docs(AUDIT-WP-0008): record E2 adapter review
Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a025c2-407a-7a32-b40a-f37a52f03f62
This commit is contained in:
parent
5c5e98c8b5
commit
34f0077a9b
1 changed files with 11 additions and 5 deletions
|
|
@ -393,11 +393,17 @@ minute, and requires two temporary read-enabled identities each scoped to one
|
|||
fixture tenant. The production `user-engine` identity remains unchanged and is
|
||||
not a test credential.
|
||||
|
||||
This is progress, not evidence and not live authorization. Whitehat still owes
|
||||
a complete dated engagement and executable identity adapter; the operator must
|
||||
approve that target/window, after which audit-core supplies the formal
|
||||
post-approval owner acknowledgement. T05 becomes `done` only when the sanitized
|
||||
target report exists and has been routed to `risk-nexus`.
|
||||
Whitehat supplied a production engagement record at `3770b41` and a bounded
|
||||
adapter at `7396fe7`. Target review found that the adapter omits audit-core's
|
||||
required `Idempotency-Key` header on POST, so it would abort fixture seeding
|
||||
with `idempotency_key_mismatch` and cannot yet produce evidence. Review reply
|
||||
`74b815ea-341f-455d-8fdb-2333f5753f76` accepted the two-identity fixture shape
|
||||
in principle and requested that fix plus corrected production-approval and
|
||||
owner-acknowledgement provenance before formal acknowledgement.
|
||||
|
||||
This is progress, not evidence and not live authorization. T05 becomes `done`
|
||||
only when the corrected engagement is acknowledged, the bounded run completes,
|
||||
and its sanitized target report has been routed to `risk-nexus`.
|
||||
|
||||
```task
|
||||
id: AUDIT-WP-0008-T06
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue