docs(AUDIT-WP-0008): record E2 adapter review
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a025c2-407a-7a32-b40a-f37a52f03f62
This commit is contained in:
tegwick 2026-08-22 00:04:41 +02:00
parent 5c5e98c8b5
commit 34f0077a9b

View file

@ -393,11 +393,17 @@ minute, and requires two temporary read-enabled identities each scoped to one
fixture tenant. The production `user-engine` identity remains unchanged and is
not a test credential.
This is progress, not evidence and not live authorization. Whitehat still owes
a complete dated engagement and executable identity adapter; the operator must
approve that target/window, after which audit-core supplies the formal
post-approval owner acknowledgement. T05 becomes `done` only when the sanitized
target report exists and has been routed to `risk-nexus`.
Whitehat supplied a production engagement record at `3770b41` and a bounded
adapter at `7396fe7`. Target review found that the adapter omits audit-core's
required `Idempotency-Key` header on POST, so it would abort fixture seeding
with `idempotency_key_mismatch` and cannot yet produce evidence. Review reply
`74b815ea-341f-455d-8fdb-2333f5753f76` accepted the two-identity fixture shape
in principle and requested that fix plus corrected production-approval and
owner-acknowledgement provenance before formal acknowledgement.
This is progress, not evidence and not live authorization. T05 becomes `done`
only when the corrected engagement is acknowledged, the bounded run completes,
and its sanitized target report has been routed to `risk-nexus`.
```task
id: AUDIT-WP-0008-T06