approval-engine/docs/audit-source-registration.md
tegwick b46b0f2666 docs(admission): resolve approval audit tenant and redaction inputs
Assistant: codex
Assistant-Model: gpt-5.6-luna
Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
2026-09-08 17:01:42 +02:00

2.1 KiB

Platform approval audit sender

Source return for APPROVAL-WP-0002-T01/T04 and AUDIT-WP-0009-T09, 2026-09-08. This records the existing platform store's required registration; it neither provisions a credential nor admits another tenant.

Field Required value
Sender and permitted source approval-engine (exact)
Tenants ["tenant:platform"] (exact)
Write / read true / false
Evidence kind load-bearing
Completeness trade none
Secret policy redact
Consumer mount Secret approval-engine/approval-engine-audit, key audit-token

The accepted platform tenant decision is already implemented in the Engine default, production CLI and deployment arguments. The audit envelope carries that same store tenant without normalization. This is the tenant list Audit Core requested; neither platform, tenant:coulomb, nor * is required. A future store serving another tenant needs a separate registration review.

Choose redact explicitly: the receiver should retain a legitimate revocation record with an accidentally secret-shaped field removed, rather than reject the event and leave its delivery pending. Approval payloads must still contain no credentials. Redaction findings do not excuse a producer defect. Audit Core's scope overlay does not set this field; the protected sender registry entry must explicitly carry secret_policy: redact when provisioned.

The transactional outbox emits issuance, use, supersession and revocation; heartbeat uses the same durable drain. Its atomicity and retry contract remain in outbox-contract.md. Receiver identity/scope/ingress and credential admission precede live drain proof. Attestation freshness, omission detection and reconciliation retain their separate AUDIT-WP-0009-T02/T04/T06 owners and bounds; this registration does not claim their completion.

First provisioning still requires the platform-owned custody record linking the receiver's protected sender registry and this mounted credential. No credential value belongs in this document, Git, Hub or a rollout receipt.