
in [outbox-contract.md](outbox-contract.md). Receiver identity/scope/ingress and
|
||
|
|
credential admission precede live drain proof. Attestation freshness, omission
|
||
|
|
detection and reconciliation retain their separate AUDIT-WP-0009-T02/T04/T06
|
||
|
|
owners and bounds; this registration does not claim their completion.
|
||
|
|
|
||
|
|
First provisioning still requires the platform-owned custody record linking
|
||
|
|
the receiver's protected sender registry and this mounted credential. No
|
||
|
|
credential value belongs in this document, Git, Hub or a rollout receipt.
|