"subject":"Live audit-core receiver on railiance01, restated in canon terms",
"note":"Joins reuse-surface id capability.audit.event-retain to ITC-CAP operations.audit. Maturity attaches to this provision, not the abstract capability. data.backup is cited, not restated.",
"requirement_note":"Production dependency for user-engine outbox delivery. D4 is the current ask; D5 would need measured integrity verification and actively controlled reliability."
},
{
"consumer":"audit-core.railiance01",
"capability":"data.archive",
"profile":"operational",
"requirement_note":"INTENT still wants unbounded WORM archive beyond the 30-day platform backup window. Unmet. Owner: audit-core to write a demand; resource-control to procure a different bucket/lifecycle than Barman. No provision is invented here."
}
],
"provisions":[
{
"provider":"audit-core.railiance01",
"capability":"operations.audit",
"profile":"administrative",
"environment":"production",
"maturity":"D4",
"implements":"HTTP POST /v1/events into append-only PostgreSQL on platform-pg, namespace audit-core, ClusterIP + default-deny",
"maturity_rationale":"Approved for production dependency since AUDIT-WP-0005. Not D5: one replica, reliability is not actively controlled. Integrity is measured (hash chain + verify + external head) but is not WORM.",
"note":"operations.audit does not declare depends_on data.transactional in the catalog. The live store is Postgres; this names which provision satisfies it."
"note":"Cite resource-control/data/capability/platform-audit-storage.json. Do not restate that case. Recoverable window 30 days, provision D4 against a D5 requirement.",
"evidence_basis":"measured",
"observed_at":"2026-08-14"
},
{
"capability":"security.secrets",
"provider":"OpenBao / external-secrets on reef-railiance",
"relation":"may_use",
"note":"ClusterSecretStore openbao-audit-core and openbao-audit-core-database. Never class P."
}
],
"consumes":[
{
"class":"S",
"name":"retained events",
"quantity":{
"value":null,
"unit":"GB"
},
"period":"month",
"basis":"unknown",
"gap":"pg_total_relation_size of audit_core has not been recorded against this provision (owner: audit-core)"
},
{
"class":"H",
"name":"receiver operation",
"quantity":{
"value":null,
"unit":"hour"
},
"period":"month",
"supply":"internal",
"basis":"unknown",
"gap":"operator hours are not recorded (owner: audit-core; start a time record later)"
},
{
"class":"I",
"name":"intelligence",
"quantity":{
"value":null,
"unit":"token"
},
"period":"month",
"basis":"unknown",
"gap":"audit-core does not meter token consumption against this provision (owner: audit-core)"
}
],
"evidence":[
{
"hook":"audit_records",
"basis":"measured",
"value":"in-pod remote failure matrix 12 pass / 0 fail / 3 skip; live accept 202 before and after lease rotation",
"data.archive is required by INTENT and unprovided. A founder decision is needed before resource-control procures a WORM/object-lock destination distinct from the 30-day Barman bucket.",
"integrity_verification is measured. A database owner who rewrites the suffix and the external attestation together can still lie; that is the stated proof bound.",