Answer flex-auth B3: the emitter is the section 4 source, not the archive
AUDIT-IN-0005. flex-auth produces the decision record, declares no §11 emission guarantee, and declined to take the reading that moves the obligation to audit-core. audit-core declines it too, on its own authority: class, cadence and detection surface are properties of emitting; audit-core cannot detect non-production; the obligations already sit on each sender registration; archive-as-source would make §11's check vacuous; and no access-engine sender is registered at all. Binds audit-core, does not rule §11 — gate-house still owns that, so flex-auth's G2 stays open. Reflexive half: audit-core's own chain-head attestation emission is now declared in layer.yaml rather than only in docs/integrity.md prose, and asserted against the CronJob and the contract by test. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: opus Assistant-Process: 63291@bnt-lap001 Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
This commit is contained in:
parent
5dc70afe64
commit
40fc7d694c
5 changed files with 338 additions and 1 deletions
|
|
@ -1,5 +1,78 @@
|
|||
# Intake records
|
||||
|
||||
## AUDIT-IN-0005 — Which repository is the §4 source of evidence for the decision record
|
||||
|
||||
```yaml
|
||||
id: AUDIT-IN-0005
|
||||
kind: intake
|
||||
title: 'Which repository is the §4 source of evidence for the decision record
|
||||
(flex-auth B3 / declared gap G2)'
|
||||
status: closed
|
||||
origin: cross-repo
|
||||
origin_ref: FLEX-WP-0030 B3 / flex-auth conformance gap G2
|
||||
priority: high
|
||||
owner: audit-core
|
||||
requested_by: flex-auth
|
||||
description: >
|
||||
§11 requires every repository catalogued in §4 as a source of evidence to
|
||||
declare its emission guarantee — class, cadence and the detection surface the
|
||||
governing cadence profile requires — in its machine-readable layer
|
||||
declaration, and says a source declaring none is not conforming.
|
||||
|
||||
flex-auth (access-engine) produces the decision record and declares none. Two
|
||||
readings are defensible from the text: flex-auth is a §4 source and is
|
||||
non-conformant today, or audit-core is the source and flex-auth is merely the
|
||||
producer of an artifact audit-core is the source of. flex-auth declined to
|
||||
pick the second — the reading that favours it — and asked audit-core to say
|
||||
which side of the line audit-core holds. The custodian confirmed audit-core
|
||||
can answer without waiting on gate-house, and that answering does not close
|
||||
G2. Estate-wide view: the-custodian/docs/assessments/2026-09-21-layer-declaration-boundaries.md.
|
||||
created: '2026-09-21'
|
||||
updated: '2026-09-21'
|
||||
outcome: declined-with-the-surface-offered
|
||||
closed: '2026-09-21'
|
||||
resolution: 'audit-core is NOT the §4 source of evidence for the decision
|
||||
record. The emitter is, and for the decision record the emitter is
|
||||
access-engine. Five reasons, none of them preference. (1) Class, cadence and
|
||||
detection surface are all properties of the act of emitting; audit-core
|
||||
produces no decision record, and told gate-house before this question existed
|
||||
that it cannot detect non-production at all — AUDIT-IN-0003 against
|
||||
GH-DEC-2026-014 limit 3. A declaration here would promise behaviour audit-core
|
||||
cannot observe. (2) It is audit-core''s standing doctrine in writing:
|
||||
completeness at the boundary is the emitter''s property, not the archive''s
|
||||
(AUDIT-IN-0001), and emission atomicity at the source is an AUDIT-WP-0009
|
||||
non-goal. Taking the role now would reverse for the asking repository a
|
||||
boundary held against gate-house and approval-engine. (3) The operative shape
|
||||
already assigns it: evidence_kind and heartbeat_classes sit on each SENDER
|
||||
registration, per source and per class, for all four registered sources,
|
||||
because §11 and the cadence profile both make the classification the source''s
|
||||
published one. (4) Archive-as-source makes §11 vacuous — every emission
|
||||
obligation would land on the one repository that can observe no emission, and
|
||||
no source could ever be non-conforming. That is the §9.1 defect §11 says it has
|
||||
corrected four times. (5) As fact: no sender named access-engine or flex-auth
|
||||
is registered, no token, no ingress, no scope row — the decision record never
|
||||
reaches audit-core custody, and a repository cannot be the source of evidence
|
||||
it has never received. WHAT AUDIT-CORE OWES INSTEAD, and it is not nothing: the
|
||||
rare load-bearing form access-engine expects — heartbeat per class plus
|
||||
reconciliation, never rate — is built and registerable through an intake, with
|
||||
the standing bound that neither control covers a source suppressing an event
|
||||
and its own count together (§16). WHAT THIS DOES NOT DO: it binds audit-core,
|
||||
it does not rule §11. gate-house authors §11 and still owns the ruling, so G2
|
||||
does not close on this record alone — this is audit-core''s confirmation, not
|
||||
gate-house''s ruling. REFLEXIVE HALF: asked which side of the line it holds,
|
||||
audit-core answered about itself too. It emits no event into another
|
||||
repository''s custody, but it does produce the chain-head attestation, whose
|
||||
class, cadence and detection surface were stated only in docs/integrity.md
|
||||
prose. They are now declared in layer.yaml under emission_guarantee
|
||||
(load-bearing, rare, daily 17 3 * * *, 168h freshness window degrading
|
||||
tamper_evidence to False with the reason recorded) and asserted by
|
||||
tests/test_layer_conformance.py against the CronJob and the contract. Leaving
|
||||
it in prose while charging another repository with declaring theirs would have
|
||||
been the flattering reading of an unruled boundary.'
|
||||
recorded_in: docs/section-4-source-of-evidence.md
|
||||
work: AUDIT-WP-0009-T13
|
||||
```
|
||||
|
||||
## AUDIT-IN-0003 — Register informed-decision as a load-bearing sender; commitment-only payload doctrine
|
||||
|
||||
```yaml
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue