diff --git a/workplans/AUDIT-WP-0008-tenancy-posture-alignment.md b/workplans/AUDIT-WP-0008-tenancy-posture-alignment.md index 5990fb0..c628dc0 100644 --- a/workplans/AUDIT-WP-0008-tenancy-posture-alignment.md +++ b/workplans/AUDIT-WP-0008-tenancy-posture-alignment.md @@ -393,11 +393,17 @@ minute, and requires two temporary read-enabled identities each scoped to one fixture tenant. The production `user-engine` identity remains unchanged and is not a test credential. -This is progress, not evidence and not live authorization. Whitehat still owes -a complete dated engagement and executable identity adapter; the operator must -approve that target/window, after which audit-core supplies the formal -post-approval owner acknowledgement. T05 becomes `done` only when the sanitized -target report exists and has been routed to `risk-nexus`. +Whitehat supplied a production engagement record at `3770b41` and a bounded +adapter at `7396fe7`. Target review found that the adapter omits audit-core's +required `Idempotency-Key` header on POST, so it would abort fixture seeding +with `idempotency_key_mismatch` and cannot yet produce evidence. Review reply +`74b815ea-341f-455d-8fdb-2333f5753f76` accepted the two-identity fixture shape +in principle and requested that fix plus corrected production-approval and +owner-acknowledgement provenance before formal acknowledgement. + +This is progress, not evidence and not live authorization. T05 becomes `done` +only when the corrected engagement is acknowledged, the bounded run completes, +and its sanitized target report has been routed to `risk-nexus`. ```task id: AUDIT-WP-0008-T06